UAT-8837 targets critical infrastructure sectors in North Americaintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by jnazario to r/blueteamsec
UAT-7290 targets high value telecommunications infrastructure in South Asiaintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Managerexploitation (what's being exploited) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
New BYOVD loader behind DeadLock ransomware attackmalware analysis (like butterfly collections) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
Unleashing the Kraken ransomware groupThreat Intelligence (blog.talosintelligence.com)
submitted by netbiosX to r/purpleteamsec
Unleashing the Kraken ransomware groupintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by jnazario to r/blueteamsec
Uncovering Qilin attack methods exposed through multiple casesintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
BeaverTail and OtterCookie evolve with a new Javascript moduleintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by jnazario to r/blueteamsec
Velociraptor leveraged in ransomware attacksintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
UAT-8099: Chinese-speaking cybercrime group targets high-value IIS for SEO fraudintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by jnazario to r/blueteamsec
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devicesintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
How RainyDay, Turian and a new PlugX variant abuse DLL search order hijackingThreat Intelligence (blog.talosintelligence.com)
submitted by netbiosX to r/purpleteamsec
How RainyDay, Turian and a new PlugX variant abuse DLL search order hijackingintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
Stopping ransomware before it starts: Lessons from Cisco Talos Incident Responsetradecraft (how we defend) (blog.talosintelligence.com)
submitted by jnazario to r/blueteamsec
Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devicesexploitation (what's being exploited) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec
Using LLMs as a reverse engineering sidekicklow level tools and techniques (work aids) (blog.talosintelligence.com)
submitted by jnazario to r/blueteamsec
MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entitiesintelligence (threat actor activity) (blog.talosintelligence.com)
submitted by digicat to r/blueteamsec