Click here to download all references as Bib-File.•
| 2025-12-29
⋅
LinkedIn (Idan Tarab)
⋅
Active Spear-Phishing Campaign Targeting Israeli Security-Related Individuals — Infrastructure Linked to APT42 (Hashtag#CharmingKitten) |
| 2025-12-23
⋅
secpod
⋅
Zero-Day Crisis: CVE-2025-20393 Unpatched on Cisco Email Gateways, Exploited by China-Linked Hackers UAT-9686 |
| 2025-12-21
⋅
Genians
⋅
Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks RokRAT |
| 2025-12-19
⋅
PolySwarm Tech Team
⋅
Multiple Threat Actors Leveraging CVE-2025-55182 (React2Shell) ANGRYREBEL COMPOOD MINOCAT Mirai SNOWLIGHT XMRIG EtherRAT Cobalt Strike Mirai VShell xmrig JACKPOT PANDA |
| 2025-12-19
⋅
Intezer
⋅
Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs EchoGather |
| 2025-12-18
⋅
Proofpoint
⋅
Access granted: phishing with device code authorization for account takeover TA2723 UNK_AcademicFlare |
| 2025-12-18
⋅
HelpNetSecurity
⋅
Clipping Scripted Sparrow’s wings: Tracking a global phishing ring Scripted Sparrow |
| 2025-12-18
⋅
Acronis
⋅
Acronis TRU Alliance {Hunt.io}: Hunting DPRK threats - New Global Lazarus & Kimsuky campaigns BADCALL POOLRAT Quasar RAT |
| 2025-12-18
⋅
Gen Digital Inc
⋅
Gen Blogs | Defeating AuraStealer: Practical Deobfuscation Workflows for Modern Infostealers Aura Stealer |
| 2025-12-18
⋅
safebreach
⋅
Prince of Persia: A decade of Iranian Nation State APT Campaign Activity Infy Tonnerre |
| 2025-12-18
⋅
Cyderes
⋅
From Loader to Looter: ACR Stealer Rides on Upgraded CountLoader ACR Stealer CountLoader |
| 2025-12-18
⋅
BlackPoint
⋅
New MintsLoader Variant Using Hashtable Obfuscation MintsLoader |
| 2025-12-17
⋅
Cisco Talos
⋅
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager UAT-9686 |
| 2025-12-17
⋅
XLab
⋅
Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices Kimwolf Aisuru |
| 2025-12-16
⋅
sysdig
⋅
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2 EtherRAT |
| 2025-12-15
⋅
Squiblydoo
⋅
SolarMarker: Actions-On-Target solarmarker |
| 2025-12-15
⋅
StrikeReady
⋅
Russian APT actor phishes the Baltics and the Balkans |
| 2025-12-15
⋅
Bleeping Computer
⋅
French Interior Ministry confirms cyberattack on email servers |
| 2025-12-12
⋅
Google
⋅
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) ANGRYREBEL COMPOOD MINOCAT SNOWLIGHT Earth Lamia JACKPOT PANDA |
| 2025-12-11
⋅
Trend Micro
⋅
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics ROMCOM RAT SHADOW-VOID-042 |