Martin Zugec
Recent Posts
Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR
I’d like to thank my coauthors, Andrei-Marius Muntea, Andrei Mermeze, Radu-Marian Portase, ...
What Mythos Reveals About Zero Trust’s Scope Problem
The coverage of Anthropic’s Mythos Red Team report has followed a predictable arc: a ...
Technical Advisory: Axios npm Supply Chain Attack - Cross-Platform RAT Deployed via Compromised Maintainer Account
[CRITICAL] | Active RAT | Malicious npm versions removed | Assess all systems that ran npm ...
Technical Advisory: OpenClaw Exploitation in Enterprise Networks
The promise of autonomous AI agents is rapidly turning into a security beachhead for initial ...
ClickFix: A KISS from Cybercriminals
One of the biggest challenges in threat intelligence is separating the hype from the hazard. ...
Technical Advisory: React2Shell Critical Unauthenticated RCE in React (CVE-2025-55182)
TL;DR Ransomware groups are expected to rapidly weaponize this critical (CVSS 10.0) React ...
Technical Advisory: Critical Unauthenticated RCE in Windows Server Update Services (WSUS) - CVE-2025-59287
TL;DR Our telemetry indicates an active exploitation campaign targeting vulnerable Windows ...
Security Risks of Agentic AI: A Model Context Protocol (MCP) Introduction
If you've spent any time around IT, you must own that dusty box of legacy cables – a tangle ...
Why Hypervisors Are the New-ish Ransomware Target
One of the greatest challenges in cybersecurity is the constant evolution of threats. While ...
Technical Advisory: SonicWall Targeted by Ransomware Group
Bitdefender MDR has observed a significant increase in malicious activity targeting ...
Technical Advisory: Critical Remote Code Execution Vulnerability in Microsoft SharePoint Server (CVE-2025-53770)
Bitdefender analysis confirmedactive, widespread exploitation of a critical remote code ...


