Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Executive SSNs for Sale: Defending Against Identity-as-a-Service Dark Web Marketplaces — Detection and Response Guide
Overview Rapid7's threat research team recently published findings on what they describe as an "Identity-as-a-Service" economy operating acr...
Qilin Ransomware Breach at ATF Confirmed as 'Major Incident' — Detection and Response Guide for Defenders
Qilin Claims, ATF Confirms: A 'Major Incident' at a Federal Law Enforcement Agency The Bureau of Alcohol, Tobacco, Firearms and Explosives (...
Dark Caracal's GoCaracal Espionage Framework: Detection, Hunting, and Defense Guide for SOC Teams
Introduction Dark Caracal — the long-running cyber espionage group previously tied to the Crosswalk and Operation Manul campaigns and widely...
CISA Red Team Breached Two Critical Infrastructure Orgs — Detection Engineering Lessons from a Double Domain Compromise
When the Red Team Owns the Domain — and Nobody Notices CISA has published the results of two red team assessments it ran simultaneously agai...
E4del and PINHOLE RATs: Detecting FTP Banner Dead Drop Resolvers Before C2 Resolution
Threat actors have found a new place to hide their command-and-control addresses: inside the welcome banners of public FTP servers. A newly ...
Mass Zimbra Collaboration Suite Exploitation: 270+ Servers Breached via Unauthenticated RCE — Detection and Remediation Guide
Threat actors have breached more than 270 Zimbra Collaboration Suite (ZCS) instances in an ongoing, active exploitation campaign abusing an ...
ShinyHunters Impersonates Security Staff to Breach ReliaQuest: Detecting and Defeating Help Desk Social Engineering
Introduction ReliaQuest — a well-known managed detection and response provider — has publicly confirmed that one of its own employees was ta...
SynkLoader Multitool Malware: Screen-Hijacking Credential Theft and Pre-Ransomware Staging — Detection and Hardening Guide
Introduction Security researchers have detailed SynkLoader, a multilingual malware multitool that resurrects a technique many defenders had ...
DOUBLECUP PNG Payloads: Detect Fake Steganography and Image-Embedded Malware
DOUBLECUP PNG Payloads: Detect Fake Steganography and Image-Embedded Malware The SANS Internet Storm Center diary entry on DOUBLECUP calls o...