Click here to download all references as Bib-File.•
| 2026-06-08
⋅
SYGNIA
⋅
Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected |
| 2026-06-08
⋅
StepSecurity
⋅
The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent Shai-Hulud |
| 2026-06-04
⋅
RESIDENT.NGO
⋅
Case Study — UNC1151 Gmail Phishing (“Suspicious account activity”) Targeting Belarusian Pro-Democracy Politician, May 2026 |
| 2026-06-03
⋅
Check Point Research
⋅
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem AnimateClipper Remus |
| 2026-06-03
⋅
Microsoft
⋅
How Microsoft names threat actors Wisteria Tsunami |
| 2026-06-03
⋅
sonatype
⋅
Lazarus Group's Latest: Brandjacking Campaign on npm |
| 2026-06-02
⋅
Qualys
⋅
The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs CL-STA-1020 |
| 2026-06-01
⋅
ExaTrack
⋅
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 PixyNetLoader |
| 2026-05-31
⋅
Socket
⋅
Famous Chollima Targets PHP Developers Through Compromised Packagist Package JADESNOW |
| 2026-05-28
⋅
neso.re
⋅
ClickFix x HijackLoader: Dissecting a Live Stealer Campaign - Part 2 HijackLoader |
| 2026-05-28
⋅
eSentire
⋅
Nimbus RAT: How Threat Actors Are Abusing Microsoft Teams and Google Drive to Deploy a Java RAT |
| 2026-05-28
⋅
ESET Research
⋅
ESET APT Activity Report Q4 2025–Q1 2026 WAVESHAPER BirdCall BLINDINGCAN RokRAT Rook Tiger RAT |
| 2026-05-28
⋅
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations LegionRelay PhantomRelay |
| 2026-05-28
⋅
WithSecure
⋅
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations GreyVibe |
| 2026-05-28
⋅
LevelBlue
⋅
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign |
| 2026-05-27
⋅
Wiz.io
⋅
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure JINX-0164 |
| 2026-05-26
⋅
Intrinsec
⋅
Pivoting on a malspam infrastructure delivering JS malware backed by bulletproof networks |
| 2026-05-21
⋅
PWC
⋅
Inside Red Lamassu’s JFMBackdoor JFMBackdoor Calypso |
| 2026-05-20
⋅
Seqrite Labs
⋅
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure Cobalt Strike |
| 2026-05-20
⋅
Hackernoon
⋅
ZeffSec Resurfaces on Telegram, Claims Breach of Gozine2.ir ZeffSec |