Nation-State Cyber Threats
SilverFox Deploys 3-Driver BYOVD Chain and ValleyRAT Against Japanese Manufacturer
Three vulnerable drivers, one payload — SilverFox on the wire this week.
Actionable insights into the global threat landscape. Analysis of TTPs, Indicators of Compromise (IoCs), and emerging attack patterns.
Nation-State Cyber Threats
Three vulnerable drivers, one payload — SilverFox on the wire this week.
Nation-State Cyber Threats
New backdoor, familiar actor — the Iran-linked group tracked as Nimbus Manticore has a fresh toolset, and Kaspersky's write-up of NightLedger lands this week.
Threat Intelligence
A novel malvertising delivery technique lands from Confiant — defender review for ad-tech and retail-trader-adjacent environments this weekend.
Ransomware
Another named RaaS operator profile from PRODAFT — defender-team pattern-tracking this weekend.
Policy & Government
UK police chiefs are citing the Transport for London prosecution and the Scattered Spider sentencing to press for Cybercrime Risk Orders — a proposed civil tool to restrain suspected cyber offenders. Post-TfL policy analysis this week.
Policy & Government
A Kenyan presidential-website hack draws a Bitcoin-ransom demand — government-website defender awareness this week.
Ransomware
The first purpose-built AI-model ransomware lands from JadePuffer — a defender review for organizations hosting AI infrastructure this week.
Nation-State Cyber Threats
A Dutch intelligence advisory raises the stakes on Russian camera-hijacking activity — critical-infrastructure defender teams review IP-camera posture this week.
Threat Intelligence
A novel Microsoft 365 calendar-abuse malware framework — defender detection-engineering review this week.
Supply Chain Attack
Ecosystem supply-chain compromises now extend to RubyGems — three malicious gems built to skip CI runners and land on developer machines make this week's defender inventory work a Ruby-dependency audit.
Threat Intelligence
A second SonicWall SMA attribution lands — Volexity names UTA0533 alongside the Dark Reading INC Ransomware framing this weekend.
Nation-State Cyber Threats
CERT-UA names UAC-0145 as the Sandworm sub-cluster behind the ClickFix CAPTCHA activity against Ukrainian devices - a GRU-affiliated crew, and defender awareness for Ukraine-adjacent teams this weekend.