Skip to main content

Topic

Emerging Issue

Desktop featured image: CTI blog 3 - wide

Astaroth trojan uses GitHub to host malware configurations, TA585 delivers MonsterV2 malware in phishing campaigns, and threat actors exploit Microsoft’s logo in tech support scams

Desktop featured image: CTI blog 1 - wide

XWorm malware reemerges with ransomware, Microsoft disrupts multiple threats targeting Teams, and Storm-1175 exploits a critical GoAnywhere MFT vulnerability

Desktop featured image: CTI blog 2 - wide

Check out the latest insights on DarkCloud malware, the “Trinity of Chaos” alliance, and WARMCOOKIE updates.

Desktop featured image: CTI blog 4 - wide

SystemBC botnet targets VPS infrastructure, ShinyHunters targets enterprise cloud applications, and a phishing campaign uses AI-generated code to avoid detection

Desktop featured image: CTI blog 2 - wide

Details from Tanium’s Guardian research team on CVE-2025-20333, -20362, and -20363—and RAYINITIATOR & LINE VIPER.

Desktop featured image: CTI blog 3

AMOS Stealer campaign targets macOS, TAG-150 deploys new CastleRAT malware, and GPUGate targets IT firms in Western Europe

Desktop featured image: CTI blog 1 - wide

The latest on HexStrike AI, TinkyWinkey’s keylogging, and Silver Fox APT’s driver abuse bypassing endpoint defenses.

Modernizing federal cryptography in the quantum age featured blog image

Quantum computing is no longer a distant threat. It’s now a real, operational risk to cybersecurity’s foundations.

Desktop featured image: CTI blog 2 - wide

New Linux malware evades antivirus detection, UNC5518 deploys CORNFLAKE.V3 using ClickFix and fake CAPTCHA pages, and a PRC-Nexus campaign hijacks web traffic.

Salesloft Drift Data Breach: What We Know and What We're Doing

Hackers breached Salesloft in a major data theft, stealing OAuth and refresh tokens from Drift AI.

Desktop featured image: CTI blog 4 - wide

Researchers uncover malicious Python packages, PipeMagic masquerades as a ChatGPT desktop app, and Noodlophile Stealer targets enterprises through social media

Desktop featured image: CTI blog 3 - wide

Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors