Capstone Technologies Group

@CapTechGroup
11 Followers
27 Following
244 Posts
Veteran-owned managed IT & cybersecurity for Ohio's medical, legal, and financial firms. Springfield-based, serving the Dayton–Columbus–Cincinnati corridor since 2002. Layered protection: SentinelOne, SonicWall managed firewalls, Adlumin SOC/SIEM, immutable backups, plus security awareness and HIPAA training. SonicWall Certified · N-able Partner. We post threat patterns and practical security guidance for professional practices—what we're actually seeing.
LocationSpringfield, Ohio
Since2002 · Veteran Owned
FocusLegal · Medical · Financial
CertifiedSonicWall · N-able Partner

ZypeerShell deployments on professional services infrastructure create encrypted GSocket tunnels that bypass traditional network monitoring. The webshell's persistence mechanisms—Fortress Layer obfuscation, multi-layer integrity...

https://captechgroup.com/threat-intelligence-center/webshells-remain-popular-attack-vector-for-profess-9e7426?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=webshells-remain-popular-attack-vector-for-professional-service-firms

The Kali365 PhaaS platform exploits Microsoft's device authentication grant type (client ID d3590ed6-52b3-4102-aeff-aad2292ab01c) to generate 90-day refresh tokens that survive password and MFA changes. Attack chain:...

https://captechgroup.com/threat-intelligence-center/kali365-device-code-phishing-ecosystem-targets-mic-a6bb32?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=kali365-device-code-phishing-ecosystem-targets-microsoft-account-credentials

CVE-2026-20230 (Cisco UCM) and CVE-2026-12569 (PTC Windchill/FlexPLM) are actively exploited. The Cisco flaw is unauthenticated SSRF enabling arbitrary file writes; PTC involves unsafe deserialization leading to RCE....

https://captechgroup.com/threat-intelligence-center/cisco-flaw-cve-2026-12569-exploited-in-active-atta-32c052?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=cisco-flaw-cve-2026-12569-exploited-in-active-attacks-cisa-sets-patch-deadline

Turla's STOCKSTAY employs environmental keying and modular architecture (STOCKBROKER, STOCKMARKET, STOCKTRADER) to maintain persistence in government and diplomatic networks. The malware decrypts only on specific hosts/users/domains,...

https://captechgroup.com/threat-intelligence-center/turlas-stockstay-malware-targets-government-and-di-ac782d?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=turla-s-stockstay-malware-targets-government-and-diplomatic-networks

RUST-based clipboard hijacker exploits multi-platform trust signals: fake GitHub repos, manipulated VirusTotal votes, AI-narrated YouTube videos, and fraudulent news placement to distribute malware targeting Bitcoin, Ethereum,...

https://captechgroup.com/threat-intelligence-center/rust-clipboard-hijacker-fuels-crypto-heist-through-fe6fdc?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=rust-clipboard-hijacker-fuels-crypto-heist-through-fake-reputation-campaign

Operation Endgame disrupted SocGholish—a traffic distribution system that fingerprints victims and delivers tailored payloads based on domain-join status. Law enforcement seized 106 servers and remediated 14,971 WordPress sites, but the...

https://captechgroup.com/threat-intelligence-center/socgholish-takedown-disrupts-junkytds-and-parrottd-a625f7?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=socgholish-takedown-disrupts-junkytds-and-parrottds-operations

Qakbot's COM hijacking and WarmCookie's vtable obfuscation render static analysis ineffective. Behavioral indicators—rundll32→PowerShell chains, unusual network beaconing, API sequences—detect variants that hash-based...

https://captechgroup.com/threat-intelligence-center/ai-enabled-threat-intelligence-moves-beyond-iocs-t-70c8c3?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=ai-enabled-threat-intelligence-moves-beyond-iocs-to-stop-qakbot-and-scattered-sp

FortiBleed infostealer campaign compromised ~75k credentials from Fortinet customers across 194 countries. Attackers extracted plaintext passwords from configuration files via brute-force and dictionary attacks, then used credential...

https://captechgroup.com/threat-intelligence-center/fortibleed-infostealer-hits-fortinet-customers-acr-e365b3?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=fortibleed-infostealer-hits-fortinet-customers-across-five-industries

Mandiant documented active exploitation of CVE-2026-20245 (privilege escalation) chained with CVE-2026-20182 and CVE-2026-20127 (authentication bypass) against SD-WAN controllers. Attackers used rogue peering connections to establish...

https://captechgroup.com/threat-intelligence-center/attackers-hit-cisco-sd-wan-flaw-2-months-before-di-52a02f?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=attackers-hit-cisco-sd-wan-flaw-2-months-before-disclosure

Windows COM hijacking is now a systematic evasion technique. Threat actors modify HKEY_CLASSES_ROOT and HKEY_LOCAL_MACHINE registry hives to redirect legitimate CLSIDs toward malicious DLLs, executing within trusted process contexts....

https://captechgroup.com/threat-intelligence-center/windows-threats-abuse-com-objects-to-evade-detecti-41ed59?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=windows-threats-abuse-com-objects-to-evade-detection-and-persist