- [2026.05.01]Adjacent campaigns and a defender's playbook [3/3]
Adjacent SSH brute-force campaigns observed alongside Sorry-worm: Multiverze sshd backdoor, Diicot/Opera updated 2026 build, Mirai-derived sshscan kit. Indicators in three confidence tiers, YARA and Sigma rules, hunting queries, a reproducible activity timeline, and defensive recommendations.
- [2026.05.01]Inside Sorry-worm: anatomy of a Go ransomware-worm hybrid [2/3]
Binary-level analysis of Sorry-worm: hardcoded RSA-2048 attribution-stable indicator, AES-CBC encryption pipeline, 48-byte fixed prefix on encrypted files, UNIX-nanosecond victim ID, embedded SSH wordlist, and the layered SSH scan that runs concurrently with encryption. The single most important property: encryption and SSH propagation occur concurrently in the same process.
- [2026.05.01]Catching Sorry-worm in the wild [1/3]
A previously undocumented Linux ransomware-worm hybrid, propagating from compromised SSH relays approximately 8 hours after the sample's first public sandbox submission. Two independent propagation events from unrelated IPs, separated by ~7 hours, more consistent with autonomous worm-style propagation than a single hands-on session.
- [2026.05.01]The AI Security Narrative Has Two Halves. We're Mostly Looking at One.
The vulnpocalypse framing assumes defense is static while offense gets new tools. Looking at the actual research and product landscape, that misses what's happening on the defensive side at the same time.
- [2026.04.27]Deterrence by Cognitive Compromise
You can't deter a machine. But you can deter the operator behind it - by making the machine a liability. When intention itself becomes retrievable, the offensive economics of agentic operations changes shape.
- [2026.04.23]Detecting and Countering AI-Enabled Intrusions with Deception
Findings from four controlled wargame labs running ~1,000 LLM-driven intrusions against a HIIH high-interaction honeypot. Persistence is universal. Attackers come in three shapes. Counter-forensics has arrived - and counter-intelligence works.