Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Blind Eagle (APT-C-36) Evolved Toolkit: AsyncRAT, njRAT & LimeRAT via AutoIt RunPE and DuckDNS C2 — OTX Detection Pack
Threat Summary Between May and July 2026, the OTX community and LevelBlue SpiderLabs tracked Blind Eagle (APT-C-36) across multiple exposed ...
BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules
BLACKWATER Ransomware Gang: 2 New Victims Posted on Leak Site — India & Argentina Targeting Analysis with Detection Rules Classification: TL...
Evooo1Bot Linux Botnet: Mirai-Derived Malware Turns Edge Devices Into SOCKS5 Proxies — Detection and Remediation Guide
Evooo1Bot: The Latest Mirai Descendant Is Building Proxy Infrastructure Out of Your Edge Devices Security researchers have disclosed a previ...
Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Access — Detection and Mitigation Guide
Introduction Security researchers at SSD Secure Disclosure have published the second stage of a two-part exploit chain that achieves full An...
Clop Extortion Gang Claims Breaches at GE and Philips: Detection, Threat Hunting, and Response Playbook
Clop Claims Data Theft at GE and Philips — What Defenders Must Do Now General Electric and Philips have both confirmed they are investigatin...
VMware Exploitation, Unpatched Windows Flaw, MCP Attacks & Browser Hijacking: Weekly Threat Recap and Defensive Playbook
Introduction This week's threat landscape is a case study in a lesson I keep repeating to clients: the attacks causing the most damage are r...
Vishing Attack on Quantum Health: Defending Healthcare Networks Against Voice-Based Social Engineering and Help Desk Exploitation
Introduction Quantum Health, a major healthcare navigation and care coordination company, has disclosed a data breach after threat actors ga...
Operation ASTERIX: Detecting the AI-Built Crypto Fraud Pipeline — Fake Wallets, Vishing Panels, and Telegram Exfiltration
Introduction Rapid7's Operation ASTERIX investigation is one of the more instructive disclosures of 2025-2026 — not because the tradecraft i...
Storm-0501 Azure Cloud Ransomware: Detecting Tenant Hijacking, Backup Destruction, and Key Vault Encryption Abuse
Introduction The ransomware playbook has fundamentally changed, and Storm-0501 is the proof. This financially motivated threat actor — track...