Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
E4del and PINHOLE RATs: Detecting FTP Banner Dead Drop Resolvers Before C2 Resolution
Threat actors have found a new place to hide their command-and-control addresses: inside the welcome banners of public FTP servers. A newly ...
Cavern (Cav3rn) C2: Detecting DNS Tunneling and Google Apps Script Abuse by Iranian APT Operators
Cavern C2 Blends Into Legitimate Traffic — and Your Perimeter Won't Notice Kaspersky's ongoing tracking of the Cavern (aka Cav3rn) command-a...
Defending AI Infrastructure: Mapping Hugging Face Breach Tactics to Detection Rules
Introduction The compromise of Hugging Face signals a critical evolution in threat actor targeting: the weaponization of AI infrastructure. ...
HollowGraph C2: Detecting Microsoft 365 Graph API Abuse via Future-Dated Calendar Events
Introduction Security operations teams must adapt to a sophisticated new evasion technique observed in the wild. Researchers at Group-IB hav...
Leveraging Real-Time Intelligence to Disrupt APT Infrastructure and C2
Introduction Advanced Persistent Threats (APT) remain the most dangerous adversaries in the modern cybersecurity landscape. As we move throu...
TELEPUZ Malware: Detecting ClickFix Infection Chains and Modular C2 Activity
Introduction Since late April 2026, a new, modular threat known as TELEPUZ has been actively circulating in the wild, utilizing the highly e...
DragonForce Ransomware: Detecting Microsoft Teams C2 Abuse and Go-Based Access Tools
Introduction The threat landscape has evolved once again with the confirmation that the DragonForce ransomware operation is actively abusing...
Underminr Vulnerability: Detecting C2 Traffic Hiding Behind Trusted Domains
Underminr Vulnerability: Detecting C2 Traffic Hiding Behind Trusted Domains Introduction A critical vulnerability dubbed Underminr has expos...
WhatsApp Fake iOS Spyware Campaign: Social Engineering Detection and Incident Response Guide
Introduction Meta's WhatsApp has issued a critical security alert affecting approximately 200 users who were deceived into installing a weap...