Click here to download all references as Bib-File.•
| 2026-03-31
⋅
Google
⋅
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack WAVESHAPER |
| 2026-03-18
⋅
Google
⋅
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors GHOSTBLADE |
| 2026-03-03
⋅
Google
⋅
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Coruna |
| 2026-03-03
⋅
Google
⋅
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Coruna UNC6353 UNC6691 |
| 2026-02-26
⋅
Group-IB
⋅
GTFire Phishing Scheme: Avoiding Detection Using Google Services GTFire |
| 2026-02-21
⋅
kmsec
⋅
DPRK tests Google Drive as a malware stager |
| 2026-02-17
⋅
Google
⋅
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day BRICKSTORM GRIMBOLT SLAYSTYLE UNC6201 |
| 2026-01-30
⋅
Google
⋅
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft UNC6671 |
| 2026-01-28
⋅
Google
⋅
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network |
| 2026-01-27
⋅
Google
⋅
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 |
| 2025-12-12
⋅
Google
⋅
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) ANGRYREBEL MINOCAT SNOWLIGHT Earth Lamia |
| 2025-12-04
⋅
Aryaka Networks
⋅
Scam in the Cloud How Fraudsters Exploit Google Cloud Storage (GCS) for Deceptive Campaigns |
| 2025-11-20
⋅
Google
⋅
Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks BADAUDIO Cobalt Strike |
| 2025-11-05
⋅
Google
⋅
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools PromptLock UNC1069 |
| 2025-10-20
⋅
Google
⋅
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER MAYBEROBOT NOROBOT YESROBOT |
| 2025-09-30
⋅
Google
⋅
Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations |
| 2025-09-24
⋅
TEAMT5
⋅
Google Calendar As C2 Infrastructure: A China-Nexus Campaign With Stealthy Tactics TOUGHPROGRESS |
| 2025-09-24
⋅
Google
⋅
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors BRICKSTORM |
| 2025-09-05
⋅
Arctic Wolf
⋅
GPUGate Malware: Malicious GitHub Desktop Implants Use Hardware-Specific Decryption, Abuse Google Ads to Target Western Europe |
| 2025-08-26
⋅
Google
⋅
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift UNC6395 |