Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →Russian Auth-Flow Phishing Shows MFA Can Be Bypassed Without Exploits
Russian-linked clusters are abusing app passwords, OAuth consent, device-code login, WhatsApp linking, and captive portals. The defense is visibility and governance around authorization flows—not just MFA at login.
CaptiveCrunch Shows Why Travel Wi-Fi Is an Identity Attack Surface
Zscaler reports that Midnight Blizzard operators are abusing hotel and conference Wi-Fi captive portals for Microsoft 365 credential theft, device-code phishing, and malware delivery. Here is what SMBs and government contractors should harden first.
TA488 Turns Outlook Web Access Into a Stealthy Persistence Layer
Proofpoint reports Russia-aligned TA488 abused an Outlook Web Access XSS flaw to deploy OWAReaper, a browser-based implant that can persist beyond passwords and endpoint rebuilds.
Chinese Threat Intelligence
View all Chinese intel →vCenter Exploitation Shows Why Control Planes Need Containment
Active exploitation of CVE-2026-59310 shows why vCenter needs more than fast patching: control-plane containment, egress limits, and compromise assessment matter.
HoneyMyte’s CoolClient Rootkit Shows Why Kernel Visibility Matters
HoneyMyte’s CoolClient backdoor now includes signed kernel-mode rootkit capabilities, raising the bar for driver monitoring, Defender exclusion review, and post-compromise endpoint validation.
Pakistani Police Intrusions Show Why Public-Sector Data Systems Are Strategic Targets
SentinelLabs reporting on rival espionage activity against Pakistani law enforcement is a reminder that public-sector portals, case systems, and citizen-data apps are strategic intelligence targets — even when they are not classified systems.
North Korean Threat Intelligence
View all North Korean intel →PurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk Control
Recorded Future’s PurpleDelta research shows North Korean IT worker operations using fabricated personas, AI-assisted interviews, remote desktop tooling, and facilitators to enter legitimate remote technical roles. Defenders should treat hiring, identity proofing, endpoint onboarding, and contractor access as one security workflow.
Lazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day Intrusion
Check Point Research reports a new Lazarus Operation Dream Job wave using fake recruiting lures, trojanized PDF tooling, Microsoft Graph/OneDrive C2, Roundcube relay infrastructure, and the patched CVE-2026-68820 Windows AFD.sys zero-day.
DPRK npm Compromises Show Why Dependency Trust Is Now Identity Risk
Amazon linked compromises of popular npm packages to a DPRK-linked actor. The defensive lesson for SMBs and government contractors: dependency risk is no longer just code review — it is maintainer identity, build-pipeline behavior, and runtime trust.
Iranian Threat Intelligence
View all Iranian intel →HOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 Battlefield
Group-IB’s HOLLOWGRAPH research shows how attackers can turn Microsoft 365 calendars, Graph API traffic, and DNS into covert command-and-control. Here is what SMBs and government contractors should hunt for now.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
Iran-linked MuddyWater activity shows why ransomware response needs to examine identity compromise, remote access, and adversary objectives instead of trusting the ransom note at face value.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
HoneyMyte’s CoolClient Rootkit Shows Why Kernel Visibility Matters
HoneyMyte’s CoolClient backdoor now includes signed kernel-mode rootkit capabilities, raising the bar for driver monitoring, Defender exclusion review, and post-compromise endpoint validation.
JWR Phishing Framework Shows Why MFA Codes Are Now Live Targets
Cisco Talos documented JWR, a real-time phishing framework that lets operators steer victims through fake checkout and login flows while harvesting credentials, payment data, OTPs, identity documents, and device fingerprints. For SMBs and government contractors, the lesson is direct: MFA codes are n
Evooo1Bot Shows Why Exposed Linux and Edge Devices Are Still High-Value Targets
FortiGuard Labs documented Evooo1Bot, a Linux botnet combining Mirai-style DDoS with SSH brute forcing, SOCKS relay, credential sniffing, persistence, and exploit-driven infection of exposed devices.
Malware Crypting Services Show Why Behavioral Detection Matters
Recorded Future’s look at malware crypting services shows why SMBs and government contractors need behavioral detection, endpoint telemetry, and incident response—not just clean file scans.
Newsletter
The House-Of-L Brief.
Two short reads a day. Mornings cover markets, cyber threats, and what changed overnight. Evenings cover how AI, energy, and geopolitics are moving the world. A "why it matters" line on every story. A roundup every Sunday.
readers get The Brief
Double opt-in. One-click unsubscribe on every issue. We never share your address.