<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>APT on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/apt/</link><description>Recent content in APT on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 17 May 2026 13:18:03 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/apt/index.xml" rel="self" type="application/rss+xml"/><item><title>Google Catches the First AI Built Zero-Day and Stops a Mass Attack Before It Starts</title><link>https://hackingpassion.com/gtig-ai-zero-day/</link><pubDate>Sun, 17 May 2026 13:18:03 +0200</pubDate><guid>https://hackingpassion.com/gtig-ai-zero-day/</guid><description>&lt;p>Google caught a criminal group that used AI to find a zero-day in a popular web admin tool and had a working exploit ready for a mass attack against thousands of systems. Google has never named the tool. The attack never launched. What gave them away was a &lt;strong>CVSS severity score inside the code for a vulnerability that has never been officially rated. The AI made up a number that does not exist.&lt;/strong>&lt;/p></description></item><item><title>Fast16: The Cyberweapon That Predates Stuxnet by Five Years</title><link>https://hackingpassion.com/fast16-pre-stuxnet-cyber-sabotage/</link><pubDate>Sun, 26 Apr 2026 11:49:23 +0200</pubDate><guid>https://hackingpassion.com/fast16-pre-stuxnet-cyber-sabotage/</guid><description>&lt;p>For 21 years, a cyberweapon called &lt;strong>fast16&lt;/strong> sat completely undetected. This one did not destroy machines or blow things up. It corrupted the math. Scientists running nuclear and engineering simulations got output that looked completely normal, every number added up, every result made sense, and all of it was deliberately wrong. It surfaced last week. It predates Stuxnet by five years.&lt;/p>
&lt;p>&lt;strong>SentinelOne&lt;/strong> researchers &lt;strong>Vitaly Kamluk&lt;/strong> and &lt;strong>Juan Andrés Guerrero-Saade&lt;/strong> presented the full analysis of fast16 at &lt;strong>Black Hat Asia&lt;/strong> last week. Fast16&amp;rsquo;s core binary has a compilation timestamp of &lt;strong>August 30, 2005&lt;/strong>. Stuxnet&amp;rsquo;s C&amp;amp;C infrastructure was set up in November that same year.&lt;/p></description></item><item><title>Notepad++ Supply Chain Attack Full Story</title><link>https://hackingpassion.com/notepad-plus-plus-supply-chain-attack/</link><pubDate>Mon, 02 Feb 2026 17:41:03 +0100</pubDate><guid>https://hackingpassion.com/notepad-plus-plus-supply-chain-attack/</guid><description>&lt;p>Notepad++ delivered malware for six months. From June to December 2025, the update system was compromised. Millions of people use this software. Some of them clicked update and got spyware instead of a patch. Here is what we now know. 🧐&lt;/p>
&lt;p>The attackers did not hack Notepad++ itself, they went after the hosting provider instead. On February 2, 2026, developer Don Ho published the full disclosure of what happened. The website notepad-plus-plus.org sat on a shared hosting server, which means it shared space and resources with other customers on the same machine. Once the attackers broke into that server, they could see all the traffic flowing through it and intercept whatever they wanted.&lt;/p></description></item><item><title>SAP Just Got Breached: Four Critical Vulnerabilities Let Attackers Steal Financial Data (CVE-2026-0501)</title><link>https://hackingpassion.com/sap-patch-tuesday-four-critical-vulnerabilities-cve-2026-0501/</link><pubDate>Tue, 13 Jan 2026 14:03:32 +0100</pubDate><guid>https://hackingpassion.com/sap-patch-tuesday-four-critical-vulnerabilities-cve-2026-0501/</guid><description>&lt;h1 id="sap-just-patched-four-critical-vulnerabilities">SAP just patched four critical vulnerabilities&lt;/h1>
&lt;p>SAP just patched four critical vulnerabilities. CVSS scores up to 9.9. One lets attackers run code with nothing but a malicious link. 425,000 companies run SAP. Over 85% of Fortune 500. The patches dropped today, January 13, 2026. 🧐&lt;/p>
&lt;p>SAP Patch Tuesday just landed with seventeen security notes. Four are HotNews - SAP&amp;rsquo;s term for patch immediately or accept the consequences.&lt;/p>
&lt;p>The most severe vulnerability lets someone with a basic user account run arbitrary SQL queries against the entire financial database.&lt;/p></description></item></channel></rss>