Skip to main content
← All Articles

Category

Threat Intel

1439 articles

Advertisement

TH
HIGH
Threat Intel

Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs & Mitigations

Microsoft warns of helpdesk impersonation attacks via Teams external collaboration. Understand TTPs for initial access, lateral movement, and critical mitigation…

Runtime Rebel Intel
4 min read · Apr 20, 2026
Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks
HIGH
Threat Intel

Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks

Analysis of the Vercel infrastructure compromise, QEMU-based evasion techniques, and the rise of Android RATs leveraging update channels for delivery.

Runtime Rebel Intel
4 min read · Apr 20, 2026
ZionSiphon Malware: Detecting OT Threats to Israeli Water Systems
HIGH
Threat Intel

ZionSiphon Malware: Detecting OT Threats to Israeli Water Systems

ZionSiphon malware targets Israeli water treatment and desalination infrastructure, establishing persistence and scanning local subnets for OT services.

Runtime Rebel Intel
4 min read · Apr 20, 2026
TH
MEDIUM
Threat Intel

Apple ID Alerts Abused for Phishing via Legitimate Servers

Threat actors are exploiting Apple's account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.

Runtime Rebel Intel
4 min read · Apr 19, 2026
TH
MEDIUM
Threat Intel

Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec

Analysis of Tycoon 2FA's declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack
MEDIUM
Threat Intel

Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack

Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet
HIGH
Threat Intel

Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet

Security researchers identify Nexcorium, a new Mirai variant targeting TBK DVRs and EoL TP-Link routers via CVE-2024-3721 for large-scale DDoS attacks.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA
MEDIUM
Threat Intel

Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA

Tycoon 2FA Phishers are now leveraging device code phishing to bypass multi-factor authentication, granting them unauthorized account access.

Runtime Rebel Intel
5 min read · Apr 18, 2026
NIST NVD Data Enrichment Cutbacks: Implications for Cyber Teams
INFO
Threat Intel

NIST NVD Data Enrichment Cutbacks: Implications for Cyber Teams

NIST's reduction in NVD CVE data enrichment poses challenges for cyber teams' vulnerability management. Learn the implications and proposed industry solutions.

Runtime Rebel Intel
5 min read · Apr 18, 2026
TH
INFO
Threat Intel

Addressing Shadow AI Risks: A Governance and Visibility Imperative

Enterprises face growing risks from unmanaged AI tool usage. This analysis details Shadow AI threats, compliance challenges, and crucial governance strategies.

Runtime Rebel Intel
4 min read · Apr 18, 2026
TH
INFO
Threat Intel

White House Engages AI Labs on Emerging AI Security Concerns

The White House is engaging leading AI labs like Anthropic to address security of AI models and software, highlighting growing concerns over AI safety and supply chain…

Runtime Rebel Intel
4 min read · Apr 18, 2026
TH
HIGH
Threat Intel

Grinex Crypto Exchange Suffers $13.7M Hack, Blames Intelligence

Kyrgyzstan's Grinex crypto exchange suspended operations after a $13.7M hack. The exchange attributes the breach to Western intelligence agencies, highlighting sector…

Runtime Rebel Intel
4 min read · Apr 18, 2026
TH
INFO
Threat Intel

Claude Mythos Preview: Anthropic Limits Access to Vulnerability AI

Anthropic restricts Claude Mythos Preview access to critical infrastructure providers due to its advanced capability to exploit zero-day vulnerabilities.

Runtime Rebel Intel
3 min read · Apr 17, 2026
TH
HIGH
Threat Intel

Scattered Spider Arrest and ShowDoc Vulnerability Exploitation

Analysis of the arrest of a Scattered Spider member, active exploitation of ShowDoc vulnerabilities, and the introduction of the Satellite Cybersecurity Act.

Runtime Rebel Intel
3 min read · Apr 17, 2026
Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads
INFO
Threat Intel

Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads

Google announces Android 17 privacy updates and Play policy changes after blocking 8.3 billion ads and 24.9 million fraudulent accounts throughout 2025.

Runtime Rebel Intel
4 min read · Apr 17, 2026
Business Impersonation Fraud: Analyzing Identity Gaps in 2024
MEDIUM
Threat Intel

Business Impersonation Fraud: Analyzing Identity Gaps in 2024

Analysis of how attackers exploit identity verification gaps to execute financial fraud and brand impersonation, from shell companies to AI-driven scams.

Runtime Rebel Intel
4 min read · Apr 17, 2026
TH
INFO
Threat Intel

CrowdStrike and OpenAI Partner to Enhance AI-Driven Threat Hunting

CrowdStrike and OpenAI introduce the Threat Analysis Center to leverage GPT-4o for defensive cybersecurity, incident response, and hunting automation.

Runtime Rebel Intel
3 min read · Apr 17, 2026
TH
HIGH
Threat Intel

ZionSiphon Malware Targets Israeli Water Treatment ICS

Security analysis of ZionSiphon, a backdoor malware targeting Israeli desalination and water treatment facilities via ICS vulnerabilities.

Runtime Rebel Intel
3 min read · Apr 17, 2026
Operation PowerOFF Seizes 53 DDoS Domains and 3M Criminal Accounts
INFO
Threat Intel

Operation PowerOFF Seizes 53 DDoS Domains and 3M Criminal Accounts

Operation PowerOFF disrupts DDoS-for-hire services by seizing 53 domains and exposing 3 million user accounts, marking a major blow to booter service providers.

Runtime Rebel Intel
4 min read · Apr 17, 2026
TH
INFO
Threat Intel

Public-Private Operational Collaboration for National Cyber Defense

An analysis of why government-private sector operational collaboration is essential for defending critical infrastructure against sophisticated threat actors.

Runtime Rebel Intel
3 min read · Apr 17, 2026
TH
INFO
Threat Intel

Operation PowerOFF: Global Takedown of 53 DDoS-for-Hire Domains

Law enforcement agencies seized 53 booter domains and identified 75,000 users in the latest phase of Operation PowerOFF targeting the DDoS-as-a-Service market.

Runtime Rebel Intel
3 min read · Apr 17, 2026
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
HIGH
Threat Intel

Sapphire Sleet's ClickFix: North Korea Targets macOS Users

North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data. Learn how to detect…

Runtime Rebel Intel
4 min read · Apr 16, 2026
TH
INFO
Threat Intel

OpenAI Widens GPT-5.4-Cyber Access Following Anthropic Mythos

OpenAI expands access to GPT-5.4-Cyber, a specialized model for defensive security, following Anthropic's Mythos release to aid security analysts.

Runtime Rebel Intel
3 min read · Apr 16, 2026
PowMix Botnet Targets Czech Workers via Randomized C2 Traffic
HIGH
Threat Intel

PowMix Botnet Targets Czech Workers via Randomized C2 Traffic

Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.

Runtime Rebel Intel
3 min read · Apr 16, 2026