Topic
Threat Intelligence

CTI Roundup: UNC6032, APT41, Void Blizzard
The latest on UNC6032 fake AI websites, APT41’s use of Google Calendar, and Void Blizzard targeting critical sectors.

CTI Roundup: Deepfakes, ToyMaker IAB, and ClickFix
Recent news about threat actors using real-time deepfakes to land remote work, ToyMaker initial access broker, and state-sponsored hackers using ClickFix.

CTI Roundup: 12 Million Secrets and Keys Leak on GitHub
BianLian threat actors exploit JetBrains TeamCity flaws, ransomware attacks continue to accelerate, and more than 12 million secrets and keys leak on GitHub.

CTI Roundup: FBI and CISA Issue a Joint Advisory for Snatch RaaS
Threat actors repurpose old code in fake vulnerability PoC, the FBI and CISA issue a joint advisory for Snatch RaaS, and threat actors deploy new SprySOCKS Linux malware in cyberespionage attacks.

CTI Roundup: Go Infostealers, 3AM Ransomware, & RedLine/Vidar Malware
New family of Go infostealers spreads in targeted attacks, researchers discover 3AM ransomware in the wild, and RedLine/Vidar threat actors pivot to ransomware.

CTI Roundup: Stop Making These Four Common Password Mistakes Now
Threat actors use misleading dates in phishing subject lines, four common password mistakes to avoid, and Earth Estries targets global governments and tech companies.

CTI Roundup: An XLoader macOS variant, Lazarus Group Update, and Hackers Abuse Facebook Ads
XLoader macOS variant poses as a productivity app, Lazarus Group uses new malware, and threat actors abuse Facebook promotions to spread malicious code.

CTI Roundup: Monti ransomware targets VMware ESXi servers with new Linux locker
Raccoon Stealer malware reappears, AI adoption remains low among threat actors, and Monti ransomware targets VMware ESXi servers with new Linux locker

CTI Roundup: Rhysida Ransomware Threatens the Healthcare Sector
Cloud takeover campaign targets top-level executives, Rhysida ransomware threatens the healthcare sector, and LOLKEK ransomware continues to evolve.

CTI Roundup: Google AMP & Salesforce Exploited for Phishing Attacks
Threat actors abuse Google AMP for evasive phishing attacks, hackers exploit Salesforce’s email services in targeted Facebook phishing campaign, and Russian actor BlueCharlie alters infrastructure in response to disclosures.

CTI Roundup: Realst Malware targets MacOS, Infostealer Malware Sees Exponential Growth
Realst malware targets macOS Sonoma ahead of public release, infostealer malware sees exponential growth, and new Nitrogen malware spreads via Google Ads for ransomware attacks.

CTI Roundup: Ransomware Impersonates Cybersecurity Firm, Espionage Tactics Evolve in China
Ransomware impersonates Sophos, FIN8 group uses modified backdoor to deliver BlackCat ransomware, and Chinese espionage actors continue to evolve.