2026-05-21 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Two recent incidents involving The Gentlemen ransomware show the use of defense evasion tactics, including logs being cleared and attempts to add antivirus exclusions.
P15
2026-05-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…
P0
2026-05-11 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a so…
P60
2026-05-08 09:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2026-04-23 21:38 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting th…
P20
2026-04-23 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…
P0
2026-04-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany mo…
P15
2026-04-08 16:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Threat Intelligence Framework
P0
2026-04-07 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recent incident linked to the NightSpire ransomware workflow gives insight into why the RaaS structure and model, or lack thereof, are important – especially when it comes to scoping and recovering from the incident.
P15
2026-04-07 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
P0
2026-03-13 10:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Who's attacking your vendors? Read about the six main supply chain attack groups who are driving SaaS, open-source, and MSP compromise in 2026. Learn how npm supply chain attacks threaten your security today, based on threat intelligence collected by Group-IB.
P0
2025-12-09 17:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely…
P0
2025-10-22 07:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent Threat (APT) MuddyWater. The attack used a compromised mailbox to distribute Phoenix backdoor malware to international organizations and across the whole Middle East and North Africa region, targeting more than 100 government entities.
P0
2025-10-21 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Threat Intelligence Report on a Singapore-Targeted Scam Operation
P0
2025-10-15 07:37 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Suspicious Payment Details module for Threat Intelligence delivers payment identifiers tied to ransomware, illegal casinos, and laundering schemes. Fraud, AML, and compliance teams can now stop money from reaching criminal infrastructure.
P15
2025-09-29 05:58 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…
P0
2025-09-09 05:54 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
Introduction A new wave of AI-powered investment scams is targeting Indian users on Facebook and Instagram, luring them with fake celebrity endorsements and deepfake interviews. Ads featuring figures like Nirmala Sitharaman, Sadhguru, and Neha Kakkar promote fraudulent schemes, directing users to counterfeit news websites mimicking The Times of India, IndiaTime, and NDTV. These sites claim celebrities have built fortunes using exclusive investment strategies, persuading victims to deposit ₹21,0…
P0
2025-07-22 09:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Enable real-time, token-based account security that stops withdrawal fraud before your brand, players, and their revenue are compromised.
P0
2025-07-07 07:03 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Introducing BioConfirm - Enable real-time, token-based user account security that stops withdrawal fraud before your brand, customers’ trust, and revenue are compromised.
P0
2025-06-13 16:03 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…
P0
2025-05-06 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…
P5
2025-04-18 08:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Our new LLM-powered chatbot is designed for efficiency and security. Discover how Group-IB AI Assistant enhances threat intelligence workflows and provides security teams with instant insights — without compromising privacy.
P0
2025-02-12 06:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how ransomware has evolved into a sophisticated cyber threat, with groups like RansomHub leading the charge. Learn more about their adaptability, TTPs, and the rise of Ransomware-as-a-service in this first-of-three-part trilogy.
P15
2025-01-13 06:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Minimize false positives, proactively prevent threats, and gain customized fraud protection with Group-IB. Our AI-powered solutions are fine-tuned by local experts and real-time threat intelligence in key regions, ensuring optimal security performance and minimal disruption to your business.
P0
2024-11-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the highlights of Huntress Capture the Flag 2024, where teams cracked complex cyber challenges in a month-long journey of reverse engineering and malware analysis.
P0
2024-07-01 07:41 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How to best empower your business clients’ cybersecurity with critical cyber threat intelligence
P0
2024-02-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
This blog post provides a detailed look at the TTPs of a ransomware affiliate operator. In this case, the endpoint had been moved to another infrastructure (as illustrated by various command lines, and confirmed by the partner), so while Huntress SOC analysts reported the activity to the partner, no Huntress customer was impacted by the ransomware deployment.
P15
2024-02-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Evidence of a pre-existing exploit was rendered when the Huntress agent was added to an endpoint. Within minutes, and in part through the use of previously published threat intelligence, analysts were able to identify the issue and make recommendations to the customer to remediate the root cause.
P0
2023-12-14 06:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Analysis of TTPs tied to GambleForce, which carried out SQL injection attacks against companies in the APAC region
P0
2023-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analysts recently observed a novel set of tactics, techniques, and procedures used by a threat actor for data collection and exfiltration.
P0