Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-02-26 ⋅ kmsec ⋅ Kieran Miyamoto
Novel DPRK stager using Pastebin and text steganography
2026-02-25 ⋅ RedPacket Security ⋅ RedPacket Security
[SHADOWBYT3$] – Ransomware Victim: UMSA
ShadowByt3$
2026-02-25 ⋅ Google ⋅ Google Threat Intelligence Group, Mandiant
Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign
GRIDTIDE UNC2814
2026-02-25 ⋅ Cisco Talos ⋅ Cisco Talos
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
UAT-8616
2026-02-25 ⋅ Google ⋅ 0verfl0w_, Anton Chuvakin, Bob Mechler, Crystal Lister, Eduardo Mattos, Google, Jason Bisson, Joachim Metz, John Stone, Jorge Blanco, Keith Lunden, Lia Wertheimer, Matthew Siuda, Michael Robinson, Muhammad Muneer, Noah McDonald, Ollie Green, Seth Rosenblatt
Cloud Threat Horizons Report: H1 2026
UNC6426
2026-02-25 ⋅ Hive Pro ⋅ Hive Pro
SANDWORM_MODE: npm Supply Chain Attack Targeting AI Development Tools
2026-02-25 ⋅ FortiGuard Labs ⋅ Ariel Davidpur
Unmasking Agent Tesla: A Deep Dive into a Multi-Stage Campaign
Agent Tesla
2026-02-25 ⋅ Abstract Security ⋅ Abstract Security Threat Research Organization (ASTRO)
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1
BeaverTail PylangGhost GolangGhost
2026-02-25 ⋅ Twitter (@anyrun_app) ⋅ Achmad Adhikara, ANY.RUN
Tweet about KarstoRAT
KarstoRAT
2026-02-24 ⋅ Microsoft ⋅ Microsoft Defender Experts
Developer-targeting campaign using malicious Next.js repositories
StoatWaffle
2026-02-24 ⋅ BlueVoyant ⋅ Joshua Green, Patrick Mchale
Mercenary Akula Hits Ukraine-Supporting Financial Institution
RMS
2026-02-24 ⋅ Symantec ⋅ Threat Hunter Team
North Korean Lazarus Group Now Working With Medusa Ransomware
ComeBacker Medusa
2026-02-24 ⋅ abuse.ch ⋅ abuse.ch
MalwareBazaar | SHA256 63deffbdd4053a38c95221589cc2ddd0595d451808a79432fa9f5476c4542390 (WalkLoader)
WalkLoader
2026-02-23 ⋅ Twitter (@Manu_De_Lucia) ⋅ Emanuele De Lucia
Tweet about IronZero
IronZero
2026-02-23 ⋅ ⋅ DisInfo ⋅ DisInfo
Technical attack, public discredit and isolation! The history of an IT company in Moldova, pushed outside the European market
2026-02-23 ⋅ abuse.ch ⋅ abuse.ch
MalwareBazaar | SHA256 be2db69fbde37ce4b0dbd51a85cb18f78a1bfda70ef2f4ed7dcde75051f3659b (RatonRAT)
RatonRAT
2026-02-22 ⋅ Securite360.net ⋅ Muffin
OPSEC on a Budget: What BadAudio Reveals About APT24
BADAUDIO
2026-02-22 ⋅ kmsec ⋅ Kieran Miyamoto
Tracking DPRK operator IPs over time
2026-02-21 ⋅ kmsec ⋅ Kieran Miyamoto
DPRK tests Google Drive as a malware stager
2026-02-19 ⋅ Elastic ⋅ Elastic Security Labs, Salim Bitam
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites
AstarionRAT