Advertisement
FIRESTARTER Backdoor Exploits Cisco Firepower ASA Software
CISA and NCSC reveal FIRESTARTER, a persistent backdoor targeting Cisco Firepower devices running ASA software, used in federal agency compromises.
AI-Powered Phishing Surges: Defending Against Advanced Attacks
Explore the surge in AI-powered phishing, how threat actors are leveraging it for personalized attacks, and critical defensive strategies for organizations.
Beyond Code Security: Managing Your Expanding Attack Surface
Organizations often overlook security gaps in shadow IT, SaaS, and AI agents. Learn to manage an expanding attack surface beyond just secure code.
Fast16 Sabotage Malware: Precursor to State-Sponsored Cyber Warfare
Analysis of Fast16, a pre-Stuxnet sabotage malware linked to US-Iran cyber tensions, designed to tamper with high-precision calculation software results.
Chinese Spear-Phishing Campaign Targets NASA Defense Software
NASA OIG reveals a multi-year spear-phishing campaign by a Chinese national impersonating researchers to exfiltrate sensitive U.S. defense software.
UNC6692 Social Engineering: Deploying the SNOW Custom Malware Suite
UNC6692 leverages Microsoft Teams and S3-hosted payloads to deploy the SNOW modular malware ecosystem, targeting enterprise Windows environments.
Tropic Trooper APT Targets Home Routers and Japanese Infrastructure
Tropic Trooper expands operations to target Japanese entities and home routers using specialized malware like Chinoiserie to obfuscate attack origins.
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.
UNC6692 Impersonates IT Helpdesk to Deploy SNOW Malware via Teams
UNC6692 threat actors are impersonating IT helpdesk staff via Microsoft Teams to deliver custom SNOW malware, highlighting risks in SaaS messaging apps.
Building Digital Trust: The Imperative of Cyber Threat Intelligence
Explore how cyber threat intelligence and collaboration cultivate digital trust, enabling secure innovation and proactive defense against evolving threats.
State-Sponsored Cyber Operations Targeting Critical Mineral Supply Chains
Geopolitical tensions over critical minerals fuel a rising threat of state-sponsored cyber operations targeting the global mining sector and supply chains.
Chinese APT Leverages PlugX & ShadowPad with Cloud C2 for Mongolian Espionage
A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…
AI in Vulnerability Discovery: 360 Digital Security Group's Claims Examined
Runtime Rebel examines 360 Digital Security Group's claims of using AI to discover over 1,000 vulnerabilities, including at Tianfu Cup, and the implications for security…
Analyzing the $290M DeFi Breach and macOS LotL Exploitation
An analysis of the $290 million DeFi protocol hack, macOS living-off-the-land techniques, and ProxySmart SIM farming operations identified in recent reports.
China-Nexus Covert Networks: Defending Against SOHO-Based Botnets
CISA and international partners warn against the strategic use of SOHO and IoT botnets by China-nexus actors to mask malicious activity and target CNI.
iPhone Notification Database Forensic Extraction: Signal Privacy Risk
FBI forensic extraction recovered deleted Signal messages from the iOS notification database. Analyze the technical risks and learn how to secure your device.
Defensive Strategies for Routine Workflow Weaponization
Attackers are pivoting from technical exploits to weaponizing trusted workflows. Learn how to detect and mitigate these behavioral identity-based threats.
Rilian Secures $17.5M Seed for AI-Native Security Orchestration
Rilian raises $17.5 million to scale its AI-native security orchestration platform, aiming to automate complex SOC workflows and reduce alert fatigue.
GopherWhisper APT Abuses Outlook and Slack for Stealthy C2
Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.
Defeating Automated Exploitation in the Collapsing Exploit Window
AI-driven automation is accelerating the exploit lifecycle. Learn how the collapsing exploit window impacts vulnerability management and automated defense.
AI Impact on Vulnerability Management: Real-World Trends and Risks
Analyze how artificial intelligence impacts vulnerability research and discovery, separating industry hype from technical reality for security professionals.
Chinese Telegram Guarantee Marketplaces: Post-Huione Evolution
Analysis of Chinese-language Telegram marketplaces using guarantee services to facilitate money laundering and fraud following the Huione Guarantee shutdown.
The Gentlemen Ransomware Group: Rapid Escalation and Sophistication
An analysis of 'The Gentlemen' ransomware group, highlighting their rapid operational scaling and sophisticated attack methods impacting organizations globally.
ICE Deploys Graphite Spyware: Privacy Implications and Risks
U.S. Immigration and Customs Enforcement (ICE) uses Graphite spyware, raising privacy concerns for individuals and potential civil liberty issues. Understand the…