Application Security

This category focuses on the security lifecycle of software, from development and deployment to runtime behavior. Coverage includes vulnerability research, unauthorized persistence mechanisms (such as Launch Agents and Daemons), API security, and the risks associated with third-party software integrations. It serves as the primary resource for identifying how flaws or "hidden features" in applications can lead to system-wide compromise or data exfiltration.

A stylized gopher silhouette with a white Slack logo inside its chest.

Nation-State Cyber Threats

China-Linked GopherWhisper APT Hits 12 Mongolian Gov Systems Using Slack/Discord C2

ESET discovers a new espionage group abusing legitimate cloud services for command-and-control against strategically sensitive Mongolian targets. ULAN BATOR, MN — Researchers at ESET have uncovered a sophisticated, China-aligned espionage campaign targeting the Mongolian government. The threat actor, dubbed GopherWhisper, has successfully infected at least 12 government systems since late 2023,