Threat Intelligence — Page 18

GlassWorm Is Down. The Repository Problem Isn't.
CrowdStrike, Google, and Shadowserver severed four C2 channels simultaneously. Meanwhile, 157 OSV false positives quietly eroded trust in the tools defenders depend on.

FBI Flags Silent Ransom Group's Physical Intrusion Tactic Against U.S. Law Firms
The threat actor known as Silent Ransom Group has added walk-in impersonation to its toolkit, sending actors posing as IT support into law firm offices to insert storage devices into employee computers.

Three Stories You Probably Missed: Trump Mobile Leak, FIFA Phishing, and CISA's Supply Chain Cleanup
A customer data exposure, a tournament-themed phishing campaign, and a federal agency scrambling to respond to upstream compromise — a busy week for the incidents no one headlined.

LLM Agent Spotted Driving Post-Exploitation After Marimo Notebook Compromise
An unattributed intrusion set chained CVE-2026-39987 against an exposed Marimo notebook, then handed the keyboard to a language model.

DDoS-as-a-Service Grows Up: Tiered Pricing, Reseller Programs, Real Support Tickets
The booter market has shed its script-kiddie aesthetic. Today's stresser panels look like SaaS — because operationally, they are.

GREYVIBE: The Russian-Speaking Threat Actor Targeting Ukraine
Persistent attacks align with Kremlin interests, spotlighting continuous geopolitical cyber warfare.

Typosquatted NuGet 'Sicoob.Sdk' Hoovers PFX Certs From Brazilian Banks
A poisoned package impersonating Brazil's Sicoob co-op banking network exfiltrates client IDs and PFX certificates — the same certs that sign API calls into the financial system.

Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets
The DPRK-linked crew is spoofing Webex pages and antivirus installers to drop new implants on military and corporate networks.

GreyVibe's AI Playbook: What Russia-Linked Operators Are Actually Doing With ChatGPT and Gemini
A threat actor researchers are calling GreyVibe is reportedly weaving commercial AI tools into its attack workflow. The real story isn't the hype — it's the operational specifics.

JINX-0164 Runs Fake-Recruiter Playbook Against Crypto Firms, Drops Custom macOS Malware
A newly catalogued threat actor is courting engineers at cryptocurrency companies with bogus job offers, then pivoting into CI/CD systems to siphon digital assets.

Britain's Cyber Spymaster Calls AI an Unstoppable Force and Points the Finger at Moscow
The head of GCHQ's signals intelligence arm delivered a rare public speech warning that Russia is waging sustained gray-zone aggression — and that artificial intelligence will define who wins the next phase of that conflict.

CrowdStrike, Google and Shadowserver Pull the Plug on GlassWorm's C2
A coordinated takedown severed every known command channel of the developer-targeting worm — for now.

Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil
Two parallel banking trojan campaigns are pulling in victims across Iberia, Mexico, and Brazilian Android users. The lures are mundane. The payloads are not.

Glassworm's blockchain command channel went down. Nobody will say who pulled the plug.
Researchers say the developer-targeting botnet is offline after its Solana and BitTorrent DHT C2 was disrupted. The mechanics of the takedown, and who authorised it, remain unexplained.

MuddyWater Targets Global Organizations with DLL Side-Loading
Iranian group MuddyWater exploits DLL side-loading in espionage affecting nine nations.