Click any tag below to further narrow down your results
Links
Tailscale is a mesh networking tool that replaces traditional VPNs by creating encrypted connections between devices without requiring a central server. It handles NAT traversal automatically, works across clouds and on-premises infrastructure, and uses identity-based access control instead of managing certificates manually.
- Tailscale creates encrypted mesh connections between devices without a central server, automatically handling NAT traversal issues (double NAT, blocked ports) that break traditional VPN/WireGuard setups
- It flips default network security posture—devices are private by default and must be deliberately exposed, rather than exposed by default and needing to be locked down
- Real-world use cases span managing home Kubernetes clusters remotely, connecting field robots, and multi-cloud/on-prem access, all set up in minutes with minimal config
- Compares favorably to OpenVPN through fixed IPs, DNS support, SSO-backed GUI access controls, and scaling to many devices without manual key/certificate management
Attackers hijack WhatsApp accounts to send obfuscated VBScript files named as business or financial documents. When opened, the script disables UAC, downloads ManageEngine Endpoint Central, and connects the PC to attacker-controlled servers for remote administration. The campaign hits users in over a dozen countries, though how WhatsApp accounts are first compromised remains unclear.
- Attackers are hijacking WhatsApp accounts to send malicious VBScript files disguised as invoices or financial reports, hitting users across 11+ countries.
- Opening the file disables UAC, then silently installs the legitimate ManageEngine Endpoint Central tool to give attackers full remote control of the PC.
- Code artifacts point to Chinese-language origins and overlap with ValleyRAT/Gh0st RAT infrastructure, though no group has been formally attributed.
- It's still unknown how the attackers are initially compromising victims' WhatsApp accounts.