Click here to download all references as Bib-File.•
| 2025-11-11
⋅
Botcrawl
⋅
National Civil Service Commission of Colombia Data Breach Exposes 2.9 TB of Government Files Kazu |
| 2025-11-10
⋅
Mandiant
⋅
No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480 UNC6485 |
| 2025-11-10
⋅
Genians
⋅
State-Sponsored Remote Wipe Tactics Targeting Android Devices Quasar RAT Remcos |
| 2025-11-05
⋅
ESET Research
⋅
ESET APT Activity Report (April 2025 – September 2025): Russia-Aligned APTs Ramp Up Attacks Against Ukraine and Its Strategic Partners BACKORDER BloodAlchemy ImprudentCook RokRAT ScoringMathTea |
| 2025-11-05
⋅
Google
⋅
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools PromptLock UNC1069 |
| 2025-11-05
⋅
Huntress Labs
⋅
Gootloader Returns: What Goodies Did They Bring? GootLoader MeowBackConn Supper |
| 2025-11-04
⋅
The Record
⋅
Treasury sanctions 8 for laundering North Korea earnings from cybercrime, IT worker scheme |
| 2025-11-04
⋅
Twitter (@nextronresearch)
⋅
Tweet about BQT ransomware on Linux BQTlock |
| 2025-11-03
⋅
Breached Company
⋅
When the Defenders Become the Attackers: Cybersecurity Experts Indicted for BlackCat Ransomware Operations BlackCat BlackCat |
| 2025-11-03
⋅
Seqrite
⋅
Operation Peek-a-Baku: Silent Lynx APT makes sluggish shift to Dushanbe Laplas (Reverseshell) SilentSweeper YoroTrooper |
| 2025-11-02
⋅
Symantec
⋅
Multi-Stage In-Memory Agent Tesla Campaign Targets LATAM Agent Tesla |
| 2025-10-31
⋅
Seqrite
⋅
Operation SkyCloak: Tor Campaign targets Military of Russia & Belarus |
| 2025-10-31
⋅
Expel
⋅
Certified OysterLoader: Tracking Rhysida ransomware gang activity via code-signing certificates Broomstick |
| 2025-10-30
⋅
Github (cocomelonc)
⋅
Malware development trick 54: steal data via legit Angelcam API. Simple C example |
| 2025-10-30
⋅
Arctic Wolf
⋅
UNC6384 Weaponizes ZDI-CAN-25373 Vulnerability to Deploy PlugX Against Hungarian and Belgian Diplomatic Entities PlugX |
| 2025-10-29
⋅
01xyris
⋅
Aura Stealer #2 beatin the obfuscation Aura Stealer |
| 2025-10-29
⋅
Palo Alto Networks Unit 42
⋅
Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack Airstalk CL-STA-1009 |
| 2025-10-29
⋅
Qianxin
⋅
Smoking Gun Uncovered: RPX Relay at PolarEdge’s Core Exposed PolarEdge |
| 2025-10-28
⋅
ThreatFabric
⋅
New Android Malware Herodotus Mimics Human Behaviour to Evade Detection |
| 2025-10-27
⋅
Trend Micro
⋅
Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C Water Saci |