logo

Cybereason Blog

ID: cb3ac1f4-f16e-5b02-9073-dad1bf8e3b41

STIX ID: identity--cb3ac1f4-f16e-5b02-9073-dad1bf8e3b41

Feed Type: rss

Earliest post: 2023-12-11

Latest post: 2026-02-05

Threat research, attack analysis, and security insights from the Cybereason research team — covering real-world incidents, adversary tactics, detection methods, and defensive strategies.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
Cybereason TTP Briefing Q4 2025: Diverse Phishing Tactics and RATs on the Rise2026-02-05TrueCybereason Consulting TeamTrue
Fake Installer: Ultimately, ValleyRAT infection2026-02-03TrueCybereason Security Services TeamTrue
CVE-2025-55182: Critical Vulnerability, React2Shell, Allows for Unauthenticated RCE2025-12-05TrueCybereason Consulting TeamTrue
License to Encrypt: “The Gentlemen” Make Their Move2025-11-18TrueCybereason Security Services TeamTrue
Tycoon 2FA Phishing Kit Analysis2025-11-03TrueCybereason Security Services TeamTrue
From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations2025-10-29TrueCybereason Security Services TeamTrue
Cybereason TTP Briefing Q3 2025: LOLBINs and CVE Exploits Dominate2025-10-23TrueCybereason Consulting TeamTrue
Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-618822025-10-05TrueCybereason Consulting TeamTrue
Behind the Mask of Madgicx Plus: A Chrome Extension Campaign Targeting Meta Advertisers2025-09-09TrueCybereason Security Services TeamTrue
CVE-2025-53770 & CVE-2025-53771: Critical On-Prem SharePoint Vulnerabilities2025-07-22TrueCybereason Consulting TeamTrue
BlackSuit: A Hybrid Approach with Data Exfiltration and Encryption2025-07-11TrueCybereason Security Services TeamTrue
Deploying NetSupport RAT via WordPress & ClickFix2025-07-07TrueCybereason Security Services TeamTrue
Introducing the Cybereason TTP Briefing: Frontline Threat Intelligence Insights2025-06-29TrueCybereason Consulting TeamTrue
Ransomware Gangs Collapse as Qilin Seizes Control2025-06-17TrueCybereason Security Services TeamTrue
Copyright Phishing Lures Leading to Rhadamanthys Stealer Now Targeting Europe2025-05-21TrueCybereason Security Services TeamTrue
Genesis Market - Malicious Browser Extension2025-05-21TrueCybereason Security Services TeamTrue
CVE-2025-32433: Unauthenticated RCE Vulnerability in Erlang/OTP’s SSH Implementation2025-04-20TrueCybereason Consulting TeamTrue
From Shadow to Spotlight: The Evolution of LummaStealer and Its Hidden Secrets2025-04-11TrueCybereason Security Services TeamTrue
The Curious Case of PlayBoy Locker2025-03-25TrueCybereason Security Services TeamTrue
Three Zero-Day Vulnerabilities Discovered in VMware Products2025-03-05TrueCybereason Consulting TeamTrue
Phorpiex - Downloader Delivering Ransomware2025-01-28TrueCybereason Security Services TeamTrue
CVE-2025-23006: Critical Vulnerability Discovered in SonicWall SMA 1000 Series2025-01-24TrueCybereason Consulting TeamTrue
CVE-2024-55956: Zero-Day Vulnerability in Cleo Software Could Lead to Data Theft2024-12-17TrueCybereason Consulting TeamTrue
Your Data Is Under New Lummanagement: The Rise of LummaStealer2024-12-17TrueCybereason Security Services TeamTrue
Stellar Discovery of A New Cluster of Andromeda/Gamarue C22024-12-03TrueCybereason Security Services TeamTrue
THREAT ANALYSIS: Beast Ransomware2024-10-18TrueCybereason Security Services TeamTrue
CUCKOO SPEAR Part 2: Threat Actor Arsenal2024-10-04TrueCybereason Security Services TeamTrue
CUCKOO SPEAR Part 1: Analyzing NOOPDOOR from an IR Perspective2024-09-13TrueCybereason Security Services TeamTrue
Cuckoo Spear – the latest Nation-state Threat Actor targeting Japanese companies2024-07-25TrueCybereason Security Services TeamTrue
Hardening of HardBit2024-07-10TrueCybereason Security Services TeamTrue
I am Goot (Loader)2024-06-25TrueCybereason Security Services TeamTrue
Malicious Life Podcast: What Happened at Uber?2024-06-11TrueMalicious Life PodcastTrue
THREAT ALERT: The XZ Backdoor - Supply Chaining Into Your SSH2024-05-29TrueCybereason Security Services TeamTrue
Behind Closed Doors: The Rise of Hidden Malicious Remote Access2024-05-06TrueCybereason Security Services TeamTrue
Threat Alert: The Anydesk Breach Aftermath2024-03-22TrueCybereason Security Services TeamTrue
Beware of the Messengers, Exploiting ActiveMQ Vulnerability2024-03-13TrueCybereason Security Services TeamTrue
Unboxing Snake - Python Infostealer Lurking Through Messaging Services2024-03-05TrueCybereason Security Services TeamTrue
From Cracked to Hacked: Malware Spread via YouTube Videos2024-02-12TrueCybereason Security Services TeamTrue
THREAT ALERT: Ivanti Connect Secure VPN Zero-Day Exploitation2024-02-06TrueCybereason Security Services TeamTrue
THREAT ALERT: DarkGate Loader2024-01-29TrueCybereason Security Services TeamTrue
Malicious Life Podcast: The Mariposa Botnet2024-01-22TrueMalicious Life PodcastTrue
Malicious Life Podcast: The Real Story of Citibank’s $10M Hack2024-01-09TrueMalicious Life PodcastTrue
Malicious Life Podcast: How to Hack Into Satellites2023-12-27TrueMalicious Life PodcastTrue
THREAT ALERT: CITRIXBLEED (CVE-2023-4966)2023-12-18TrueCybereason Security Services TeamTrue
Malicious Life Podcast: Moonlight Maze2023-12-11TrueMalicious Life PodcastTrue

1–45 of 45