Click here to download all references as Bib-File.•

Enter keywords to filter the library entries below or Propose new Entry
2026-04-14 ⋅ Gen ⋅ Gen Threat Labs
Chasing an Angry Spark
2026-04-10 ⋅ Infoblox ⋅ Chong Lua Dao, Infoblox Threat Intel
Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers
2026-04-09 ⋅ ⋅ F6 ⋅ F6
Eastern Signature: Investigating a Cyberattack by an Asian Threat Group
ShadowPad
2026-04-07 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
2026-04-01 ⋅ SOC Prime ⋅ Daryna Olyniychuk
UAC-0255 Attack Detection: Threat Actors Impersonate CERT-UA to Infect Ukrainian Public and Private Sector Organizations With AGEWHEEZE RAT
AGEWHEEZE Cyber Serp
2026-03-31 ⋅ Google ⋅ Adrian Hernandez, Ashley Zaya, Austin Larsen, Christopher Gardner, Dima Lenz, Michael Rudden, Mon Liclican, Tyler McLellan
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
WAVESHAPER
2026-03-26 ⋅ Unit 42
Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government
MASOL
2026-03-23 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
NICKEL ALLEY strategy: Fake it ‘til you make it
PylangGhost GolangGhost Nickel Alley
2026-03-22 ⋅ Christoffer Strömblad ⋅ Christoffer Strömblad
Threat Assessment: TeamPCP - CanisterWorm & Kubernetes Wiper Campaign
TeamPCP
2026-03-20 ⋅ Nextron Systems ⋅ Pezier Pierre-Henri
RegPhantom Backdoor Threat Analysis
RegPhantom
2026-03-19 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
Android devices ship with firmware-level malware
Keenadu
2026-03-18 ⋅ Google ⋅ Google Threat Intelligence Group
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
GHOSTBLADE UNC6748
2026-03-18 ⋅ Google ⋅ Google Threat Intelligence Group
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
GHOSTBLADE
2026-03-12 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
Storm-2561
2026-03-11 ⋅ Bitdefender ⋅ Jade Brown
Bitdefender Threat Debrief | March 2026
ShadowByt3$
2026-03-09 ⋅ Abstract Security ⋅ Abstract Security Threat Research Organization (ASTRO)
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2
GolangGhost PylangGhost GolangGhost
2026-03-07 ⋅ OpenSourceMalware ⋅ OpenSourceMalware
PolinRider: DPRK Threat Actor Implants Malware in Hundreds of GitHub Repos
JADESNOW
2026-03-06 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
AI as tradecraft: How threat actors operationalize AI
OtterCookie
2026-03-05 ⋅ Symantec ⋅ Threat Hunter Team
Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company
Tsundere
2026-03-05 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')
JADESNOW