Click here to download all references as Bib-File.•
2024-11-06
⋅
YouTube ( Hexacon)
⋅
Caught in the wild - Past, present and future |
2024-10-31
⋅
Microsoft
⋅
Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network |
2024-10-29
⋅
Microsoft
⋅
Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files |
2024-10-28
⋅
Google
⋅
Hybrid Russian Espionage and Influence Campaign Aims to Compromise Ukrainian Military Recruits and Deliver Anti-Mobilization Narratives CraxsRAT Pronsis Loader PureLogs Stealer |
2024-10-24
⋅
Seqrite
⋅
Operation Cobalt Whisper: Threat Actor Targets Multiple Industries Across Hong Kong and Pakistan Cobalt Strike Operation Cobalt Whisper |
2024-10-24
⋅
Datadog
⋅
Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview BeaverTail InvisibleFerret |
2024-10-23
⋅
Cisco Talos
⋅
Threat Spotlight: WarmCookie/BadSpace Cobalt Strike csharp-streamer RAT WarmCookie |
2024-10-22
⋅
Cisco Talos
⋅
Threat actor abuses Gophish to deliver new PowerRAT and DCRAT PowerRAT |
2024-10-22
⋅
Twitter (@threatinsight)
⋅
Twitter Thread attributing Voldemort to TA415 (APT41, BrassTyphoon) Voldemort |
2024-10-17
⋅
Microsoft Security
⋅
New macOS vulnerability, “HM Surf”, could lead to unauthorized data access |
2024-10-15
⋅
⋅
Weixin
⋅
Analysis of the attack activities of APT-C-35 (belly brain worm) against a manufacturing company in South Asia Unidentified 117 (Donot Loader) |
2024-10-09
⋅
Recorded Future
⋅
Outmaneuvering Rhysida: How Advanced Threat Intelligence Shields Critical Infrastructure from Ransomware Broomstick Rhysida |
2024-10-09
⋅
Palo Alto
⋅
Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware beavertail Beavertail |
2024-10-06
⋅
Google
⋅
Caught in the wild - Past, present and future |
2024-09-30
⋅
X (@GenThreatLabs)
⋅
Tweet on FAKEUPDATES pushing WARMCOOKIE backdoor via compromised websites targeting France FAKEUPDATES WarmCookie |
2024-09-26
⋅
Microsoft
⋅
Storm-0501: Ransomware attacks expanding to hybrid cloud environments Storm-0501 |
2024-09-18
⋅
Twitter (@MsftSecIntel)
⋅
Tweet about threat actor Vanilla Tempest INC GootLoader Storm-0494 |
2024-09-06
⋅
splunk
⋅
Handala’s Wiper: Threat Analysis and Detections Handala Hatef Handala |
2024-09-05
⋅
Fortinet
⋅
Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401 SideWalk |
2024-08-30
⋅
Microsoft
⋅
North Korean threat actor Citrine Sleet exploiting Chromium zero-day FudModule |