Security Insights

Latest threat analysis, industry news, and security best practices from our expert team.

Has:
midnight-blizzard9 articles
Sep 12, 2026

GTG-20006 / Midnight Blizzard Abused Claude AI to Regenerate Malware After Detection — SOC Detection and Threat Hunting Guide

A Detection Adversary That Rewrites Itself: What Anthropic's GTG-20006 Disclosure Means for Your SOC On Thursday, Anthropic disclosed that i...

sigma-rulekql-detectionthreat-hunting
Incident ResponseRead Now
Sep 11, 2026

Midnight Blizzard CaptiveCrunch + LegionLoader ClickFix + Melofee Linux Implant: OTX Pulse Analysis — Enterprise Detection Pack

Midnight Blizzard CaptiveCrunch + LegionLoader ClickFix + Melofee Linux Implant: Enterprise Detection Brief Threat Summary Three concurrent ...

darkwebotx-pulsedarkweb-apt
Darkweb AptRead Now
Sep 11, 2026

Midnight Blizzard CaptiveCrunch, LegionLoader ClickFix & Passkey AiTM Campaigns: OTX Pulse Analysis — Identity Theft Detection Pack

Midnight Blizzard CaptiveCrunch, LegionLoader ClickFix & Passkey AiTM Campaigns: OTX Pulse Analysis — Identity Theft Detection Pack Threat S...

darkwebotx-pulsedarkweb-credentials
Darkweb CredentialsRead Now
Aug 12, 2026

Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack

Midnight Blizzard CaptiveCrunch + UNC6671 Vishing Extortion Wave: OTX Pulse Analysis — Credential & OAuth Attack Detection Pack Three concur...

darkwebotx-pulsedarkweb-apt
Darkweb AptRead Now
Aug 12, 2026

CaptiveCrunch (Midnight Blizzard) & UNC6671 Vishing Extortion: OTX Pulse Analysis — M365 Credential Theft Detection Pack

Threat Summary Two concurrent OTX pulses reveal a coordinated surge in identity-centric attacks against Microsoft 365 and enterprise cloud e...

darkwebotx-pulsedarkweb-credentials
Darkweb CredentialsRead Now
Aug 12, 2026

Midnight Blizzard CaptiveCrunch, codemado AiTM Phishing Stack, GhostDesk Spyware & WP-SHELLSTORM Webshell Botnet: OTX Pulse Analysis — Credential Theft Detection Pack

Threat Intelligence Briefing: AiTM Phishing Industrialization, Nation-State Captive Portal Abuse, and Mass Webshell Deployment Threat Summar...

darkwebotx-pulsedarkweb-credentials
Darkweb CredentialsRead Now
Aug 3, 2026

Midnight Blizzard Hotel Wi-Fi Attacks: Defending Microsoft 365 Accounts Against Custom Malware

Introduction Microsoft has confirmed a sophisticated campaign orchestrated by the Russian state-sponsored threat actor Midnight Blizzard (AP...

incident-responseransomwarebreach-response
Incident ResponseRead Now
Aug 1, 2026

Storm-2945 'CaptiveCrunch': Hotel Wi-Fi DNS Hijacking and M365 Token Theft Defense

Storm-2945 'CaptiveCrunch': Hotel Wi-Fi DNS Hijacking and M365 Token Theft Defense Introduction Since early May 2026, a sophisticated cyber-...

mdrthreat-huntingendpoint-detection
SOC & MDRRead Now
Aug 1, 2026

CaptiveCrunch: Defending Against Midnight Blizzard's Hotel Portal Compromise Campaign

CaptiveCrunch: Defending Against Midnight Blizzard's Hotel Portal Compromise Campaign Introduction Midnight Blizzard, the Russian state-spon...

healthcare-cybersecurityhipaa-compliancehealthcare-ransomware
Incident ResponseRead Now