Advertisement
DoJ Disrupts 3 Million-Device Botnets Behind 31.4 Tbps DDoS Attacks
The DoJ disrupted C2 infrastructure for major IoT botnets AISURU and Kimwolf, which were responsible for record-breaking 31.4 Tbps DDoS attacks.
DOJ Disrupts Aisuru, Kimwolf, JackSkid, and Mossad IoT Botnets
Federal authorities dismantle infrastructure for four major IoT botnets controlling 3 million devices used in record-breaking DDoS attacks worldwide.
Architectural Security Risks of MCP in LLM Environments
Explore architectural security risks introduced by MCP in Large Language Model environments, deemed unpatchable and requiring fundamental redesigns for future safety.
1stProtect's Behavioral Endpoint Security Emerges
1stProtect launches with $20M funding, offering an endpoint security platform that uses behavioral monitoring and user intent verification to stop real-time cyberattacks.
Bitrefill Attributes Cyberattack to North Korean Lazarus Group
Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.
Cobalt Strike and Vidar Infrastructure: 2025 Year in Review Analysis
Recorded Future’s 2025 report analyzes Cobalt Strike C2 trends, Vidar infostealer infrastructure, and the rise of AI-driven malicious hosting patterns.
Advertisement
Iranian Cyber Infrastructure Hardening Ahead of Operation Epic Fury
Analysis of Iran's six-month buildup of US-based shell companies and resilient cyber infrastructure to survive kinetic strikes and maintain hacking operations.
APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit
Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.
FBI Seizes Handala Infrastructure Following Stryker Cyberattack
The FBI dismantled Handala hacktivist infrastructure after a destructive attack on Stryker wiped 80,000 devices. Learn about these wiping TTPs.
FortiGate RaaS and Citrix Exploits: Defensive Analysis of New TTPs
An analysis of the latest ThreatsDay bulletin covering FortiGate RaaS, Citrix exploits, and LiveChat phishing lures targeting perimeter security.
DJI Romo Remote Camera Access via MQTT Vulnerability
An MQTT misconfiguration in DJI Romo vacuums allows unauthorized remote control and camera access for 7,000 devices. Learn the risks and mitigation steps.
Raven Emerges From Stealth with $20M for Runtime Security
Raven secures $20M in funding to launch a runtime application security platform designed to detect anomalous behavior and block sophisticated cyberattacks.
DarkSword iOS Exploit Kit: Full Takeover via 6 Flaws and 3 Zero-Days
Analysis of DarkSword, a sophisticated iOS exploit kit using six vulnerabilities, including three zero-days, for state-sponsored surveillance and data theft.
EU Sanctions China and Iran Entities Over APT31 Cyber Operations
The European Union imposes sanctions on Chinese and Iranian entities linked to APT31 and state-sponsored cyber espionage targeting democratic institutions.
Analysis of 'iranbot' Message in Cowrie Honeypot Logs
A peculiar 'iranbot_was_here' message, alongside Telnet logins and portscans, was observed in Cowrie honeypot logs, signaling potential reconnaissance activity.
Hardening Endpoint Management Systems: CISA Alert on Intune Attacks
CISA warns of active cyberattacks targeting endpoint management systems, specifically Microsoft Intune.
DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users
DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…
XBOW: AI-Powered Offensive Security Reshapes Vulnerability Discovery
XBOW, an autonomous offensive security firm, secured $120M, reaching a $1B+ valuation. Explore its AI-powered platform for vulnerability discovery and validation.
Machine-Speed Attacks: The Failure of Predictive Security Models
Analysis of why predictive security models fail against machine-speed attacks and the technical shift toward preemptive security strategies for defenders.
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs
US Treasury sanctions North Korea's IT worker network used to fund WMD programs. Learn how these actors use fake identities and how to secure remote hiring.
Adminer & phpMyAdmin: Attacker Scans Target Database Management Tools
Runtime Rebel observes increased honeypot scans targeting Adminer and phpMyAdmin.
DarkSword iOS Exploit Chain: Analyzing Multi-Actor Zero-Day Campaigns
Analysis of the DarkSword iOS exploit chain, used by multiple actors to deploy GHOSTBLADE and GHOSTKNIFE malware via zero-day vulnerabilities in iOS 18.7.
SideWinder APT Expands Southeast Asia Espionage Campaign
SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.
DarkSword iOS Exploit Kit: Analysis of State-Sponsored Spyware Chains
Analysis of the DarkSword exploit kit targeting six iOS vulnerabilities for state-sponsored surveillance and full device compromise via WebKit exploits.