Topic
Threat Intelligence

CTI Roundup: Microsoft Warns About Mercury and DEV-1084 Attacks on Hybrid Environments
Microsoft’s security advisory on Mercury and DEV-1084 and a report linking Russian hackers to attacks against NATO and the EU.

CTI Roundup: Threat Actors Use Self-Extracting (SFX) Archives for Backdoor Attacks
A new SFX exploit enables stealthy backdoor attacks, an ALPHV ransomware affiliate is targeting Veritas Backup Exec, and CTI tracks the emergence of Rorschach ransomware.

CTI Roundup: How Weak is Your Password?
Key findings from the Specops 2023 Weak Password Report, a look at the recently exposed APT43 hacking group, and a breakdown of the New AlienFox toolkit.

Finding and Fixing the Trojanized 3CX DesktopApp
Customers of the popular 3CX voice and video calling desktop application should be on high alert. Here's how Tanium can help.

CTI Roundup: New CISA tool detects hacking activity in Microsoft cloud services
A joint advisory on LockBit 3.0 ransomware, CISA’s latest tool which detects hacking activity in Microsoft cloud services, and ScarCruft’s evolving arsenal.

CTI Roundup: US Federal Agency Hacked Using Telerik
Hackers used the Telerik bug to breach a US federal agency, a suspected Chinese actor used the Fortinet zero-day along with custom malware to engage in cyberespionage, and the Tick advanced persistent threat (APT) group targeted the customers of an East Asian data loss prevention (DLP) company.

CTI Roundup: FBI and CISA Issue Royal Ransomware Warning
A joint FBI and CISA advisory on Royal ransomware, Sharp Panda’s new malware variant, and an update on IceFire ransomware.

CTI Roundup: Threat Actors Exploiting ChatGPT
Hackers use fake ChatGPT apps to push Windows and Android malware, attackers flood NPM repository with over 15,000 spam packages containing phishing links, and New Stealc malware emerges with a wide set of stealing capabilities.

CTI Roundup: Business Email Compromise Groups Go Global
BEC groups target companies worldwide, RedEyes hackers use new malware to steal data, and Devs targeted by W4SP Stealer malware in malicious PyPI packages.

CTI Roundup: ESXiArgs Ransomware Attacks Target VMware
The latest on ESXiArgs ransomware attacks, new QakNote attacks pushing QBot malware via Microsoft OneNote files, and Biden’s attention to data privacy in the State of the Union.

CTI Roundup: Threat Actors Use Sliver C2 Framework
Sliver’s growing popularity as an open-source C2 framework, Emotet’s comeback and new evasion techniques, and how Chinese hackers exploited a Fortinet flaw using a 0-Day.

CTI Roundup: Ransomware Profits Drop as Attacks Remain High
Reporting revealed declining ransomware profits in 2022, a new backdoor based on the CIA’s Hive malware is discovered, and a new wave of BackdoorDiplomacy attacks are targeting Iranian government entities.