logo

Volexity Blog

ID: 85818f22-92ff-5c68-8dc1-a9c6d6e505ec

STIX ID: identity--85818f22-92ff-5c68-8dc1-a9c6d6e505ec

Feed Type: skeleton

Earliest post: 2014-09-24

Latest post: 2025-12-04

The Volexity Blog delivers in-depth threat research, forensic case studies, and expert analysis of advanced attacks and adversary techniques to help defenders understand and respond to real-world cybersecurity threats.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks2025-12-04TrueTrue
APT Meets GPT: Targeted Operations with Untamed LLMs2025-10-08TrueTrue
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows2025-04-22TrueTrue
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication2025-02-13TrueTrue
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access2024-11-22TrueTrue
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA2024-11-15TrueTrue
StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms2024-08-02TrueTrue
DISGOMOJI Malware Used to Target Indian Government2024-06-13TrueTrue
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices2024-05-15TrueTrue
Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400)2024-04-12TrueTrue
CharmingCypress: Innovating Persistence2024-02-13TrueTrue
How Memory Forensics Revealed Exploitation of Ivanti Connect Secure VPN Zero-Day Vulnerabilities2024-02-01TrueTrue
Ivanti Connect Secure VPN Exploitation: New Observations2024-01-18TrueTrue
Ivanti Connect Secure VPN Exploitation Goes Global2024-01-15TrueTrue
Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN2024-01-10TrueTrue
EvilBamboo Targets Mobile Devices in Multi-year Campaign2023-09-22TrueTrue
Charming Kitten Updates POWERSTAR with an InterPlanetary Twist2023-06-28TrueTrue
3CX Supply Chain Compromise Leads to ICONIC Incident2023-03-30TrueTrue
Using Memory Analysis to Detect EDR-Nullifying Malware2023-03-07TrueTrue
₿uyer ₿eware: Fake Cryptocurrency Applications Serving as Front for AppleJeus Malware2022-12-01TrueTrue
Mass Exploitation of (Un)authenticated Zimbra RCE: CVE-2022-279252022-08-10TrueTrue
SharpTongue Deploys Clever Mail-Stealing Browser Extension “SHARPEXT”2022-07-28TrueTrue
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach2022-06-15TrueTrue
Zero-Day Exploitation of Atlassian Confluence2022-06-02TrueTrue
Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS2022-03-22TrueTrue
Operation EmailThief: Active Exploitation of Zero-day XSS Vulnerability in Zimbra2022-02-03TrueTrue
XE Group – Exposed: 8 Years of Hacking & Card Skimming for Profit2021-12-07TrueTrue
North Korean BLUELIGHT Special: InkySquid Deploys RokRAT2021-08-24TrueTrue
North Korean APT InkySquid Infects Victims Using Browser Exploits2021-08-17TrueTrue
Suspected APT29 Operation Launches Election Fraud Themed Phishing Campaigns2021-05-27TrueTrue
Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities2021-03-02TrueTrue
Responding to the SolarWinds Breach: Detect, Prevent, and Remediate the Dark Halo Supply Chain Attack2020-12-16TrueTrue
Dark Halo Leverages SolarWinds Compromise to Breach Organizations2020-12-14TrueTrue
OceanLotus: Extending Cyber Espionage Operations Through Fake Websites2020-11-06TrueTrue
Evil Eye Threat Actor Resurfaces with iOS Exploit and Updated Implant2020-04-21TrueTrue
Storm Cloud Unleashed: Tibetan Focus of Highly Targeted Fake Flash Campaign2020-03-31TrueTrue
Microsoft Exchange Control Panel (ECP) Vulnerability CVE-2020-0688 Exploited2020-03-06TrueTrue

1–37 of 37