Threat Intelligence — Page 18

Threat Intelligence

GlassWorm Is Down. The Repository Problem Isn't.

CrowdStrike, Google, and Shadowserver severed four C2 channels simultaneously. Meanwhile, 157 OSV false positives quietly eroded trust in the tools defenders depend on.

3 min read
Threat Intelligence

FBI Flags Silent Ransom Group's Physical Intrusion Tactic Against U.S. Law Firms

The threat actor known as Silent Ransom Group has added walk-in impersonation to its toolkit, sending actors posing as IT support into law firm offices to insert storage devices into employee computers.

3 min read
Threat Intelligence

Three Stories You Probably Missed: Trump Mobile Leak, FIFA Phishing, and CISA's Supply Chain Cleanup

A customer data exposure, a tournament-themed phishing campaign, and a federal agency scrambling to respond to upstream compromise — a busy week for the incidents no one headlined.

2 min read
Threat Intelligence

LLM Agent Spotted Driving Post-Exploitation After Marimo Notebook Compromise

An unattributed intrusion set chained CVE-2026-39987 against an exposed Marimo notebook, then handed the keyboard to a language model.

2 min read
Threat Intelligence

DDoS-as-a-Service Grows Up: Tiered Pricing, Reseller Programs, Real Support Tickets

The booter market has shed its script-kiddie aesthetic. Today's stresser panels look like SaaS — because operationally, they are.

3 min read
Threat Intelligence

GREYVIBE: The Russian-Speaking Threat Actor Targeting Ukraine

Persistent attacks align with Kremlin interests, spotlighting continuous geopolitical cyber warfare.

2 min read
Threat Intelligence

Typosquatted NuGet 'Sicoob.Sdk' Hoovers PFX Certs From Brazilian Banks

A poisoned package impersonating Brazil's Sicoob co-op banking network exfiltrates client IDs and PFX certificates — the same certs that sign API calls into the financial system.

2 min read
Threat Intelligence

Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets

The DPRK-linked crew is spoofing Webex pages and antivirus installers to drop new implants on military and corporate networks.

2 min read
Threat Intelligence

GreyVibe's AI Playbook: What Russia-Linked Operators Are Actually Doing With ChatGPT and Gemini

A threat actor researchers are calling GreyVibe is reportedly weaving commercial AI tools into its attack workflow. The real story isn't the hype — it's the operational specifics.

2 min read
Threat Intelligence

JINX-0164 Runs Fake-Recruiter Playbook Against Crypto Firms, Drops Custom macOS Malware

A newly catalogued threat actor is courting engineers at cryptocurrency companies with bogus job offers, then pivoting into CI/CD systems to siphon digital assets.

2 min read
Threat Intelligence

Britain's Cyber Spymaster Calls AI an Unstoppable Force and Points the Finger at Moscow

The head of GCHQ's signals intelligence arm delivered a rare public speech warning that Russia is waging sustained gray-zone aggression — and that artificial intelligence will define who wins the next phase of that conflict.

3 min read
Threat Intelligence

CrowdStrike, Google and Shadowserver Pull the Plug on GlassWorm's C2

A coordinated takedown severed every known command channel of the developer-targeting worm — for now.

2 min read
Threat Intelligence

Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil

Two parallel banking trojan campaigns are pulling in victims across Iberia, Mexico, and Brazilian Android users. The lures are mundane. The payloads are not.

3 min read
Threat Intelligence

Glassworm's blockchain command channel went down. Nobody will say who pulled the plug.

Researchers say the developer-targeting botnet is offline after its Solana and BitTorrent DHT C2 was disrupted. The mechanics of the takedown, and who authorised it, remain unexplained.

3 min read
Threat Intelligence

MuddyWater Targets Global Organizations with DLL Side-Loading

Iranian group MuddyWater exploits DLL side-loading in espionage affecting nine nations.

2 min read
© 2026 Threat Vectr