Click here to download all references as Bib-File.•
| 2026-04-10
⋅
Infoblox
⋅
Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers |
| 2026-04-07
⋅
Microsoft
⋅
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks |
| 2026-04-01
⋅
SOC Prime
⋅
UAC-0255 Attack Detection: Threat Actors Impersonate CERT-UA to Infect Ukrainian Public and Private Sector Organizations With AGEWHEEZE RAT AGEWHEEZE Cyber Serp |
| 2026-03-31
⋅
Google
⋅
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack WAVESHAPER |
| 2026-03-23
⋅
Sophos
⋅
NICKEL ALLEY strategy: Fake it ‘til you make it PylangGhost GolangGhost Nickel Alley |
| 2026-03-20
⋅
Nextron Systems
⋅
RegPhantom Backdoor Threat Analysis RegPhantom |
| 2026-03-18
⋅
Google
⋅
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors GHOSTBLADE |
| 2026-03-09
⋅
Abstract Security
⋅
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2 GolangGhost PylangGhost GolangGhost |
| 2026-03-07
⋅
OpenSourceMalware
⋅
PolinRider: DPRK Threat Actor Implants Malware in Hundreds of GitHub Repos JADESNOW |
| 2026-03-06
⋅
Microsoft
⋅
AI as tradecraft: How threat actors operationalize AI OtterCookie |
| 2026-03-05
⋅
Symantec
⋅
Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company Tsundere |
| 2026-03-05
⋅
eSentire
⋅
North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin') JADESNOW |
| 2026-03-04
⋅
Huntress Labs
⋅
"Malware, from the Outside!": How a Threat Actor Used Fake OpenClaw Installers to Infect Systems with GhostSocks and Information Stealers GhostSocks Vidar |
| 2026-03-03
⋅
Sophos
⋅
Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies APTIran |
| 2026-03-03
⋅
Google
⋅
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Coruna |
| 2026-03-03
⋅
Google
⋅
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Coruna UNC6353 UNC6691 |
| 2026-02-25
⋅
Google
⋅
Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign GRIDTIDE UNC2814 |
| 2026-02-25
⋅
Google
⋅
Cloud Threat Horizons Report: H1 2026 UNC6426 |
| 2026-02-25
⋅
Abstract Security
⋅
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1 BeaverTail PylangGhost GolangGhost |
| 2026-02-24
⋅
Symantec
⋅
North Korean Lazarus Group Now Working With Medusa Ransomware ComeBacker Medusa |