logo

Elastic Security Labs

ID: 3b67b5ad-2c09-590d-9457-06e4d7970a2f

STIX ID: identity--3b67b5ad-2c09-590d-9457-06e4d7970a2f

Feed Type: rss

Earliest post: 2020-05-30

Latest post: 2026-08-25

Advanced threat research, detection engineering insights, and security analysis from the Elastic Security Labs team — covering adversary techniques, anomaly detection, malware behavior, and defensive strategies powered by Elastic data.

01/01/2020
08/28/2026
Title Date Published Describes IncidentAuthorVisible
Living off the coding agent: Two tales of tunnels and LaunchAgents2026-08-07TrueTrue
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages2026-08-06TrueTrue
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support2026-07-31TrueTrue
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend2026-07-31TrueTrue
What's new in Elastic Defend: 800+ vulnerable driver rules, automated troubleshooting, and ARM support2026-07-31TruePedro Jaramillo,Roxana Gheorghe,Mia LaVadaTrue
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution2026-07-23TrueRuben Groenewoud,Bryan Porras BlanchTrue
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution2026-07-23TrueTrue
New North Korean campaign uses fake coding interviews to steal developer credentials2026-07-18TrueTrue
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains2026-07-16TrueTrue
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit2026-07-08TrueTrue
From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI2026-06-23TrueTrue
Lost in relocation: analysis of a new loader distributing CASTLESTEALER2026-06-19TrueTrue
Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace2026-05-26TrueTrue
PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT2026-05-22TrueTrue
Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild2026-05-09TrueTrue
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook2026-05-07TrueTrue
DFIR: From alert to root cause using Osquery without leaving Elastic Security2026-05-01TrueRaquel TabuyoTrue
DFIR: From alert to root cause using Osquery without leaving Elastic Security2026-05-01TrueTrue
CI/CD pipeline abuse: the problem no one is watching2026-04-29TrueTrue
The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation2026-04-21TrueTrue
Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT2026-04-14TrueTrue
Hooked on Linux: Rootkit Detection Engineering2026-04-02TrueTrue
How we caught the Axios supply chain attack2026-04-02TrueTrue
Elastic releases detections for the Axios supply chain compromise2026-04-01TrueTrue
Elastic releases detections for the Axios supply chain compromise2026-04-01TrueRuben Groenewoud,Samir Bousseaden,Salim Bitam,Joe Desimone,Colson Wilhoit,Andrew PeaseTrue
Inside the Axios supply chain compromise - one RAT to rule them all2026-04-01TrueTrue
Fake Installers to Monero: A Multi-Tool Mining Operation2026-03-31TrueTrue
Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER2026-03-27TrueTrue
Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework2026-03-26TrueTrue
Supercharge Your SOC2026-03-24TruePaul EwingTrue
Supercharge Your SOC2026-03-24TrueTrue
Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario2026-03-20TrueRuben GroenewoudTrue
Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario2026-03-20TrueTrue
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect2026-03-19TrueTrue
Patch diff to SYSTEM2026-03-06TrueJoe DesimoneTrue
Patch diff to SYSTEM2026-03-06TrueTrue
Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft2026-03-05TrueTrue
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites2026-02-20TrueTrue
The Immutable Illusion: Pwning Your Kernel with Cloud Files2026-02-20TrueTrue
Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder2026-02-18TrueTrue
Speeding APT Attack Confirmation with Attack Discovery, Workflows, and Agent Builder2026-02-18TrueJames Spiteri,Dhrumil PatelTrue
BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign2026-02-11TrueTrue
SolarWinds Web Help Desk Exploitation - February 20262026-02-10TrueTrue
SolarWinds Web Help Desk Exploitation - February 20262026-02-10TrueElastic Security LabsTrue
DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector2026-02-06TrueTrue
DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector2026-02-06TrueElastic Security LabsTrue
Automating GOAD and Live Malware Labs2026-02-05TrueTrue
Automating GOAD and Live Malware Labs2026-02-05TrueNic Palmer,Adrian ChenTrue
NANOREMOTE, cousin of FINALDRAFT2025-12-11TrueTrue
RONINGLOADER: DragonBreath’s New Path to PPL Abuse2025-11-15TrueTrue

1–50 of 173