Skip to content
Friday, June 19, 2026
  • Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review
  • FortiBleed Shows Firewall Patching Is Not Compromise Recovery
  • Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene
  • SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review
  • FortiBleed Shows Firewall Patching Is Not Compromise Recovery
  • Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene
  • SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration of an API gateway identity bypass risk for Apache APISIX authentication plugins.

    Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review

    6 minutes ago
  • Editorial cybersecurity illustration of compromised firewall perimeter devices leaking credential streams into command infrastructure.

    FortiBleed Shows Firewall Patching Is Not Compromise Recovery

    14 hours ago
  • Professional cybersecurity illustration of Secure Boot, UEFI firmware, and DBX revocation defense.

    Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene

    19 hours ago
  • Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack

    SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

    1 day ago
  • Editorial cybersecurity illustration of a Tor-based crypto clipper spreading through USB shortcuts and stealing clipboard wallet data.

    Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity

    2 days ago
  • Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.

    Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

    5 days ago
  • Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.

    Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

    6 days ago
  • Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.

    FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

    6 days ago
  • Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.

    Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

    6 days ago
  • Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.

    Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

    7 days ago
Editorial cybersecurity illustration of an API gateway identity bypass risk for Apache APISIX authentication plugins.
  • Cyber Security Blog
  • General CTI
6 minutes ago

Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review

Apache disclosed a cluster of APISIX authentication and identity plugin CVEs. The defensive priority is patching, plugin inventory, and validating what backend services trust from the gateway.

Editorial cybersecurity illustration of compromised firewall perimeter devices leaking credential streams into command infrastructure.
  • Cyber Security Blog
  • General CTI
14 hours ago

FortiBleed Shows Firewall Patching Is Not Compromise Recovery

FortiBleed is a reminder that edge firewall patching is necessary, but it does not prove a previously exposed appliance is clean. Defenders need compromise review, credential rotation, and rebuild plans for perimeter devices.

Professional cybersecurity illustration of Secure Boot, UEFI firmware, and DBX revocation defense.
  • Cyber Security Blog
  • General CTI
19 hours ago

Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene

CERT/CC warns that multiple vendor-signed UEFI applications can be abused to bypass Secure Boot before the operating system and EDR controls ever load. For SMBs and government contractors, the fix is not just firmware patching; it is verifying DBX revocation coverage across managed endpoints.

Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack
  • Cyber Security Blog
  • General CTI
1 day ago

SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

Zscaler ThreatLabz reported that SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, creating downstream exposure across e-commerce sites. Here is what SMBs and government contractors should do about third-party browser code risk.

Pro-Iranian Hackers Expand Targeting of US Critical Infrastructure as Cyber Chaos Escalates
  • Iranian Cyber Threat Intelligence

Pro-Iranian Hackers Expand Targeting of US Critical Infrastructure as Cyber Chaos Escalates

AiFrame Campaign: 30 Fake AI Chrome Extensions with 300K Users Steal Credentials, Gmail Content
  • Malware

AiFrame Campaign: 30 Fake AI Chrome Extensions with 300K Users Steal Credentials, Gmail Content

Fake Google Security Check Transforms Browser Into Surveillance Toolkit via PWA Installation
  • General CTI
  • Malware

Fake Google Security Check Transforms Browser Into Surveillance Toolkit via PWA Installation

Tool of First Resort: Israel-Hamas War in Cyber
  • Detection
  • General CTI

Tool of First Resort: Israel-Hamas War in Cyber

Editorial cybersecurity illustration of an API gateway identity bypass risk for Apache APISIX authentication plugins.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review

acint6 minutes ago04 mins

Apache disclosed a cluster of APISIX authentication and identity plugin CVEs. The defensive priority is patching, plugin inventory, and validating what backend services trust from the gateway.

Read More
Editorial cybersecurity illustration of compromised firewall perimeter devices leaking credential streams into command infrastructure.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

FortiBleed Shows Firewall Patching Is Not Compromise Recovery

acint14 hours ago04 mins

FortiBleed is a reminder that edge firewall patching is necessary, but it does not prove a previously exposed appliance is clean. Defenders need compromise review, credential rotation, and rebuild plans for perimeter devices.

Read More
Professional cybersecurity illustration of Secure Boot, UEFI firmware, and DBX revocation defense.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene

acint19 hours ago03 mins

CERT/CC warns that multiple vendor-signed UEFI applications can be abused to bypass Secure Boot before the operating system and EDR controls ever load. For SMBs and government contractors, the fix is not just firmware patching; it is verifying DBX revocation coverage across managed endpoints.

Read More
Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack
  • Cyber Security Blog
  • General CTI
  • Malware
  • Social Engineering

SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

acint1 day ago03 mins

Zscaler ThreatLabz reported that SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, creating downstream exposure across e-commerce sites. Here is what SMBs and government contractors should do about third-party browser code risk.

Read More
Editorial cybersecurity illustration of a Tor-based crypto clipper spreading through USB shortcuts and stealing clipboard wallet data.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity

acint2 days ago05 mins

Microsoft research on a Tor-routed crypto clipper shows why defenders should connect USB shortcut execution, script interpreters, localhost proxy activity, and clipboard theft into one investigation path.

Read More
Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

acint5 days ago03 mins

The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

Read More
Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Operational Technology (OT)
  • Privacy & Security

Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

acint6 days ago03 mins

Handala’s California Water Service claim is a reminder that critical-infrastructure defense starts with proving separation between billing systems, telemetry platforms, and operational technology.

Read More
Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

acint6 days ago04 mins

Fortinet CVE-2026-49938 is a medium-severity FortiPortal API access-control issue, but sensitive network configuration exposure can still give attackers a valuable map of the environment.

Read More
Editorial cybersecurity illustration of authentication-stack compromise and critical infrastructure defense for Velvet Ant Operation Highland.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Velvet Ant Shows Authentication Infrastructure Is Critical Infrastructure

acint6 days ago04 mins

Velvet Ant’s Operation Highland shows why PAM, OpenSSH, jump hosts, and proxy paths deserve the same defensive priority as identity providers and domain controllers.

Read More
Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

acint7 days ago04 mins

Zscaler ThreatLabz says the Shai-Hulud campaign has expanded across package ecosystems and introduced prompt-injection tactics aimed at automated AI security triage. The defense lesson is simple: treat package content as hostile input, even when an LLM is doing the review.

Read More
  • 1
  • 2
  • 3
  • …
  • 36

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

b4dff3e918

You May Have Missed

Industrial fuel storage tanks and monitoring screens representing cyber risk to automatic tank gauge systems.
  • Cyber Security Blog
  • General CTI

Fuel Tank Gauge Attacks Show Why Small OT Still Needs Internet Exposure Control

acint 2 weeks ago
  • General CTI

TeamPCP Spreads Trivy Supply Chain Attack to Docker Hub and Kubernetes with Devastating Wiper Payload

acint 3 months ago
  • Malware

Fake Clawdbot VS Code Extension Deploys ScreenConnect RAT

acint 5 months ago5 months ago
  • Malware

SANDWORMMODE: Self-Replicating npm Worm Steals Dev Secrets and Targets AI Coding Tools

acint 4 months ago
Editorial cybersecurity illustration of AI-assisted influence operations, credential theft, and crypto fraud infrastructure.
  • AI (General)
  • Cyber Security Blog

Patriot Bait Shows AI-Enabled Fraud Can Turn Trust Into Attack Surface

acint 4 weeks ago
  • Iranian Cyber Threat Intelligence

FBI Alert: Iranian MOIS Hackers Weaponize Telegram as C2 Channel to Target Dissidents Worldwide

acint 3 months ago
Notepad++ logo representing Chinese state-sponsored supply chain attack
  • Chinese Cyber Threat Intelligence

Chinese APT Lotus Blossom Hijacks Notepad++ Update Mechanism to Deploy Chrysalis Backdoor

acint 5 months ago
  • AI (General)
  • Malware

DeepLoad Malware: AI-Generated Evasion Meets ClickFix Delivery in Enterprise Credential Theft Campaign

acint 3 months ago
2026 Powered By BlazeThemes.