Click here to download all references as Bib-File.•
| 2026-01-28
⋅
Accenture
⋅
Analysis of RustyRocket – A Custom WorldLeaks Exfiltration Tool RustyRocket |
| 2026-01-28
⋅
Proofpoint
⋅
Can’t stop, won’t stop: TA584 innovates initial access XWorm TA584 |
| 2026-01-28
⋅
Google
⋅
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network |
| 2026-01-27
⋅
Google
⋅
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 |
| 2026-01-26
⋅
Trend Micro
⋅
PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups PeckBirdy GRAYRABBIT |
| 2026-01-22
⋅
Red Asgard
⋅
Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain StoatWaffle |
| 2026-01-20
⋅
Jamf
⋅
Threat Actors Expand Abuse of Microsoft Visual Studio Code StoatWaffle |
| 2026-01-20
⋅
Abstract Security
⋅
Contagious Interview: Tracking the VS Code Tasks Infection Vector BeaverTail InvisibleFerret |
| 2026-01-20
⋅
FalconFeeds
⋅
Inside Iran’s APT Network: Profiling the Most Active Iranian State‑Linked Threat Actors |
| 2026-01-16
⋅
sysdig
⋅
VoidLink threat analysis: Sysdig discovers C2-compiled kernel rootkits VoidLink |
| 2026-01-14
⋅
Microsoft
⋅
Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations |
| 2026-01-13
⋅
Spamhaus
⋅
Spamhaus Botnet Threat Update July to December 2025 Coper FluBot Joker Aisuru Mirai AsyncRAT BianLian Cobalt Strike DCRat Havoc Latrodectus PureLogs Stealer Quasar RAT Remcos Rhadamanthys Sliver ValleyRAT Venom RAT Vidar XWorm |
| 2026-01-09
⋅
flare
⋅
New Threat Actor Group PayTool Targets Canadians with Traffic Scams PayTool |
| 2026-01-03
⋅
Linkedin (Tammy H.)
⋅
Emerging Threat: The DeadFrog AV/EDR Killer |
| 2025-12-30
⋅
Koi Security
⋅
DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers DarkSpectre ShadyPanda |
| 2025-12-18
⋅
Proofpoint
⋅
Access granted: phishing with device code authorization for account takeover TA2723 UNK_AcademicFlare |
| 2025-12-18
⋅
Acronis
⋅
Acronis TRU Alliance {Hunt.io}: Hunting DPRK threats - New Global Lazarus & Kimsuky campaigns BADCALL POOLRAT Quasar RAT |
| 2025-12-16
⋅
sysdig
⋅
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2 EtherRAT |
| 2025-12-15
⋅
Amazon
⋅
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure |
| 2025-12-12
⋅
Google
⋅
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) ANGRYREBEL MINOCAT SNOWLIGHT Earth Lamia |