Skip to main content
← All Articles

Category

Threat Intel

1439 articles

Advertisement

Ghostwriter Targets Ukraine Government with Prometheus Phishing
HIGH
Threat Intel

Ghostwriter Targets Ukraine Government with Prometheus Phishing

Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware. Learn detection and…

Runtime Rebel Intel
4 min read · May 22, 2026
Dismantling First VPN: Global Takedown of Ransomware Infrastructure
HIGH
Threat Intel

Dismantling First VPN: Global Takedown of Ransomware Infrastructure

Authorities dismantle First VPN Service, a critical infrastructure hub used by 25 ransomware groups for masking data theft and DDoS attacks.

Runtime Rebel Intel
4 min read · May 22, 2026
Verizon DBIR 2024: Healthcare Targeted by Social Engineering
HIGH
Threat Intel

Verizon DBIR 2024: Healthcare Targeted by Social Engineering

An analysis of the 2024 Verizon DBIR healthcare findings, highlighting the surge in social engineering, ransomware, and supply chain vulnerabilities.

Runtime Rebel Intel
3 min read · May 22, 2026
TH
MEDIUM
Threat Intel

Tech Support Fraud: Executives Plead Guilty in Infrastructure Case

Former executives of CallerReady plead guilty to facilitating global tech support scams by providing call-tracking and CRM infrastructure to fraudsters.

Runtime Rebel Intel
3 min read · May 22, 2026
Webworm Group Exploits Discord and MS Graph to Target EU Governments
HIGH
Threat Intel

Webworm Group Exploits Discord and MS Graph to Target EU Governments

China-linked threat actor Webworm utilizes Discord and Microsoft Graph API for C2 infrastructure in a campaign targeting European government organizations.

Runtime Rebel Intel
4 min read · May 22, 2026
TH
HIGH
Threat Intel

FBI Disrupts First VPN Service Used by Ransomware Groups

The FBI and international partners dismantled First VPN, a specialized service used by dozens of ransomware groups for reconnaissance and intrusions.

Runtime Rebel Intel
4 min read · May 22, 2026
TH
MEDIUM
Threat Intel

Canadian Man Arrested for Kimwolf Botnet Operations

Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.

Runtime Rebel Intel
4 min read · May 22, 2026
Bypassing Hardware Gates: Exploitability of Vulnerable Drivers
HIGH
Threat Intel

Bypassing Hardware Gates: Exploitability of Vulnerable Drivers

Technical analysis of how researchers bypass hardware-gating to exploit Windows kernel-mode drivers without physical devices in BYOVD attacks.

Runtime Rebel Intel
4 min read · May 22, 2026
TH
HIGH
Threat Intel

US and Canada Charge Suspected KimWolf Botnet Operator

Authorities dismantle the KimWolf botnet following the arrest of a Canadian national linked to nearly two million global device infections and DDoS attacks.

Runtime Rebel Intel
4 min read · May 22, 2026
Kimwolf Botnet Operator Jacob Butler Arrested in DDoS-for-Hire Case
HIGH
Threat Intel

Kimwolf Botnet Operator Jacob Butler Arrested in DDoS-for-Hire Case

DOJ arrests Canadian operator of the Kimwolf botnet, a variant of the AISURU malware, used in large-scale DDoS-for-hire attacks against global targets.

Runtime Rebel Intel
3 min read · May 22, 2026
Communicating AI's Impact on Vulnerability Discovery to Boards
INFO
Threat Intel

Communicating AI's Impact on Vulnerability Discovery to Boards

Security leaders must articulate AI-driven vulnerability trends and strategic resource needs to their boards, translating technical risks into business impact.

Runtime Rebel Intel
5 min read · May 22, 2026
TH
MEDIUM
Threat Intel

Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation

Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.

Runtime Rebel Intel
4 min read · May 22, 2026
TH
INFO
Threat Intel

Linux Process-Specific HTTP Proxying: Tools and Analysis Gaps

Explores the utility of process-specific HTTP proxying for Linux debugging and reverse engineering, highlighting the absence of a generic solution akin to Proxifier.

Runtime Rebel Intel
5 min read · May 21, 2026
TH
INFO
Threat Intel

AI-Powered Threat Hunting: Claude Integration into Falcon Platform

Runtime Rebel analyzes CrowdStrike's new Claude AI integration into the Falcon Platform, enhancing threat hunting, incident response, and security operations with…

Runtime Rebel Intel
4 min read · May 21, 2026
TH
INFO
Threat Intel

Apple's App Store Fraud Prevention: Over $11B Blocked

Runtime Rebel analyzes Apple's disclosure of blocking $11B in App Store fraud over six years, detailing the ongoing fight against malicious apps.

Runtime Rebel Intel
4 min read · May 21, 2026
Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis
HIGH
Threat Intel

Linux Rootkits and Router Zero-Day Exploits: ThreatsDay Analysis

Recent intelligence highlights a surge in Linux rootkits and router zero-day vulnerabilities targeting trusted system components and AI-driven intrusions.

Runtime Rebel Intel
4 min read · May 21, 2026
Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy
HIGH
Threat Intel

Showboat Linux Malware Targets Middle East Telecom via SOCKS5 Proxy

Researchers discover Showboat, a modular Linux post-exploitation framework used in Middle East telecom attacks to establish persistent SOCKS5 proxy backdoors.

Runtime Rebel Intel
3 min read · May 21, 2026
Underminr Attack: How Attackers Hijack Trusted Brand CDNs
HIGH
Threat Intel

Underminr Attack: How Attackers Hijack Trusted Brand CDNs

The Underminr exploit allows threat actors to use CDN infrastructure to hijack brand reputation and cloak malicious traffic. Learn how to detect and mitigate.

Runtime Rebel Intel
4 min read · May 21, 2026
TH
INFO
Threat Intel

Ocean Launches Agentic AI Email Security Platform with $28M Funding

Ocean emerges from stealth with $28M to deploy specialized AI agents that simulate human reasoning to detect sophisticated phishing and BEC threats.

Runtime Rebel Intel
3 min read · May 21, 2026
TH
INFO
Threat Intel

Flipper One: The Evolution of Linux-Based Hardware Pentesting Tools

Flipper Devices announces the Flipper One, an open Linux platform. Analyze the security implications and defensive requirements for this modular hacking tool.

Runtime Rebel Intel
4 min read · May 21, 2026
TH
HIGH
Threat Intel

Police Seize First VPN Service Linked to Global Ransomware Attacks

International law enforcement dismantles First VPN, a bulletproof service used by threat actors for ransomware deployment and anonymous data exfiltration.

Runtime Rebel Intel
3 min read · May 21, 2026
AI in Cybersecurity: Weighing Risks, Benefits, and Defender Concerns
INFO
Threat Intel

AI in Cybersecurity: Weighing Risks, Benefits, and Defender Concerns

Analysis of cybersecurity professionals' perceptions on AI's dual role, exploring its potential to enhance defenses against evolving threats while acknowledging…

Runtime Rebel Intel
5 min read · May 21, 2026
TH
MEDIUM
Threat Intel

Ukraine Identifies Odesa-Based Infostealer Operator

Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.

Runtime Rebel Intel
3 min read · May 21, 2026
TH
INFO
Threat Intel

AI Security: Beyond Benchmarks, Towards Process-Driven Assurance

Traditional security benchmarks fail for AI. This analysis details the challenges in measuring AI security and advocates for process-driven risk management and vigilance.

Runtime Rebel Intel
5 min read · May 20, 2026