A campaign tied to Screening Serpens shows how AppDomainManager abuse can turn a trusted .NET startup path into an early-stage hiding place for malware.
A reported .NET abuse chain shows how defenders can lose visibility before an application fully settles, especially when startup manipulation is paired with DLL sideloading and recruitment-themed lures.
An FT-attributed allegation about Iran-linked actors using ChatGPT and Gemini points to a broader security shift: generative AI may be lowering the cost of phishing, translation, and reconnaissance, without changing the old logic of intrusion.
A destructive campaign reportedly hit IT, backup, and recovery systems at multiple organizations, showing how modern intrusions can aim to erase the path back to normal operations.