Skip to main content

Topic

Threat Intelligence

CTI Roundup: UNC6032, APT41, Void Blizzard
Jun 4, 2025

The latest on UNC6032 fake AI websites, APT41’s use of Google Calendar, and Void Blizzard targeting critical sectors.

CTI Roundup: Deepfakes, ToyMaker IAB, and ClickFix
Apr 30, 2025

Recent news about threat actors using real-time deepfakes to land remote work, ToyMaker initial access broker, and state-sponsored hackers using ClickFix.

CTI Roundup: 12 Million Secrets and Keys Leak on GitHub
Mar 20, 2024

BianLian threat actors exploit JetBrains TeamCity flaws, ransomware attacks continue to accelerate, and more than 12 million secrets and keys leak on GitHub.

stock image: face in dark room lit by glow of a computer monitor
Sep 27, 2023

Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.

CTI Roundup: Go Infostealers, 3AM Ransomware, & RedLine/Vidar Malware
Sep 21, 2023

New family of Go infostealers spreads in targeted attacks, researchers discover 3AM ransomware in the wild, and RedLine/Vidar threat actors pivot to ransomware.

CTI Roundup: Stop Making These Four Common Password Mistakes Now
Sep 6, 2023

Threat actors use misleading dates in phishing subject lines, four common password mistakes to avoid, and Earth Estries targets global governments and tech companies.

Tanium–Blog-2.3.22-Naveen Goela’s Mission to Mature Security with Science
Aug 29, 2023

XLoader macOS variant poses as a productivity app, Lazarus Group uses new malware, and threat actors abuse Facebook promotions to spread malicious code.

CTI Roundup: Monti ransomware targets VMware ESXi servers with new Linux locker
Aug 23, 2023

Raccoon Stealer malware reappears, AI adoption remains low among threat actors, and Monti ransomware targets VMware ESXi servers with new Linux locker

CTI Roundup: Rhysida Ransomware Threatens the Healthcare Sector
Aug 16, 2023

Cloud takeover campaign targets top-level executives, Rhysida ransomware threatens the healthcare sector, and LOLKEK ransomware continues to evolve.

CTI Roundup: Google AMP & Salesforce Exploited for Phishing Attacks
Aug 9, 2023

Threat actors abuse Google AMP for evasive phishing attacks, hackers exploit Salesforce’s email services in targeted Facebook phishing campaign, and Russian actor BlueCharlie alters infrastructure in response to disclosures.

CTI Roundup: Realst Malware targets MacOS, Infostealer Malware Sees Exponential Growth
Aug 2, 2023

Realst malware targets macOS Sonoma ahead of public release, infostealer malware sees exponential growth, and new Nitrogen malware spreads via Google Ads for ransomware attacks.

Image for MITRE ATT&CK blog post
Jul 26, 2023

Ransomware impersonates Sophos, FIN8 group uses modified backdoor to deliver BlackCat ransomware, and Chinese espionage actors continue to evolve.