<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat-Intelligence on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/threat-intelligence/</link><description>Recent content in Threat-Intelligence on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 17 May 2026 13:18:03 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/threat-intelligence/index.xml" rel="self" type="application/rss+xml"/><item><title>Google Catches the First AI Built Zero-Day and Stops a Mass Attack Before It Starts</title><link>https://hackingpassion.com/gtig-ai-zero-day/</link><pubDate>Sun, 17 May 2026 13:18:03 +0200</pubDate><guid>https://hackingpassion.com/gtig-ai-zero-day/</guid><description>&lt;p>Google caught a criminal group that used AI to find a zero-day in a popular web admin tool and had a working exploit ready for a mass attack against thousands of systems. Google has never named the tool. The attack never launched. What gave them away was a &lt;strong>CVSS severity score inside the code for a vulnerability that has never been officially rated. The AI made up a number that does not exist.&lt;/strong>&lt;/p></description></item><item><title>DesckVB RAT Uses Windows' Own Tools to Stay Hidden and Leaves Almost Nothing Behind</title><link>https://hackingpassion.com/desckvb-rat-fileless-malware-2026/</link><pubDate>Sat, 11 Apr 2026 12:52:30 +0200</pubDate><guid>https://hackingpassion.com/desckvb-rat-fileless-malware-2026/</guid><description>&lt;p>A Remote Access Trojan called DesckVB has been actively hitting systems throughout 2026, running almost entirely inside memory with barely anything written to disk, hiding its final payload inside a process it names &lt;strong>Microsoft.exe&lt;/strong>, and attempting to switch off the camera LED before streaming video back to the attacker. A cracked version of the builder is already circulating freely, meaning attackers with minimal skills can deploy this today without writing a single line of code. Forensics teams sweep these machines afterward and find very little. The system looks completely clean. 😏&lt;/p></description></item><item><title>Hackers Are Hijacking NGINX Servers Without Installing Malware</title><link>https://hackingpassion.com/nginx-hijacking-no-malware/</link><pubDate>Thu, 05 Feb 2026 13:58:06 +0100</pubDate><guid>https://hackingpassion.com/nginx-hijacking-no-malware/</guid><description>&lt;p>Hackers are hijacking NGINX web servers and rerouting live traffic through their own infrastructure. No malware installed, no vulnerability exploited. Just a few lines changed in a configuration file, and every visitor&amp;rsquo;s data flows through attacker-controlled servers without anyone noticing. 🧐&lt;/p>
&lt;p>NGINX is the most popular web server on the planet. It powers over 5 million websites and handles roughly one in three web connections worldwide. Banks, governments, and universities all depend on it. And right now, a campaign is silently turning these servers into traffic relays.&lt;/p></description></item></channel></rss>