Threat Intelligence — Page 30

Threat Intelligence

JDY Botnet Turns 1,500 Compromised SOHO Devices Into a Nation-State Targeting Engine

Lumen's Black Lotus Labs links the scanning network to Volt Typhoon. The threat isn't the botnet itself — it's the reconnaissance data it harvests before you've even read the CVE advisory.

2 min read
Threat Intelligence

JDY Botnet's Quiet Comeback: 1,500 SOHO and IoT Nodes Now Mapping the Internet

Researchers tie the reconstituted scanner network to China-nexus operators conducting persistent, large-scale reconnaissance against exposed services.

3 min read
Threat Intelligence

Tracing 'The Gentlemen' RaaS: OPSEC Trail Points to an Izhevsk Operator

A 90/10 affiliate split rocketed the crew to second place by victim count. The administrator's forum breadcrumbs are less impressive.

3 min read
Threat Intelligence

Microsoft Pulls GitHub Repos After 73 Open-Source Projects Get Stealer-Spiked

The 'Miasma' incident looks less like a novel supply-chain zero-day and more like classic account takeover hitting a soft target: the org's own open-source footprint.

3 min read
Threat Intelligence

Gamaredon and UAC-0226 Are Still Riding the WinRAR Path-Traversal Bug Into Ukrainian Networks

Nearly a year after a patch shipped, CVE-2025-8088 keeps paying dividends for two Russia-aligned crews running stealer campaigns against Ukraine.

2 min read
Threat Intelligence

Hades Hits PyPI: 37 Poisoned Wheels Auto-Exec via .pth Trick

A fresh splinter of the Miasma supply-chain campaign abuses Python's site-packages path hook to fire on import — and goes hunting for Bun credentials.

2 min read
Threat Intelligence

FROST: A Browser-Only Side Channel That Reads Your SSD to Guess What You're Doing

Graz University researchers show that JavaScript timing alone can fingerprint websites and applications by measuring contention on a victim's solid-state drive.

3 min read
Threat Intelligence

Meta Catches NSO Spear-Phishing on WhatsApp, Asks Court to Hold Vendor in Contempt

The injunction was supposed to keep Pegasus operators away from WhatsApp users. Meta says NSO came back anyway — and is now asking a judge to do something about it.

3 min read
Threat Intelligence

VerdantBamboo Ports BRICKSTORM to BSD, Goes Hunting for Linux Appliances

A China-nexus crew is rewriting its toolkit to live on the boxes most EDR vendors forgot about.

2 min read
Threat Intelligence

UNC3753 Hit U.S. Professional Services Firms With Vishing and Walk-In Intrusions

Dozens of legal, financial, and consulting firms were hit between January and May 2026 in a data-theft extortion run that blended phone-based social engineering with physical site visits.

3 min read
Threat Intelligence

How Ukraine Turned a Nation-State Cyberwar Into a Masterclass in Operational Resilience

Former foreign minister Dmytro Kuleba details how pre-planned contingencies — not ad-hoc crisis management — kept Ukrainian government and business functions alive under sustained Russian attack.

2 min read
Threat Intelligence

Microsoft Bakes a Two-Hour Quarantine Into VS Code Extension Auto-Updates

The delay is a soft tripwire against marketplace supply chain attacks — buying defenders a window to flag malicious updates before they propagate.

3 min read
Threat Intelligence

Silent Ransom Group Escalates Vishing Campaign Against U.S. Law Firms

Mandiant tracks rapid data theft following fake IT-support calls, raising fresh questions about Form 8-K Item 1.05 disclosure timing for affected firms.

3 min read
Threat Intelligence

Bright Data's iOS SDK Quietly Conscripts Smart TVs Into a Scraping Proxy Network

A reverse-engineering of the SDK shows how consumer apps — including always-on televisions — relay traffic for the proxy giant now courting AI customers.

3 min read
Threat Intelligence

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected

The campaign — tracked publicly as Miasma — propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

2 min read
© 2026 Threat Vectr