Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →Cyclops Blink on Cisco FMC Shows Why Edge Appliances Need Compromise Review
Sophos CTU and Cisco Talos reporting on Cyclops Blink activity against Cisco Secure FMC shows why edge security appliances need compromise review, not just emergency patching.
OWAReaper Shows Why Exchange Mailboxes Need Post-Patch Compromise Review
Resecurity’s OWAReaper report shows why on-prem Exchange response cannot stop at patching: defenders need mailbox-permission audits, token revocation, OWA exposure control, and post-patch compromise review.
Russian Auth-Flow Phishing Shows MFA Can Be Bypassed Without Exploits
Russian-linked clusters are abusing app passwords, OAuth consent, device-code login, WhatsApp linking, and captive portals. The defense is visibility and governance around authorization flows—not just MFA at login.
Chinese Threat Intelligence
View all Chinese intel →Antino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware Detection
Cisco Talos reports China-nexus UAT-11587 used the Antino backdoor with Outlook and OneDrive as command-and-control channels. Here is what SMB and government-contractor defenders should monitor.
Warlock Ransomware Shows SharePoint Is Still Critical Infrastructure Risk
Recorded Future News and Symantec report China-nexus Warlock ransomware attacks against water, telecom, government, and university targets. Here is what SMB and government-contractor defenders should do about exposed SharePoint risk.
TA419 Shows AI Policy Is Now an Espionage Phishing Target
Proofpoint reports China-aligned TA419 is targeting U.S. AI policy experts with identity impersonation and adversary-in-the-middle phishing. Here is what SMBs, law firms, universities, and government contractors should take from it.
North Korean Threat Intelligence
View all North Korean intel →Ted Backdoor Shows Why Edge Load Balancers Need Compromise Review
Rapid7’s DPRK-attributed ted backdoor and curlRAT research shows why HAProxy, SSH, cron, and other Linux edge services need integrity checks, centralized logs, and post-compromise review.
Nisos DPRK Investigation Shows Why Remote Hiring Is a Security Control
Nisos’ DPRK employment-fraud investigation shows why remote hiring, contractor onboarding, identity verification, and access control now belong in the same security conversation.
PurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk Control
Recorded Future’s PurpleDelta research shows North Korean IT worker operations using fabricated personas, AI-assisted interviews, remote desktop tooling, and facilitators to enter legitimate remote technical roles. Defenders should treat hiring, identity proofing, endpoint onboarding, and contractor access as one security workflow.
Iranian Threat Intelligence
View all Iranian intel →NodeRabbit and PollCat Show Why Developer Workstations Need Recruiting-Lure Controls
Mirage Kitten’s NodeRabbit and PollCat malware campaigns show why fake recruiter coding tests are a practical workstation, credential, and supply-chain risk for SMBs and government contractors.
HOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 Battlefield
Group-IB’s HOLLOWGRAPH research shows how attackers can turn Microsoft 365 calendars, Graph API traffic, and DNS into covert command-and-control. Here is what SMBs and government contractors should hunt for now.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
PeopleSoft WAF Bypass Shows Why Patch-First Beats Perimeter Rules
GTIG/Mandiant report renewed PeopleSoft exploitation using encoded-path WAF bypasses. Here is what defenders should validate beyond perimeter string matching.
Storm-3168 Shows Why Service Principals Are Cloud Ransomware Risk
Microsoft’s Storm-3168 reporting shows how compromised Azure service principals can drive fast cloud destruction, credential collection, and recovery sabotage. Here is what SMB and government-contractor defenders should tighten first.
Lunex Stealer Shows BYOVD Is Moving Into Credential Theft
Lunex/Psychedelic Stealer uses BYOVD tradecraft to blind endpoint security before stealing browser credentials, cookies, and wallet data. Here is what SMB and government-contractor defenders should prioritize.
Storm-2570 Shows Why Ransomware Defense Should Track Tradecraft, Not Payloads
Microsoft’s Storm-2570 reporting shows why defenders should track ransomware affiliate behavior: RMM abuse, tunnels, credential theft, lateral movement, security tampering, and cloud exfiltration before encryption.
Newsletter
The House-Of-L Brief.
Two short reads a day. Mornings cover markets, cyber threats, and what changed overnight. Evenings cover how AI, energy, and geopolitics are moving the world. A "why it matters" line on every story. A roundup every Sunday.
readers get The Brief
Double opt-in. One-click unsubscribe on every issue. We never share your address.



