logo

ThreatLocker Blog

ID: 8d45e58f-561b-564e-b72e-7710085c92ea

STIX ID: identity--8d45e58f-561b-564e-b72e-7710085c92ea

Feed Type: rss

Earliest post: 2025-01-03

Latest post: 2026-06-03

Actionable cybersecurity insights, zero-trust guidance, threat research, and practical defensive strategies from the ThreatLocker team — focused on endpoint protection, application control, and secure access management.

01/01/2020
06/03/2026
Title Date Published Describes IncidentAuthorVisible
Red Hat npm packages compromised with credential stealing worm 2026-06-03TrueTrue
Why cybersecurity in higher education needs Zero Trust 2026-06-02TrueTrue
How Mini Shai-Hulud worm moved through supply chain, impacting GitHub, Nx Console, & TanStack 2026-05-27TrueTrue
GitHub breach likely caused by Nx Console compromise 2026-05-21TrueTrue
Reverse Shai-Hulud: Supply chain compromise impacts @antv packages 2026-05-19TrueTrue
MiniPlasma: Windows privilege escalation zero-day affects fully patched systems2026-05-19TrueTrue
GhostLock and the limits of threat hype: A closer look 2026-05-15TrueTrue
What YellowKey and GreenPlasma zero-day exploits reveal about trusting native Windows security 2026-05-15TrueTrue
Sorry ransomware exploits cPanel authentication bypass 2026-05-14TrueTrue
TeamPCP supply chain attack hits TanStack2026-05-14TrueTrue
What JDownloader and Daemon Tools reveal about software distribution trust 2026-05-11TrueTrue
Dirty Frag: 9-year-old vulnerability enabling root access on Linux2026-05-11TrueTrue
Microsoft Edge is keeping your passwords in plaintext memory: Here’s what that actually means 2026-05-06TrueTrue
DigiCert compromise precedes widespread Microsoft Defender false positives2026-05-04TrueTrue
Linux Copy Fail zero-day enables privilege escalation 2026-05-01TrueTrue
Vect ransomware exposed: An inside look at its affiliate network 2026-04-28TrueTrue
Financial services cybersecurity: Why Zero Trust is critical 2026-04-27TrueTrue
Adobe Acrobat Reader CVE-2026-34621: Active exploitation via prototype pollution2026-04-23TrueTrue
Secure communication: Why Zero Trust comes first 2026-04-17TrueTrue
Why cybercriminals favor data exfiltration over ransomware 2026-04-16TrueTrue
Malware as a service: How cybercrime became a scalable business 2026-04-15TrueTrue
Why cybercriminals favor data exfiltration over ransomware 2026-04-14TrueTrue
The Claude Mythos Preview proves now is the time for Zero Trust 2026-04-14TrueTrue
Axios supply chain attack: How a compromised npm package delivered RAT malware2026-04-14TrueTrue
What is PowerShell? Understanding vulnerabilities and practical mitigations2026-04-13TrueTrue
Supply chain attack: Security scanner compromise leads to widespread infostealer and ransomware pivot2026-04-07TrueTrue
USB Rubber Ducky attacks explained: Keystroke injection, evasion, and defense 2026-03-31TrueTrue
Powercat malware campaign: Fake game cheats deliver infostealer targeting Discord, Roblox, and crypto wallets 2026-03-25TrueTrue
What the Stryker cyberattack teaches us2026-03-13TrueTrue
Conduent data breach among the largest in U.S. history 2026-03-12TrueTrue
Windows Notepad vulnerability: Markdown risk explained2026-02-26TrueTrue
SSL-VPN Compromise: How perimeter device breaches lead to ransomware and domain takeover2026-02-23TrueTrue
Discord Zendesk breach highlights growing risk of third-party vendor access 2026-02-19TrueTrue
ConsentFix attacks abuse GitHub OAuth tokens to bypass authentication 2026-02-16TrueTrue
0ktapus phishing campaign: How attackers abuse Okta SSO to bypass MFA 2026-02-13TrueTrue
Notepad++ supply chain compromise: Trojanized updates used in suspected nation-state attack 2026-02-06TrueTrue
WinRAR CVE-2025-8088 explained: Directory traversal vulnerability enables arbitrary file writes2026-02-05TrueTrue
WinRAR CVE-2025-8088 explained2026-02-05TrueTrue
Malicious VS Code tasks.json abuse enables multi-stage infostealer deployment2026-02-02TrueTrue
Fake Booking.com ClickFix attack abuses Cloudflare verification to deliver malware 2026-01-23TrueTrue
A vendor’s breach becomes a business crisis: Lessons from the Cierant Data breach2025-12-30TrueTrue
React2Shell to real-world breach: How an unpatched dev server led to a Windows compromise 2025-12-29TrueTrue
Ransomware cases highlight ongoing security pressure in financial services 2025-12-29TrueTrue
Top 10 post-exploitation tools threat actors use in real intrusions 2025-12-16TrueTrue
From Armillaria loader to EDR killer 2025-12-12TrueTrue
Analysis of 7-Zip vulnerabilities: CVE-2025-11001 and CVE-2025-110022025-12-12TrueTrue
Cyber Hero MDR catches NetSupport RAT2025-12-09TrueTrue
How law firms can reduce liability when sensitive client data Is breached 2025-12-04TrueTrue
How internal communications shape data breach liability for employers 2025-12-03TrueTrue
Scam and credential theft activity spikes during open enrollment: What CISOs need to know 2025-12-03TrueTrue

1–50 of 112