Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Iranian Telegram-Controlled Spyware Targeting Dissidents and Journalists: Detection and Defense Guide
Iranian State Spyware Uses Telegram as C2 — What Defenders Need to Know Now Cybersecurity agencies from the United States, the United Kingdo...
Nimbus Manticore Recruitment Lures: Detecting Cross-Platform Node.js RATs on Linux and macOS
Executive Summary Kaspersky has attributed two previously undocumented malware families to Nimbus Manticore, the Iranian state-aligned threa...
Cavern (Cav3rn) C2: Detecting DNS Tunneling and Google Apps Script Abuse by Iranian APT Operators
Cavern C2 Blends Into Legitimate Traffic — and Your Perimeter Won't Notice Kaspersky's ongoing tracking of the Cavern (aka Cav3rn) command-a...
Defending Against CrashStealer macOS Malware and Mobile Surveillance Operations
Introduction Recent intelligence reveals multiple concerning developments in the threat landscape that require immediate defensive attention...
CISA AA26-097A: Iranian APT Targeting Rockwell Automation PLCs — Detection and Defense for Critical Infrastructure OT
CISA AA26-097A: Iranian APT Targeting Rockwell Automation PLCs — Detection and Defense for Critical Infrastructure OT Introduction On April ...
Rockwell Logic Implants: Defending Against Iranian APT Targeting of Exposed PLCs
Introduction On April 7, 2026, a joint advisory from the FBI, CISA, and the NSA underscored a severe threat to Operational Technology (OT): ...
AA26-097A: Iranian APT Targeting Rockwell Automation PLCs – Detection and Hardening
Introduction On April 7, 2026, CISA released advisory AA26-097A detailing active exploitation by Iranian-affiliated APT actors targeting U.S...