#threat-intel
26 stories taggedthreat-intel · page 2 of 2.

DHS Probes Intrusion Into HSIN, the Federal Info-Sharing Platform
The Homeland Security Information Network was compromised, according to the department. Attribution remains open. The exposure question is bigger than the intrusion itself.

BEC Isn't an Email Problem. It's a Supply Chain.
Underground forums reveal Business Email Compromise as a multi-stage operation built on account access, target research, and cash-out networks, not a clever phishing lure.

From Modded Game Controllers to IBM X-Force Red: The Chris Thompson Arc
A teenage hardware tinkerer grows up to run one of the most recognizable offensive-security brands in enterprise tech, then leaves to build something new.

Monday Brief: A DirtyClone Linux Bug, Turla's New Backdoor, and the Infostealer Churn
Old access paths, missed patches, and a fresh kernel flaw kept defenders busy. A roundup of what moved this week in the cybercrime ecosystem.

Week in Brief: Russia's Cellebrite Use, Five Eyes AI Warning, macOS Backdoor, Scattered Spider Pleas
State-backed mobile forensics against an activist, an intelligence alliance's AI advisory, a new Mac implant, and a cybercrime case moving toward sentencing.

Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant
Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.

Mistic Backdoor Shows Up in IAB-Brokered Intrusions Across Four Verticals
A quiet new implant tied to the KongTuke access broker is landing on insurance, education, IT, and professional services networks, and it's not riding a CVE to get there.

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC
Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

AryStinger Quietly Conscripts 4,300 Old Routers Into a Recon Proxy Fabric
Researchers say the malware skips the usual DDoS playbook and instead builds infrastructure for pre-breach reconnaissance.

Clipper Crew Buys Sponsored Posts on News Sites to Push Trojanized Crypto Tools
An untracked actor is laundering credibility through paid press placements, a phishing-grade WordPress hub, and seeded GitHub and SourceForge repos to deliver clipboard hijackers.

The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents handing over real credentials: the criminal stack is industrialising.