Skip to content
Wednesday, June 17, 2026
  • Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure
  • Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation
  • FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target
  • Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure
  • Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation
  • FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target
  • Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.

    Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

    3 days ago
  • Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.

    Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

    4 days ago
  • Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.

    FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

    4 days ago
  • Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.

    Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

    4 days ago
  • Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.

    Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

    5 days ago
  • Editorial cybersecurity illustration of a government breach notification portal being checked for fake disclosure submissions.

    Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls

    5 days ago
  • Editorial cybersecurity illustration showing Portainer container management risk and host takeover controls.

    Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults

    5 days ago
  • Editorial cybersecurity illustration showing an AI browser extension side panel exposing authenticated web sessions.

    MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk

    6 days ago
  • Cyber threat intelligence illustration of defenders monitoring ERP and PeopleSoft administrative endpoints under active exploitation.

    ShinyHunters PeopleSoft Exploitation Shows ERP Admin Endpoints Are Breach Surface

    6 days ago
  • Abstract cybersecurity illustration of AI agent memory, database checkpoints, and remote code execution risk.

    LangGraph Checkpointer Bugs Show AI Agent Memory Is Backend Attack Surface

    6 days ago
Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
  • AI (General)
  • Cyber Security Blog
3 days ago

Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.
  • Cyber Security Blog
  • General CTI
4 days ago

Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

Handala’s California Water Service claim is a reminder that critical-infrastructure defense starts with proving separation between billing systems, telemetry platforms, and operational technology.

Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.
  • Cyber Security Blog
  • General CTI
4 days ago

FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

Fortinet CVE-2026-49938 is a medium-severity FortiPortal API access-control issue, but sensitive network configuration exposure can still give attackers a valuable map of the environment.

Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
4 days ago

Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

Velvet Ant’s Operation Highland shows why PAM, OpenSSH, jump hosts, and proxy paths deserve the same defensive priority as identity providers and domain controllers.

FBI Confirms Handala Hackers Breached Director Patel’s Personal Email Account
  • Iranian Cyber Threat Intelligence

FBI Confirms Handala Hackers Breached Director Patel’s Personal Email Account

Vibe Coding Gone Wrong: Moltbook AI Social Network Exposes 4.75 Million Records in Massive Database Breach
  • General CTI

Vibe Coding Gone Wrong: Moltbook AI Social Network Exposes 4.75 Million Records in Massive Database Breach

Russian Legion Hacker Alliance Launches OpDenmark Campaign Against Danish Critical Infrastructure
  • Russian Cyber Threat Intelligence

Russian Legion Hacker Alliance Launches OpDenmark Campaign Against Danish Critical Infrastructure

Infostealer Infection Unmasks DPRK Operative Behind Polyfill.io Supply Chain Attack and US Crypto Exchange Infiltration
  • North Korean Cyber Threat Intelligence

Infostealer Infection Unmasks DPRK Operative Behind Polyfill.io Supply Chain Attack and US Crypto Exchange Infiltration

Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

acint3 days ago03 mins

The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

Read More
Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Operational Technology (OT)
  • Privacy & Security

Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

acint4 days ago03 mins

Handala’s California Water Service claim is a reminder that critical-infrastructure defense starts with proving separation between billing systems, telemetry platforms, and operational technology.

Read More
Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

acint4 days ago04 mins

Fortinet CVE-2026-49938 is a medium-severity FortiPortal API access-control issue, but sensitive network configuration exposure can still give attackers a valuable map of the environment.

Read More
Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

acint4 days ago04 mins

Velvet Ant’s Operation Highland shows why PAM, OpenSSH, jump hosts, and proxy paths deserve the same defensive priority as identity providers and domain controllers.

Read More
Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

acint5 days ago04 mins

Zscaler ThreatLabz says the Shai-Hulud campaign has expanded across package ecosystems and introduced prompt-injection tactics aimed at automated AI security triage. The defense lesson is simple: treat package content as hostile input, even when an LLM is doing the review.

Read More
Editorial cybersecurity illustration of a government breach notification portal being checked for fake disclosure submissions.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security
  • Social Engineering

Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls

acint5 days ago03 mins

Maine took its public breach notification database offline after fake disclosures were published. The lesson for SMBs and government contractors: public trust workflows need verification, moderation, and correction controls.

Read More
Editorial cybersecurity illustration showing Portainer container management risk and host takeover controls.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults

acint5 days ago03 mins

intWave disclosed CVE-2026-33590 in Portainer, where insecure default Docker security settings could let regular users escalate toward host takeover. Here is what SMBs and government contractors should lock down.

Read More
Editorial cybersecurity illustration showing an AI browser extension side panel exposing authenticated web sessions.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk

acint6 days ago05 mins

Rebora disclosed MaXSS and Spyder, two critical flaws in AI browser-extension side panels. The lesson for SMBs and government contractors: browser extensions are endpoint software with identity-session reach and need governance.

Read More
Cyber threat intelligence illustration of defenders monitoring ERP and PeopleSoft administrative endpoints under active exploitation.
  • Cyber Security Blog
  • General CTI

ShinyHunters PeopleSoft Exploitation Shows ERP Admin Endpoints Are Breach Surface

acint6 days ago03 mins

GTIG and Mandiant report active ShinyHunters exploitation of Oracle PeopleSoft CVE-2026-35273. Here is what defenders should lock down, hunt, and segment now.

Read More
Abstract cybersecurity illustration of AI agent memory, database checkpoints, and remote code execution risk.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

LangGraph Checkpointer Bugs Show AI Agent Memory Is Backend Attack Surface

acint6 days ago04 mins

Check Point Research disclosed LangGraph checkpointer flaws that could turn user-controlled state-history filters into SQL injection, unsafe deserialization, and remote code execution. The lesson for SMBs and government contractors: AI agent memory is application infrastructure, not magic middleware.

Read More
  • 1
  • 2
  • 3
  • …
  • 36

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

26e0a5a081

You May Have Missed

    Steaelite RAT Bundles Ransomware and Data Theft in Single Web Panel for Double Extortion Attacks

    acint 4 months ago
    • Chinese Cyber Threat Intelligence

    Unit 42 Exposes Active Exploitation of BeyondTrust CVE-2026-1731 with VShell and SparkRAT Backdoors

    acint 4 months ago
    Editorial illustration of AI literacy, database fundamentals, and rural cybersecurity support.
    • AI (General)
    • Cyber Security Blog

    AI Literacy Needs Fundamentals: Teaching Technology in the Real World

    acint 1 month ago4 weeks ago
    Editorial cybersecurity illustration of exposed AI applications and cloud-native workloads at risk from misconfiguration
    • AI (General)
    • Cyber Security Blog

    Exposed AI Apps Turn Misconfiguration Into RCE Risk

    acint 1 month ago
    • Business

    Google Disrupts World’s Largest Residential Proxy Botnet

    acint 5 months ago5 months ago

      LockBit 5.0 Ransomware Emerges: Cross-Platform Threat Targeting Windows, Linux, and ESXi Systems

      acint 4 months ago
      • Business

      CISA Confirms VMware ESXi Flaw CVE-2025-22225 Now Exploited in Active Ransomware Campaigns

      acint 4 months ago
      Satellite over Earth with glowing geospatial data streams representing NASA Prithvi AI in orbit
      • Makes you Think

      NASA Put a Geospatial AI Foundation Model in Orbit — That Should Make You Think

      acint 1 month ago
      2026 Powered By BlazeThemes.