Skip to content
SEC-04

Threat Intelligence

Active campaigns, malware families and ransomware tracking.

Recent

  1. Field reportTI-2026-0437

    Malware that does not wait for an operator

    Talos reports CLOSEDQUORUM, the first documented implant with fully autonomous command and control — a shift from speed and scale to effort displacement.

    3 minSource: Cisco Talos

  2. Field reportTI-2026-0436

    Reading JavaScript written not to be read

    String arrays, renamed functions, encoded URLs and runtime decoders — a Talos walkthrough of getting obfuscated samples to explain themselves.

    3 minSource: Cisco Talos

  3. Field reportTI-2026-0435

    405 samples, twelve on endpoints

    Unit 42 gathered every AI-enabled malware sample it could find. Three percent reached a real machine, and none needed new detection.

    SeverityLow

    3 minSource: Unit 42

  4. Field reportTI-2026-0434

    Seven families, sixty-five machines

    Bitdefender's SilkParasite report describes about a year of quiet work across Central Asia and the Caucasus, five of the seven toolsets previously undocumented.

    SeverityMedium

    3 minSource: The Record

  5. Field reportTI-2026-0433

    An adversary that writes its own playbooks

    Talos documents UAT-10147 using agentic AI after the breach, not before it — for exploit refinement, validation and documenting its own intrusions.

    SeverityHigh

    3 minSource: Cisco Talos

  6. News briefTI-2026-0432

    Medusa passes five hundred organisations

    A joint advisory puts the count above 500 as of April, against 300 in March last year — and names what the affiliates are paid.

    SeverityHigh

    2 minSource: BleepingComputer

  7. News briefTI-2026-0431

    A nine-month-old patch meets a ransomware crew

    CISA has flagged CVE-2025-60710 as used in ransomware attacks. Microsoft fixed it in November 2025.

    SeverityHigh

    2 minSource: BleepingComputer

  8. News briefTI-2026-0430

    ShieldBreak turns Defender into a way up

    A privilege escalation flaw disclosed without notice, with a working exploit and no patch yet.

    SeverityHigh

    2 minSource: BleepingComputer

  9. Field reportTI-2026-0429

    JWR phishing kit streams keystrokes live

    Talos documents a framework whose operators watch partial card numbers appear before the victim submits anything.

    SeverityHigh

    2 minSource: Cisco Talos

  10. Field reportTI-2026-0428

    Ransomware crews are skipping the encryption

    Extortion without a payload is faster, quieter, and defeats the control most organisations invested in.

    SeverityCritical

    9 min

  11. AnalysisTI-2026-0421

    Initial access brokers are specialising by sector

    Listings now advertise vertical, revenue band and security stack.

    SeverityHigh

    6 min

  12. Research noteTI-2026-0414

    Infostealer logs feed almost every other campaign

    Commodity credential theft on personal devices is the input to targeted intrusion.

    SeverityHigh

    5 min

  13. Field reportTI-2026-0407

    Build systems are the current supply chain target

    Not the package registry — the pipeline that consumes it.

    SeverityCritical

    8 min