Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →This Week in Threats
Latest Threat Intelligence
Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →Russian Router Targeting Shows Why Edge Hygiene Is a Mission Requirement
A joint CISA, NSA, FBI, and allied advisory says Russian FSB Center 16 actors continue exploiting poorly configured routers. Here is what SMBs and government contractors should prioritize now.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
GTIG’s STOCKSTAY research shows how Turla blends modular .NET malware, WebSocket C2, and diplomatic targeting. Here are the defensive lessons for SMBs and government contractors.
Chinese Threat Intelligence
View all Chinese intel →JadeProx Shows Why China-Nexus Intrusions Still Start With Basic Exposure
Group-IB’s JadeProx reporting shows how China-nexus operators combined exposed services, DLL sideloading, phishing infrastructure, and TriBack Loader. Here is what SMBs and government contractors should hunt first.
Daxin and Stupig Show Why Legacy Access Paths Matter in Manufacturing Defense
Symantec and Carbon Black found China-linked Daxin active in a Taiwan high-tech manufacturing environment alongside a new pre-login SYSTEM backdoor. Here is what defenders should take from it.
Pakistani Police Intrusions Show Why Public-Sector Data Systems Are Strategic Targets
SentinelLabs reporting on rival espionage activity against Pakistani law enforcement is a reminder that public-sector portals, case systems, and citizen-data apps are strategic intelligence targets — even when they are not classified systems.
North Korean Threat Intelligence
View all North Korean intel →Mastra npm Compromise Shows AI Frameworks Are Supply-Chain Targets
Microsoft linked the Mastra AI npm package compromise to North Korean actor Sapphire Sleet. Here is what SMBs and government contractors should do about AI framework supply-chain risk.
Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk
Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.
DPRK Threat Actors Leverage GitHub as Command and Control Infrastructure in Multi-Stage LNK Attacks
North Korean state-sponsored threat actors have been observed targeting South Korean organizations with a sophisticated multi-stage attack chain that abuses GitHub as command and control (C2) infrastructure. Fortinet FortiGuard Labs published research on April 2, 2026 detailing t
Iranian Threat Intelligence
View all Iranian intel →Iranian PLC Exploitation Shows Why OT Remote Access Is Now a Board-Level Risk
Federal agencies warn Iranian-affiliated actors are exploiting internet-exposed PLCs across U.S. critical infrastructure. Here is what SMBs, municipalities, utilities, and government contractors should do first.
APT34 Shows Why Identity Infrastructure Is Iran’s Quietest Attack Path
KELA’s APT34/OilRig reporting shows why Iranian espionage risk is increasingly an identity, Exchange, DNS, and trusted-infrastructure problem — not just a malware problem.
Project CAV3RN Turns Outlook Calendars and DNS Into Covert C2
Kaspersky reported a Project CAV3RN module that abuses Microsoft Outlook calendar events and DNS AAAA records for covert command-and-control. Here is what SMBs and government contractors should monitor in Microsoft Graph, Entra ID, endpoint, and DNS logs.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
Daxin and Stupig Show Why Legacy Access Paths Matter in Manufacturing Defense
Symantec and Carbon Black found China-linked Daxin active in a Taiwan high-tech manufacturing environment alongside a new pre-login SYSTEM backdoor. Here is what defenders should take from it.
SharePoint KEV Listing Turns Collaboration Servers Into Incident-Response Priorities
CISA added exploited SharePoint Server RCE CVE-2026-58644 to KEV. Here is what SMBs and government contractors should do beyond patching.
FortiSandbox KEV Listing Turns Patch Lag Into Security-Control Risk
CISA added two FortiSandbox OS command injection flaws to KEV. Here is what SMBs and government contractors should do before patch lag becomes compromise.
Siemens ROX II Zero-Day Chain Shows Why OT Switches Need Asset-Level Defense
Unit 42 disclosed three Siemens ROX II vulnerabilities that can be chained from file disclosure to root access and persistence. Here is what SMBs, industrial operators, and government contractors should do now.
Newsletter
The Bulwark Brief.
Cyber threat intel, AI, and tech worth your attention, what we're tracking that day, with a "why it matters" line on every item. Most weekdays. No fluff.