NANOFIREWALL BLOG

NANOFIREWALL BLOG

  • LinkedIn
  • Home
  • Advanced Attacks
  • Research
  • Expert Insights
  • About Us
  • Contact Us

Author: Vukasin

  • 13
    May
    IoT

    Vukasin

    Preemptive Cybersecurity for the Industrial Edge

    Preemptive Cybersecurity for the Industrial Edge

    Preemptive Cybersecurity for the Industrial Edge The Edge Device Isn’t the Target. The Path to It Is. Patched edge device. Segmented network. Next-gen firewall. None of it makes you safer. It just makes you slower to compromise. We pulled four months of attack data from the industrial edge devices our nanoFirewall protects. Almost none of

    Continue Reading

  • 8
    Jan
    Uncategorized

    Vukasin

    LLMProbe: Early-2026 Automated Scanning of Public LLM Inference Endpoints

    LLMProbe: Early-2026 Automated Scanning of Public LLM Inference Endpoints

    LLMProbe: Early-2026 Automated Scanning of Public LLM Inference Endpoints Summary On January 8, 2026, our systems observed a coordinated campaign of automated HTTP requests targeting common Large Language Model (LLM) API endpoints such as /v1/chat, /v1/chat/completions, /openai/v1/chat/completions, and /api/chat. The attacker iterated through multiple popular model names (gpt-4o, llama3, grok-2, mistral-large-latest, etc.) and sent the

    Continue Reading

  • 15
    Dec
    CVEs

    Vukasin

    React2Shell: Critical Pre-Auth RCE in React Server Components

    React2Shell: Critical Pre-Auth RCE in React Server Components

    React2Shell: Critical Pre-Auth RCE in React Server Components Summary In early December 2025, a critical remote code execution vulnerability was disclosed in React that allows unauthenticated attackers to execute arbitrary code on affected servers. The flaw, tracked as CVE-2025-55182 and assigned a CVSS score of 10.0, impacts React’s Server Components (RSC) implementation and has been

    Continue Reading

  • 11
    Dec
    Advanced Attacks

    Vukasin

    The Zombie Server: How a Dead T-Shirt Store Became a Cyberattack Hub

    The Zombie Server: How a Dead T-Shirt Store Became a Cyberattack Hub

    The Zombie Server: How a Dead T-Shirt Store Became a Cyberattack Hub The Vanishing Store It started with a simple online t-shirt shop. TeeFall.com—a small business selling “legendary” printed tees, with an Instagram page (@teetall.com) that hadn’t posted in over a year. On the surface, nothing seemed unusual. But something was very wrong. The website

    Continue Reading

  • 8
    Aug
    CVEs

    Vukasin

    Proactive Detection in Action: The SharePoint Exploit We Blocked Before Microsoft Did

    Proactive Detection in Action: The SharePoint Exploit We Blocked Before Microsoft Did

    Proactive Detection in Action: The SharePoint Exploit We Blocked Before Microsoft Did Summary In this post, we break down a critical SharePoint vulnerability that was actively exploited in the wild — and how we detected and blocked it weeks before public disclosure. By analyzing malicious requests to endpoints like /_layouts/15/toolpane.aspx, our systems identified the exploit

    Continue Reading

  • 11
    Jul
    Advanced Attacks

    Vukasin

    Iran-Israel Cyber Conflict: An In-Depth Analysis of Threat Actors and Cyber Operations

    Iran-Israel Cyber Conflict: An In-Depth Analysis of Threat Actors and Cyber Operations

    Iran-Israel Cyber Conflict: An In-Depth Analysis of Threat Actors and Cyber Operations The cyber battlefield between Iran and Israel has escalated into a persistent, multi-dimensional conflict targeting national infrastructure, defense assets, and civilian digital ecosystems. This post analyzes key threat actors, their tactics, and the strategic implications of their operations. The primary goal is to

    Continue Reading

  • 1
    Jul
    Botnet

    Vukasin

    How a Simple POST Request Leads to Persistent Whisper Botnet Access

    How a Simple POST Request Leads to Persistent Whisper Botnet Access

    How a Simple POST Request Leads to Persistent Whisper Botnet Access Executive Summary Between June 21st and 23rd, malicious activity originating from IP address 31.170.22[.]205, registered in Latvia, was detected targeting a vulnerable CGI interface on an IoT device. The attacker attempted to exploit this interface through a crafted HTTP POST request to Factory.cgi, aiming

    Continue Reading

Search

Categories

  • Advanced Attacks
  • Botnet
  • CVEs
  • IoT
  • Uncategorized

Recent Posts

  • Preemptive Cybersecurity for the Industrial EdgeMay 13, 2026
  • LLMProbe: Early-2026 Automated Scanning of Public LLM Inference EndpointsJanuary 8, 2026
  • React2Shell: Critical Pre-Auth RCE in React Server ComponentsDecember 15, 2025
  • The Zombie Server: How a Dead T-Shirt Store Became a Cyberattack HubDecember 11, 2025
  • Proactive Detection in Action: The SharePoint Exploit We Blocked Before Microsoft DidAugust 8, 2025

Social Icons

  • LinkedIn
  • YouTube

NANOFIREWALL BLOG

NANOFIREWALL BLOG

nanoFirewall is at the cutting edge of IoT cybersecurity, offering a revolutionary, AI-powered defense system designed to protect interconnected devices from both network layer attacks and web application layer attacks.

Stay informed. Stay secured.

Check your inbox or spam folder to confirm your subscription.