Still Circling: Blind Eagle's Toolkit Keeps Evolving 2026-07-17 True Serhii Melnyk True ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites 2026-07-16 True Rodel Mendrez True Mitigating New Vulnerabilities with owLSM 2026-07-13 True True Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor 2026-07-09 True Nathaniel Morales True From Phishing to Persistence: A CrySome RAT Infection Chain Analysis 2026-07-06 True Sean Shirley and Kyle Sopt True AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign 2026-07-02 True LevelBlue SpiderLabs True An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails 2026-06-30 True Hajime Takai True Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux 2026-06-25 True True LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign 2026-06-24 True Dawid Nesterowicz True Operation FlutterBridge: The FlutterShell macOS Backdoor 2026-06-18 True Maor Gabay True RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse 2026-06-17 True Serhii Melnyk True Reversing NVIDIA’s CVE-2026-24190: How a Kernel Flaw Put Enterprise AI Clusters and Workstations at Risk 2026-06-15 True Alon Bancic True The Device Code Phishing Tsunami: What We’re Seeing in the Wild 2026-06-09 True John Kevin Adriano True macOS ClickFix Social Engineering Campaigns 2026-06-04 True Maor Gabay True ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery 2026-06-04 True King Orande and Cris Tomboc True The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP 2026-06-03 True Jose Martin True Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign 2026-05-28 True Maor Gabay True From WinRE to SYSTEM: Hunting the YellowKey and MiniPlasma Attack Chain 2026-05-22 True True YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled 2026-05-19 True James Ballantyne True A Closer Look at The Gentlemen’s Alleged Leak 2026-05-18 True Arthur Erzberger True Threat Analysis: Backdoored Electron Apps Evading Defenses 2026-05-08 True Michael Morose True Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication 2026-05-07 True Mahadev Joshi True LevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses 2026-05-05 True True Inside Vect Ransomware-as-a-Service 2026-04-30 True SpiderLabs Researcher True Hacking Hotels via Smart Stationary Bikes: How Unsecured Gym Equipment Can Lead to RCE 2026-04-29 True John Lopez True Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems 2026-04-23 True Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley True A Closer Look at the Novel and Stealthy KarstoRAT Malware 2026-04-21 True Chen Aviani True Go With the Flow: Abusing OAuth Device Code Flow 2026-04-20 True Jakub Wiewiorski True RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait 2026-04-17 True True Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead 2026-04-13 True Jamie Mamroe True Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet 2026-04-10 True Sean Shirley True Axios NPM Package Supply Chain Compromise Leads to RAT Deployment 2026-04-09 True Mahadev Joshi and Sho Kishimoto True Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign 2026-04-09 True King Orande and Cris Tomboc True Major Supply Chain Compromise in the Popular axios npm Package 2026-04-03 True Karl Sigler True Using RF Power Levels to Defeat MAC Address Randomization Enabling Passive Device Tracking 2026-03-31 True Tom Neaves True Azure ServiceBus WebSockets as a C2 Channel 2026-03-24 True Stuart White True Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure 2026-03-23 True Sean Shirley True “Say My Name”: How MioLab is building MacOS Stealer Empire 2026-03-20 True Mark Tsipershtein and Evgeny Ananin True Fake CAPTCHA Campaign: Inside a Multi-Stage Stealer Assault 2026-03-19 True Shabtay Barel, Serhii Melnyk, Rodel Mendrez True KongTuke: A King Among Threat Groups 2026-03-18 True True How LevelBlue OTX and Cybereason XDR Detected a North Korea-Linked Remote IT Worker 2026-03-17 True Tue Luu True Epic Fury Update: Stryker Attack Highlights Handala's Shift from Espionage to Disruption 2026-03-12 True Arthur Erzberger True Weaponizing Safe Links: Abuse of Multi-Layered URL Rewriting in Phishing Attacks 2026-03-12 True John Kevin Adriano True Beware the ClickFix Trap: REMCOS RAT Hiding in “Helpful” PUAs 2026-03-09 True Hema Loganathan True CVE-2025-61915: Buffer Underflow Vulnerability Leads to Memory Corruption in CUPS 2026-03-05 True Ariel Silver True LevelBlue SpiderLabs Breaks Down the Role of Cyber Operations Taken in the Iran Crisis 2026-03-04 True Gal Romano True Operation Epic Fury: From Regional Escalation to Global Cyber Risk 2026-03-03 True LevelBlue SpiderLabs True Pwning Malware with Ninjas and Unicorns 2026-02-16 True Cade Wriglesworth True How ClickFix Opens the Door to Stealthy StealC Information Stealer 2026-02-12 True Rodel Mendrez True Stealerium Unmasked: Inside a Multi-Lure, Multi-Stage Stealer Campaign 2026-02-11 True Bernard Bautista True