Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →This Week in Threats
Latest Threat Intelligence
Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →TA458 Half-Click Webmail Exploits Show Why Mail Servers Need Priority Hardening
Proofpoint reporting on TA458 shows how half-click webmail exploits turn mail servers into espionage targets. Here is what SMBs and government contractors should harden first.
Russian Router Targeting Shows Why Edge Hygiene Is a DIB Priority
CISA and allied agencies warn that Russian FSB Center 16 actors continue targeting poorly configured routers and network devices. Here is what SMBs and government contractors should fix first.
Russian Router Targeting Shows Why Edge Hygiene Is a Mission Requirement
A joint CISA, NSA, FBI, and allied advisory says Russian FSB Center 16 actors continue exploiting poorly configured routers. Here is what SMBs and government contractors should prioritize now.
Chinese Threat Intelligence
View all Chinese intel →Project ORBITAL Maps the Edge-Device Relay Networks Hiding APT Traffic
Project ORBITAL tracks Operational Relay Box networks used by advanced threat actors to hide activity behind compromised SOHO routers, IoT devices, and other neglected edge infrastructure.
JadeProx Shows Why China-Nexus Intrusions Still Start With Basic Exposure
Group-IB’s JadeProx reporting shows how China-nexus operators combined exposed services, DLL sideloading, phishing infrastructure, and TriBack Loader. Here is what SMBs and government contractors should hunt first.
Daxin and Stupig Show Why Legacy Access Paths Matter in Manufacturing Defense
Symantec and Carbon Black found China-linked Daxin active in a Taiwan high-tech manufacturing environment alongside a new pre-login SYSTEM backdoor. Here is what defenders should take from it.
North Korean Threat Intelligence
View all North Korean intel →Mastra npm Compromise Shows AI Frameworks Are Supply-Chain Targets
Microsoft linked the Mastra AI npm package compromise to North Korean actor Sapphire Sleet. Here is what SMBs and government contractors should do about AI framework supply-chain risk.
Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk
Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.
DPRK Threat Actors Leverage GitHub as Command and Control Infrastructure in Multi-Stage LNK Attacks
North Korean state-sponsored threat actors have been observed targeting South Korean organizations with a sophisticated multi-stage attack chain that abuses GitHub as command and control (C2) infrastructure. Fortinet FortiGuard Labs published research on April 2, 2026 detailing t
Iranian Threat Intelligence
View all Iranian intel →Iranian PLC Exploitation Shows Why OT Remote Access Is Now a Board-Level Risk
Federal agencies warn Iranian-affiliated actors are exploiting internet-exposed PLCs across U.S. critical infrastructure. Here is what SMBs, municipalities, utilities, and government contractors should do first.
APT34 Shows Why Identity Infrastructure Is Iran’s Quietest Attack Path
KELA’s APT34/OilRig reporting shows why Iranian espionage risk is increasingly an identity, Exchange, DNS, and trusted-infrastructure problem — not just a malware problem.
Project CAV3RN Turns Outlook Calendars and DNS Into Covert C2
Kaspersky reported a Project CAV3RN module that abuses Microsoft Outlook calendar events and DNS AAAA records for covert command-and-control. Here is what SMBs and government contractors should monitor in Microsoft Graph, Entra ID, endpoint, and DNS logs.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
Hugging Face Breach Shows AI Pipelines Are Now Production Attack Surface
Hugging Face disclosed a July 2026 production intrusion driven end-to-end by an autonomous AI agent. The lesson for defenders: AI data pipelines, token scopes, cluster admission controls, and incident-response model strategy now belong in the same risk conversation.
TELESHIM Shows Why Telegram C2 Belongs in Government Intrusion Hunts
Zscaler reported a targeted Middle East government intrusion using TELESHIM, MIXEDKEY, BINDCLOAK, DLL side-loading, scheduled tasks, and Telegram API C2. Here is what defenders should hunt for.
GoSerpent Shows Why Quiet Data Collection Is the Real Espionage Risk
Kaspersky’s GoSerpent research shows an espionage chain built around long-term access, credential dumping, staged document collection, and delayed exfiltration. For SMBs and government contractors, the lesson is simple: watch for quiet collection behavior before the data leaves.
NGINX CVE-2026-42533 Turns Reverse Proxy Configs Into Patch Priorities
CVE-2026-42533 is a critical NGINX heap buffer overflow tied to regex map and capture handling. For defenders, the lesson is bigger than one patch: internet-facing reverse proxies need version control, config review, and fast rollback-ready upgrade paths.
Newsletter
The Bulwark Brief.
Cyber threat intel, AI, and tech worth your attention, what we're tracking that day, with a "why it matters" line on every item. Most weekdays. No fluff.