Topic
Threat Intelligence

CTI Roundup: Malicious PyPI Packages Bypass Firewalls
PyPI packages use Cloudflare tunnels to bypass firewalls, new Raspberry Robin malware variant targets financial institutions in Portugal and Spain, and IcedID malware strikes again.

Rising Trend in APT Hackers Using Excel Add-ins as Intrusion Vector
APT hackers turn to malicious Excel add-ins as initial intrusion vector, PurpleUrchin bypasses CAPTCHA and steals cloud platform resources, and Russia’s Turla APT piggybacks on other hackers’ USB infections

Attackers Turn to SVG Files to Distribute QBot Malware
How hackers are using SVG files to smuggle QBot malware onto Windows systems, a new batch of ransomware families leading attacks on Windows systems, and this year’s spike in command-and-control servers.

Machine Learning. Security Friend or Foe?
Recent advancements in machine learning, the latest on Black Proxies, and the DHS Cyber Safety Board’s plan to review Lapsus$ gang’s hacking tactics.

Qakbot Malware Attacks on the Rise: Cyber Threat Intelligence Roundup
An aggressive Qakbot/Black Basta campaign that’s targeting US organizations, the US ban on Huawei, Hikvision, ZTE, and Dahua equipment, and a new report that links Chrome, Defender, and Firefox exploitation frameworks to a Spanish IT firm.

‘Tis the Season for a New Phishing Scam: Cyber Threat Intelligence Roundup
Organizations prioritize third-party risk management and gauge their own third-party security postures, Chinese hackers use Google Drive to drop malware, and a new phishing kit targets US shoppers this holiday season.

Australia Considers Ban on Ransomware Payments: Cyber Threat Intelligence Roundup
A new APT41 subgroup, Australia’s plan to ban ransomware payments, and Twitter’s mounting security woes.

Info-stealing Malware in Software Supply Chains: Cyber Threat Intelligence Roundup
Info-stealing malware in software supply chains and key findings from KELA’s latest cybercrime prevention report.

New Solutions for Addressing Software Supply Chain Attacks - Cyber Threat Intelligence Roundup
A pro-China disinformation campaign targeting US elections, Google’s new GUAC open-source project, and the ongoing debate about password expiration.

Zimbra Zero-Day Flaw: Cyber Threat Intelligence Roundup
Zimbra’s new zero-day flaw, a Ursnif malware variant focuses on ransomware and data theft, and a stealthy PowerShell backdoor disguises itself as a Windows update.

Emotet Malware Resurfaces: Cyber Threat Intelligence Roundup
The resurgence of Emotet, the evolution of IcedID, and the new Alchimist framework targeting Windows, macOS, and Linux

Business Email Compromise Attacks on the Rise: Cyber Threat Intelligence Roundup
The rising trend of business email compromise, the latest on the popular Bumblebee loader, and an overview of fake Microsoft Exchange ProxyNotShell exploits, which are now for sale on GitHub.