Skip to main content
← All Articles

Category

Threat Intel

1600 articles

Advertisement

HIGH
Threat Intel

Telegram tdata Credential Harvesting: Risks and Mitigation Strategies

Learn how threat actors exploit Telegram Desktop tdata folders for session hijacking and credential harvesting, bypassing multi-factor authentication.

Runtime Rebel Intel
3 min read · Apr 22, 2026
Microsoft Defender Binaries Exploited as Attack Tools
MEDIUM
Threat Intel

Microsoft Defender Binaries Exploited as Attack Tools

Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.

Runtime Rebel Intel
3 min read · Apr 22, 2026
Mustang Panda Targets Indian Banks with New LOTUSLITE Variant
HIGH
Threat Intel

Mustang Panda Targets Indian Banks with New LOTUSLITE Variant

Mustang Panda deploys a new LOTUSLITE malware variant against Indian financial institutions and South Korean policy entities for cyber espionage operations.

Runtime Rebel Intel
3 min read · Apr 22, 2026
BlackCat Ransomware Negotiator Scheme: Insider Threat Implications
MEDIUM
Threat Intel

BlackCat Ransomware Negotiator Scheme: Insider Threat Implications

A ransomware negotiator's guilty plea in a BlackCat scheme highlights critical insider threat risks and the importance of stringent controls in ransom payment processes.

Runtime Rebel Intel
5 min read · Apr 22, 2026
MEDIUM
Threat Intel

Scattered Spider Member Tylerb Pleads Guilty: Smishing Analysis

Tyler Robert Buchanan's guilty plea exposes Scattered Spider smishing tactics that compromised 12+ tech firms and stole millions in cryptocurrency.

Runtime Rebel Intel
4 min read · Apr 22, 2026
INFO
Threat Intel

Security Expert Aids BlackCat Ransomware, Exposing IR Risks

A US security expert pleaded guilty to collaborating with the BlackCat ransomware group, leveraging his negotiation role.

Runtime Rebel Intel
5 min read · Apr 21, 2026

Advertisement

SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
HIGH
Threat Intel

SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware

Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.

Runtime Rebel Intel
3 min read · Apr 21, 2026
Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks
HIGH
Threat Intel

Angelo Martino Pleads Guilty to Aiding BlackCat Ransomware Attacks

Angelo Martino pleaded guilty to collaborating with BlackCat (ALPHV) ransomware operators, facilitating credential-based breaches and high-stakes negotiations.

Runtime Rebel Intel
3 min read · Apr 21, 2026
INFO
Threat Intel

Grupo Seguritech: Risks of Mexico’s Surveillance Expansion

An analysis of Grupo Seguritech's expansion into the US market, evaluating the security and privacy implications of international surveillance infrastructure.

Runtime Rebel Intel
4 min read · Apr 21, 2026
Chinese APT Targeting Indian Banks and Korean Policy Circles
HIGH
Threat Intel

Chinese APT Targeting Indian Banks and Korean Policy Circles

Chinese state-sponsored threat actors are conducting cyber-espionage against Indian financial institutions and South Korean policy entities using recycled TTPs.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Threat Intel

Insider Threat: Former Negotiator Pleaded Guilty to BlackCat Attacks

A former cybersecurity negotiator at DigitalMint has pleaded guilty to conducting BlackCat (ALPHV) ransomware attacks against U.S. organizations.

Runtime Rebel Intel
4 min read · Apr 21, 2026
INFO
Threat Intel

Satoshi Nakamoto Identity: Adam Back and Bitcoin's Origins

Explores the resurfaced speculation that Adam Back is Satoshi Nakamoto, examining the evidence and implications for Bitcoin's ethos.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Threat Intel

KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group

KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.

Runtime Rebel Intel
4 min read · Apr 21, 2026
WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies
MEDIUM
Threat Intel

WhatsApp Metadata Leak: Exposure Risks and Mitigation Strategies

WhatsApp's metadata leakage allows strangers to infer limited user information without interaction, potentially aiding targeted social engineering or other malicious…

Runtime Rebel Intel
5 min read · Apr 20, 2026
INFO
Threat Intel

Scattered Spider Member Tyler Buchanan Pleads Guilty in US

Tyler Buchanan, a British national linked to the Scattered Spider cybercrime group, pleaded guilty in the US to charges of hacking, fraud, and cryptocurrency theft.

Runtime Rebel Intel
4 min read · Apr 20, 2026
MEDIUM
Threat Intel

Beyond Backups: Essential BCDR for Ransomware & Operational Resilience

Learn why traditional data backups are insufficient for business continuity. This analysis highlights the critical role of BCDR in mitigating ransomware and outage…

Runtime Rebel Intel
5 min read · Apr 20, 2026
HIGH
Threat Intel

Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs & Mitigations

Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.

Runtime Rebel Intel
4 min read · Apr 20, 2026
Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks
HIGH
Threat Intel

Vercel Breach and QEMU Abuse: Analyzing Modern Trust-Based Attacks

Analysis of the Vercel infrastructure compromise, QEMU-based evasion techniques, and the rise of Android RATs leveraging update channels for delivery.

Runtime Rebel Intel
4 min read · Apr 20, 2026
ZionSiphon Malware: Detecting OT Threats to Israeli Water Systems
HIGH
Threat Intel

ZionSiphon Malware: Detecting OT Threats to Israeli Water Systems

ZionSiphon malware targets Israeli water treatment and desalination infrastructure, establishing persistence and scanning local subnets for OT services.

Runtime Rebel Intel
4 min read · Apr 20, 2026
MEDIUM
Threat Intel

Apple ID Alerts Abused for Phishing via Legitimate Servers

Threat actors are exploiting Apple's account notification system to send authentic-looking phishing emails that bypass traditional spam filters and SPF checks.

Runtime Rebel Intel
4 min read · Apr 19, 2026
MEDIUM
Threat Intel

Tycoon 2FA Market Shift: Fragmentation and the Rise of Dadsec

Analysis of Tycoon 2FA's declining market share as threat actors reuse its technical artifacts in Dadsec and other phishing-as-a-service platforms.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack
MEDIUM
Threat Intel

Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack

Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet
HIGH
Threat Intel

Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet

Security researchers identify Nexcorium, a new Mirai variant targeting TBK DVRs and EoL TP-Link routers via CVE-2024-3721 for large-scale DDoS attacks.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA
MEDIUM
Threat Intel

Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA

Tycoon 2FA Phishers are now leveraging device code phishing to bypass multi-factor authentication, granting them unauthorized account access.

Runtime Rebel Intel
5 min read · Apr 18, 2026