Skip to content
Thursday, June 18, 2026
  • SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk
  • Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity
  • Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure
  • Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk
  • Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity
  • Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure
  • Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack

    SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

    42 minutes ago
  • Editorial cybersecurity illustration of a Tor-based crypto clipper spreading through USB shortcuts and stealing clipboard wallet data.

    Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity

    15 hours ago
  • Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.

    Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

    4 days ago
  • Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.

    Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

    5 days ago
  • Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.

    FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

    5 days ago
  • Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.

    Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

    5 days ago
  • Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.

    Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

    6 days ago
  • Editorial cybersecurity illustration of a government breach notification portal being checked for fake disclosure submissions.

    Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls

    6 days ago
  • Editorial cybersecurity illustration showing Portainer container management risk and host takeover controls.

    Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults

    6 days ago
  • Editorial cybersecurity illustration showing an AI browser extension side panel exposing authenticated web sessions.

    MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk

    7 days ago
Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack
  • Cyber Security Blog
  • General CTI
42 minutes ago

SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

Zscaler ThreatLabz reported that SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, creating downstream exposure across e-commerce sites. Here is what SMBs and government contractors should do about third-party browser code risk.

Editorial cybersecurity illustration of a Tor-based crypto clipper spreading through USB shortcuts and stealing clipboard wallet data.
  • Cyber Security Blog
  • General CTI
15 hours ago

Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity

Microsoft research on a Tor-routed crypto clipper shows why defenders should connect USB shortcut execution, script interpreters, localhost proxy activity, and clipboard theft into one investigation path.

Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
  • AI (General)
  • Cyber Security Blog
4 days ago

Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.
  • Cyber Security Blog
  • General CTI
5 days ago

Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

Handala’s California Water Service claim is a reminder that critical-infrastructure defense starts with proving separation between billing systems, telemetry platforms, and operational technology.

287 Chrome Extensions Caught Exfiltrating Browsing History from 37.4 Million Users
  • General CTI

287 Chrome Extensions Caught Exfiltrating Browsing History from 37.4 Million Users

ShinyHunters Claims 350GB Data Theft from European Commission’s AWS Cloud Infrastructure

    ShinyHunters Claims 350GB Data Theft from European Commission’s AWS Cloud Infrastructure

    Open-Source CyberStrikeAI Tool Weaponized in AI-Driven FortiGate Attacks Across 55 Countries

      Open-Source CyberStrikeAI Tool Weaponized in AI-Driven FortiGate Attacks Across 55 Countries

      Google Patches Two Chrome Zero-Days Actively Exploited in the Wild, CISA Adds to KEV Catalog
      • General CTI

      Google Patches Two Chrome Zero-Days Actively Exploited in the Wild, CISA Adds to KEV Catalog

      Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack
      • Cyber Security Blog
      • General CTI
      • Malware
      • Social Engineering

      SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

      acint42 minutes ago03 mins

      Zscaler ThreatLabz reported that SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, creating downstream exposure across e-commerce sites. Here is what SMBs and government contractors should do about third-party browser code risk.

      Read More
      Editorial cybersecurity illustration of a Tor-based crypto clipper spreading through USB shortcuts and stealing clipboard wallet data.
      • Cyber Security Blog
      • General CTI
      • Malware
      • Privacy & Security

      Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity

      acint15 hours ago05 mins

      Microsoft research on a Tor-routed crypto clipper shows why defenders should connect USB shortcut execution, script interpreters, localhost proxy activity, and clipboard theft into one investigation path.

      Read More
      Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
      • AI (General)
      • Cyber Security Blog
      • General CTI
      • Privacy & Security

      Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

      acint4 days ago03 mins

      The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

      Read More
      Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.
      • Cyber Security Blog
      • General CTI
      • Iranian Cyber Threat Intelligence
      • Operational Technology (OT)
      • Privacy & Security

      Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

      acint5 days ago03 mins

      Handala’s California Water Service claim is a reminder that critical-infrastructure defense starts with proving separation between billing systems, telemetry platforms, and operational technology.

      Read More
      Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.
      • Cyber Security Blog
      • General CTI
      • Privacy & Security

      FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

      acint5 days ago04 mins

      Fortinet CVE-2026-49938 is a medium-severity FortiPortal API access-control issue, but sensitive network configuration exposure can still give attackers a valuable map of the environment.

      Read More
      Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.
      • Chinese Cyber Threat Intelligence
      • Cyber Security Blog
      • General CTI
      • Privacy & Security

      Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

      acint5 days ago04 mins

      Velvet Ant’s Operation Highland shows why PAM, OpenSSH, jump hosts, and proxy paths deserve the same defensive priority as identity providers and domain controllers.

      Read More
      Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.
      • AI (General)
      • Cyber Security Blog
      • General CTI
      • Malware
      • Privacy & Security

      Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

      acint6 days ago04 mins

      Zscaler ThreatLabz says the Shai-Hulud campaign has expanded across package ecosystems and introduced prompt-injection tactics aimed at automated AI security triage. The defense lesson is simple: treat package content as hostile input, even when an LLM is doing the review.

      Read More
      Editorial cybersecurity illustration of a government breach notification portal being checked for fake disclosure submissions.
      • Cyber Security Blog
      • General CTI
      • Privacy & Security
      • Social Engineering

      Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls

      acint6 days ago03 mins

      Maine took its public breach notification database offline after fake disclosures were published. The lesson for SMBs and government contractors: public trust workflows need verification, moderation, and correction controls.

      Read More
      Editorial cybersecurity illustration showing Portainer container management risk and host takeover controls.
      • Cyber Security Blog
      • General CTI
      • Privacy & Security

      Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults

      acint6 days ago03 mins

      intWave disclosed CVE-2026-33590 in Portainer, where insecure default Docker security settings could let regular users escalate toward host takeover. Here is what SMBs and government contractors should lock down.

      Read More
      Editorial cybersecurity illustration showing an AI browser extension side panel exposing authenticated web sessions.
      • AI (General)
      • Cyber Security Blog
      • General CTI
      • Privacy & Security

      MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk

      acint7 days ago05 mins

      Rebora disclosed MaXSS and Spyder, two critical flaws in AI browser-extension side panels. The lesson for SMBs and government contractors: browser extensions are endpoint software with identity-session reach and need governance.

      Read More
      • 1
      • 2
      • 3
      • …
      • 36

      File Search

      2
      ThumbNameSizeDate
      Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

      IOCs_YARA_TTPs_Posted_Articles

      Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
      21 Items
      99.71 KB
      March 22, 2024

      0

      c1f1398615

      You May Have Missed

      • Malware

      PDFSider: The Stealthy Backdoor Targeting Fortune 100 Financial Institutions

      acint 4 months ago
      • Iranian Cyber Threat Intelligence

      FBI Flash Alert: Iranian Handala Hackers Weaponize Telegram for Malware C2 Operations

      acint 3 months ago
      • Chinese Cyber Threat Intelligence

      Hide and Seek in Windows’ Closet: Unmasking the WinSxS Hijacking Hideout

      bulwarkblack 2 years ago2 years ago
      • General CTI

      CVE-2026-33017: Critical Langflow AI Platform Flaw Exploited Within 20 Hours of Disclosure

      acint 3 months ago
      Editorial cybersecurity illustration of Void Dokkaebi InvisibleFerret developer endpoint malware risk
      • Cyber Security Blog
      • Malware

      Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk

      acint 4 weeks ago
      • General CTI

      SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

      acint 5 months ago
      • Malware

      JavaScript Malware: 50,000+ Bank Users at Risk Worldwide

      bulwarkblack 2 years ago2 years ago
      • Projects

      Velvet Tempest Ransomware Group Deploys CastleRAT via ClickFix Attacks Linked to Termite Operations

      acint 3 months ago
      2026 Powered By BlazeThemes.