Threat Intelligence — Page 33

Threat Intelligence

Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets

The DPRK-linked crew is spoofing Webex pages and antivirus installers to drop new implants on military and corporate networks.

2 min read
Threat Intelligence

GreyVibe's AI Playbook: What Russia-Linked Operators Are Actually Doing With ChatGPT and Gemini

A threat actor researchers are calling GreyVibe is reportedly weaving commercial AI tools into its attack workflow. The real story isn't the hype — it's the operational specifics.

2 min read
Threat Intelligence

JINX-0164 Runs Fake-Recruiter Playbook Against Crypto Firms, Drops Custom macOS Malware

A newly catalogued threat actor is courting engineers at cryptocurrency companies with bogus job offers, then pivoting into CI/CD systems to siphon digital assets.

2 min read
Threat Intelligence

Britain's Cyber Spymaster Calls AI an Unstoppable Force and Points the Finger at Moscow

The head of GCHQ's signals intelligence arm delivered a rare public speech warning that Russia is waging sustained gray-zone aggression — and that artificial intelligence will define who wins the next phase of that conflict.

3 min read
Threat Intelligence

CrowdStrike, Google and Shadowserver Pull the Plug on GlassWorm's C2

A coordinated takedown severed every known command channel of the developer-targeting worm — for now.

2 min read
Threat Intelligence

Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil

Two parallel banking trojan campaigns are pulling in victims across Iberia, Mexico, and Brazilian Android users. The lures are mundane. The payloads are not.

3 min read
Threat Intelligence

Glassworm's blockchain command channel went down. Nobody will say who pulled the plug.

Researchers say the developer-targeting botnet is offline after its Solana and BitTorrent DHT C2 was disrupted. The mechanics of the takedown, and who authorised it, remain unexplained.

3 min read
Threat Intelligence

MuddyWater Targets Global Organizations with DLL Side-Loading

Iranian group MuddyWater exploits DLL side-loading in espionage affecting nine nations.

2 min read
Threat Intelligence

Megalodon Campaign Pushed 5,718 Malicious Commits Into GitHub Repos in Six Hours

An automated backdooring operation abused compromised GitHub credentials to silently inject base64-encoded bash payloads into CI/CD workflows across more than 5,500 public repositories on May 18.

2 min read
Threat Intelligence

The Bot That Learned to Lie: Inside the New Generation of AI-Driven DDoS

Defenders describe attack waves that pause, study traffic patterns, and resume from fresh infrastructure — behavior that looks less like a script and more like a sparring partner.

3 min read
Threat Intelligence

Infosecurity Europe 2026: What the London Gathering Means for the Security Calendar

The industry's largest European security conference returns to London on June 2–4, 2026, and the programme signals where enterprise security investment is heading.

2 min read
Threat Intelligence

TrapDoor: The Supply Chain Campaign That Wants Your Whole Dev Environment, Not Just Your Secrets

A cross-registry malware campaign hitting npm, PyPI, and Crates.io is going after CI/CD pipelines, SSH trust chains, and AI coding assistant files — not just credentials on install.

3 min read
Threat Intelligence

The Boring Attacks Are Winning: Why Defenders Keep Losing to Trusted Tools

Leaked tokens, poisoned npm packages, and login replays are doing more damage than zero-days this quarter. Here is how to spot the pattern before it spots you.

3 min read
Threat Intelligence

Showboat: A Modular Linux Backdoor Quietly Camped in a Middle East Telco Since 2022

Lumen's Black Lotus Labs ties the SOCKS5-capable implant to a years-long intrusion at a regional carrier, with an in-memory loader and ELF payloads that sidestep most host telemetry.

2 min read
Threat Intelligence

Megalodon Campaign Plants Malicious Workflows in 5,561 GitHub Repos in Six Hours

Throwaway accounts pushed 5,718 commits forging build-bot identities to exfiltrate CI/CD secrets, researchers said.

2 min read
© 2026 Threat Vectr