Cyderes Howler Cell has reproduced the technique on Windows 11 and confirmed the redirection in a controlled environment.
Public source
Publisher name
Public post
Howler Cell has been tracking the ongoing Microfost zero-days tied to MSNightmare, also known as Nightmare Eclipse and Chaotic Eclipse. Following prior analysis of BlueH…
Company
Cyderes
We help the world Be Everyday Ready™
- Industry
- Computer and Network Security
- Location
- Kansas City, US
- Company size
- 501–1,000 employees
About Cyderes
Today’s threatscape is relentless. So are we. At Cyderes, we specialize in building practical Identity & Access Management (IAM), Managed Detection & Response (MDR), Exposure Management, and risk programs to block and stop threats, fast. Our tireless global team is laser-focused on cybersecurity, arming organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.
See moreLatest activity
Latest activity from Cyderes
25 signals
Research & Knowledge
Cyderes reports that the same actor released four new zero-day targets for CrowdStrike, NVIDIA, Avast, and Kaspersky in the latest public zero-day release since April 2026.
Presence & Recognition
Cyderes hosted an episode of Research Saturday discussing an SEO poisoning campaign by Brian Hussey.
Research & Knowledge
Cyderes published a breakdown of four zero days hitting CrowdStrike, NVIDIA, Avast, and Kaspersky.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
LevelBlue
LevelBlue SpiderLabs team breaks down the attack and provides practical YARA rules and SentinelOne searches to hunt for Microsoft Defender placing malicious files into trusted Windows system folders
Research & Knowledge
Iterasec
Iterasec published a new article on Active Directory attack paths focusing on low-privileged footholds moving through the environment toward Domain Admin.
Research & Knowledge
Trellix
Trellix published a research blog detailing the complete kill chain for attackers hijacking Active Directory, including domain-wide user SPN enumeration, RC4 TGS requests, memory dumps, offline cracking, and obfuscation techniques.
Research & Knowledge
Exploit Pack
Exploit Pack conducted research to examine how vulnerable VBS enclave interfaces can be turned into new capabilities for its tools.
Research & Knowledge
Trellix