May 3, 2026 (opens in new tab)
May 3, 2026 The RansomISAC published regarding "Zhengzhou 403 Network Technology Co., Ltd.", a cert we reported in 2025 after it was used to sign CobaltStrike. Their investigation seemed like a wild adventure, check it out. Squiblydoo (@SquiblydooBlog) May 3, 2026 DragonBreath: Dragon in the Kernel | Ransom-ISAC Blog - Ransom-ISAC A 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an ...
Read the original article