Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →This Week in Threats
Latest Threat Intelligence
Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →Russian Router Targeting Shows Why Edge Hygiene Is a DIB Priority
CISA and allied agencies warn that Russian FSB Center 16 actors continue targeting poorly configured routers and network devices. Here is what SMBs and government contractors should fix first.
Russian Router Targeting Shows Why Edge Hygiene Is a Mission Requirement
A joint CISA, NSA, FBI, and allied advisory says Russian FSB Center 16 actors continue exploiting poorly configured routers. Here is what SMBs and government contractors should prioritize now.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
Chinese Threat Intelligence
View all Chinese intel →Project ORBITAL Maps the Edge-Device Relay Networks Hiding APT Traffic
Project ORBITAL tracks Operational Relay Box networks used by advanced threat actors to hide activity behind compromised SOHO routers, IoT devices, and other neglected edge infrastructure.
JadeProx Shows Why China-Nexus Intrusions Still Start With Basic Exposure
Group-IB’s JadeProx reporting shows how China-nexus operators combined exposed services, DLL sideloading, phishing infrastructure, and TriBack Loader. Here is what SMBs and government contractors should hunt first.
Daxin and Stupig Show Why Legacy Access Paths Matter in Manufacturing Defense
Symantec and Carbon Black found China-linked Daxin active in a Taiwan high-tech manufacturing environment alongside a new pre-login SYSTEM backdoor. Here is what defenders should take from it.
North Korean Threat Intelligence
View all North Korean intel →Mastra npm Compromise Shows AI Frameworks Are Supply-Chain Targets
Microsoft linked the Mastra AI npm package compromise to North Korean actor Sapphire Sleet. Here is what SMBs and government contractors should do about AI framework supply-chain risk.
Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk
Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.
DPRK Threat Actors Leverage GitHub as Command and Control Infrastructure in Multi-Stage LNK Attacks
North Korean state-sponsored threat actors have been observed targeting South Korean organizations with a sophisticated multi-stage attack chain that abuses GitHub as command and control (C2) infrastructure. Fortinet FortiGuard Labs published research on April 2, 2026 detailing t
Iranian Threat Intelligence
View all Iranian intel →Iranian PLC Exploitation Shows Why OT Remote Access Is Now a Board-Level Risk
Federal agencies warn Iranian-affiliated actors are exploiting internet-exposed PLCs across U.S. critical infrastructure. Here is what SMBs, municipalities, utilities, and government contractors should do first.
APT34 Shows Why Identity Infrastructure Is Iran’s Quietest Attack Path
KELA’s APT34/OilRig reporting shows why Iranian espionage risk is increasingly an identity, Exchange, DNS, and trusted-infrastructure problem — not just a malware problem.
Project CAV3RN Turns Outlook Calendars and DNS Into Covert C2
Kaspersky reported a Project CAV3RN module that abuses Microsoft Outlook calendar events and DNS AAAA records for covert command-and-control. Here is what SMBs and government contractors should monitor in Microsoft Graph, Entra ID, endpoint, and DNS logs.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
NGINX CVE-2026-42533 Turns Reverse Proxy Configs Into Patch Priorities
CVE-2026-42533 is a critical NGINX heap buffer overflow tied to regex map and capture handling. For defenders, the lesson is bigger than one patch: internet-facing reverse proxies need version control, config review, and fast rollback-ready upgrade paths.
Chrome Critical Fixes Put Browser Patch Cadence Back on the Clock
Google’s Chrome 150 desktop update fixes seven security flaws, including three Critical use-after-free vulnerabilities. For SMBs and government contractors, browser patching is endpoint risk management—not routine software hygiene.
7-Zip XZ RCE Fix Turns Archive Handling Into a Patch Priority
7-Zip 26.02 fixes an XZ archive-processing flaw that can lead to code execution when a user opens a malicious file. Treat it as endpoint patching work, not just a utility update.
wp2shell Turns WordPress Core Into a Patch-Now Web Risk
Public exploits for the WordPress Core wp2shell chain make this a patch-now priority. Here is what SMBs and government contractors should verify immediately.
Newsletter
The Bulwark Brief.
Cyber threat intel, AI, and tech worth your attention, what we're tracking that day, with a "why it matters" line on every item. Most weekdays. No fluff.