logo

Zscaler Security Research Blog

ID: dcb31053-0a55-5fcd-ba0e-975cdae7dce8

STIX ID: identity--dcb31053-0a55-5fcd-ba0e-975cdae7dce8

Feed Type: skeleton

Earliest post: 2025-04-02

Latest post: 2026-02-26

The Zscaler Security Research Blog shares expert threat research, analysis of emerging attacks, and insights on secure cloud and network defense to help security teams stay ahead of modern threats.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
OpenClaw Skill Distributes Remcos & GhostLoader2026-05-05TrueTrue
Tropic Trooper: AdaptixC2 + Custom Beacon2026-04-22TrueTrue
Payouts King Takes Aim at the Ransomware Throne2026-04-16TrueTrue
In-Memory Loader Drops ScreenConnect2026-04-09TrueTrue
China-nexus Group Targets Arabian Gulf Region2026-04-09TrueTrue
Supply Chain Attacks Surge in March 20262026-04-03TrueTrue
Anthropic Claude Code Leak2026-04-01TrueTrue
Latest Xloader Obfuscation Code & C2 Protocol2026-03-31TrueTrue
CVE-2026-20131: Analysis of FMC RCE2026-03-24TrueTrue
Technical Analysis of SnappyClient2026-03-18TrueTrue
China-nexus Group Targets Persian Gulf Region2026-03-12TrueTrue
Middle East Conflict Fuels Cyber Attacks2026-03-06TrueTrue
Dust Specter APT Targets Gov’t Officials in Iraq2026-03-04TrueTrue
APT37 Adds New Tools For Air-Gapped Networks2026-02-26TrueTrue
Mobile, IoT, and OT Risks Converge in the Public Sector2026-02-11TrueTrue
GuLoader Obfuscation Analysis2026-02-09TrueTrue
Technical Analysis of Marco Stealer2026-02-05TrueTrue
Operation Neusploit: APT28 Uses CVE-2026-215092026-02-03TrueTrue
SHEETCREEP, FIREPOWER, and MAILCREEP Analysis2026-01-27TrueTrue
GOGITTER, GITSHELLPAD, and GOSHELL Analysis2026-01-27TrueTrue
Shai-Hulud V2 Poses Risk to NPM Supply Chain2026-01-12TrueTrue
Malicious NPM Packages Deliver NodeCordRAT2026-01-07TrueTrue
Qakbot Attacks Increasing due to Evolving Threats2025-12-30TrueTrue
HijackLoader2025-12-30TrueTrue
CryptNet Ransomware2025-12-30TrueTrue
New HijackLoader Evasion Tactics2025-12-30TrueTrue
Agniane Stealer2025-12-30TrueTrue
Tracking 15 Years of Qakbot Development2025-12-30TrueTrue
TOITOIN Trojan: A New Multi-Stage Attack Targeting LATAM2025-12-30TrueTrue
ThreatLabz2025-12-30TrueTrue
ThreatLabz2025-12-30TrueTrue
Steal-It Campaign2025-12-30TrueTrue
CVE-2023-35192025-12-30TrueTrue
Windows Notifications2025-12-30TrueTrue
QakBot Stealer from Newly Registered Domains2025-12-30TrueTrue
APT36's Updated Arsenal2025-12-30TrueTrue
Nokoyawa Ransomware: Rust or Bust2025-12-30TrueTrue
Nevada Ransomware, Nokoyawa Variant2025-12-30TrueTrue
Back in Black... Basta2025-12-30TrueTrue
Coverage Advisory for MOVEit2025-12-30TrueTrue
Pikabot Updates2025-12-30TrueTrue
HijackLoader Updates2025-12-30TrueTrue
Hibernating Qakbot2025-12-30TrueTrue
BlindEagle Deploys Caminho and DCRAT2025-12-16TrueTrue
React2Shell RCE Vulnerability (CVE-2025-55182)2025-12-15TrueTrue
Technical Analysis of the BlackForce Phishing Kit2025-12-11TrueTrue
Technical Analysis of Matanbuchus 3.02025-12-02TrueTrue
CVE-2025-50165: Windows Graphics Component Flaw2025-12-01TrueTrue
In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered2025-11-25TrueTrue
Zscaler Discovers Vulnerability in Keras Models Allowing Arbitrary File Access and SSRF (CVE-2025-12058)2025-11-04TrueTrue

1–50 of 821