Skip to main content

Topic

Threat Intelligence

CTI Roundup: Malicious PyPI Packages Bypass Firewalls
Jan 18, 2023

PyPI packages use Cloudflare tunnels to bypass firewalls, new Raspberry Robin malware variant targets financial institutions in Portugal and Spain, and IcedID malware strikes again.

Rising Trend in APT Hackers Using Excel Add-ins as Intrusion Vector
Jan 12, 2023

APT hackers turn to malicious Excel add-ins as initial intrusion vector, PurpleUrchin bypasses CAPTCHA and steals cloud platform resources, and Russia’s Turla APT piggybacks on other hackers’ USB infections

Attackers Turn to SVG Files to Distribute QBot Malware
Dec 19, 2022

How hackers are using SVG files to smuggle QBot malware onto Windows systems, a new batch of ransomware families leading attacks on Windows systems, and this year’s spike in command-and-control servers.

Machine Learning. Security Friend or Foe?
Dec 14, 2022

Recent advancements in machine learning, the latest on Black Proxies, and the DHS Cyber Safety Board’s plan to review Lapsus$ gang’s hacking tactics.

Qakbot Malware Attacks on the Rise: Cyber Threat Intelligence Roundup
Dec 7, 2022

An aggressive Qakbot/Black Basta campaign that’s targeting US organizations, the US ban on Huawei, Hikvision, ZTE, and Dahua equipment, and a new report that links Chrome, Defender, and Firefox exploitation frameworks to a Spanish IT firm.

‘Tis the Season for a New Phishing Scam: Cyber Threat Intelligence Roundup
Nov 30, 2022

Organizations prioritize third-party risk management and gauge their own third-party security postures, Chinese hackers use Google Drive to drop malware, and a new phishing kit targets US shoppers this holiday season.

Australia Considers Ban on Ransomware Payments: Cyber Threat Intelligence Roundup
Nov 21, 2022

A new APT41 subgroup, Australia’s plan to ban ransomware payments, and Twitter’s mounting security woes.

Info-stealing Malware in Software Supply Chains: Cyber Threat Intelligence Roundup
Nov 8, 2022

Info-stealing malware in software supply chains and key findings from KELA’s latest cybercrime prevention report.

New Solutions for Addressing Software Supply Chain Attacks - Cyber Threat Intelligence Roundup
Nov 4, 2022

A pro-China disinformation campaign targeting US elections, Google’s new GUAC open-source project, and the ongoing debate about password expiration.

Zimbra Zero-Day Flaw: Cyber Threat Intelligence Roundup
Oct 25, 2022

Zimbra’s new zero-day flaw, a Ursnif malware variant focuses on ransomware and data theft, and a stealthy PowerShell backdoor disguises itself as a Windows update.

Emotet Malware Resurfaces: Cyber Threat Intelligence Roundup
Oct 18, 2022

The resurgence of Emotet, the evolution of IcedID, and the new Alchimist framework targeting Windows, macOS, and Linux

Business Email Compromise Attacks on the Rise: Cyber Threat Intelligence Roundup
Oct 11, 2022

The rising trend of business email compromise, the latest on the popular Bumblebee loader, and an overview of fake Microsoft Exchange ProxyNotShell exploits, which are now for sale on GitHub.