Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →Cyclops Blink on Cisco FMC Shows Why Edge Appliances Need Compromise Review
Sophos CTU and Cisco Talos reporting on Cyclops Blink activity against Cisco Secure FMC shows why edge security appliances need compromise review, not just emergency patching.
OWAReaper Shows Why Exchange Mailboxes Need Post-Patch Compromise Review
Resecurity’s OWAReaper report shows why on-prem Exchange response cannot stop at patching: defenders need mailbox-permission audits, token revocation, OWA exposure control, and post-patch compromise review.
Russian Auth-Flow Phishing Shows MFA Can Be Bypassed Without Exploits
Russian-linked clusters are abusing app passwords, OAuth consent, device-code login, WhatsApp linking, and captive portals. The defense is visibility and governance around authorization flows—not just MFA at login.
Chinese Threat Intelligence
View all Chinese intel →Dutch Warning on Chinese Edge-Device Attacks Shows Why Firewall Logs Must Leave the Firewall
A Dutch AIVD/MIVD/NCSC advisory warns that Chinese actors are expected to intensify edge-device exploitation. For SMBs and government contractors, the priority is centralized logging, segmentation, forensic readiness, and faster perimeter patch decisions.
UAT-11985 Shows AI-Assisted Phishing Is Now Real-Time Account Takeover
Cisco Talos reported an APT campaign using AI-assisted event lures, malicious QR codes, and real-time Google AitM phishing. The defensive answer is phishing-resistant MFA, invitation verification, and identity telemetry that connects clicks to sessions.
Antino Backdoor Shows Why Microsoft 365 C2 Needs Cloud-Aware Detection
Cisco Talos reports China-nexus UAT-11587 used the Antino backdoor with Outlook and OneDrive as command-and-control channels. Here is what SMB and government-contractor defenders should monitor.
North Korean Threat Intelligence
View all North Korean intel →Trojanized Terraform Providers Show IaC Pipelines Are Developer Endpoints
Zscaler ThreatLabz detailed a suspected TraderTraitor campaign using a fake Terraform provider to launch cross-platform malware. The practical lesson: infrastructure-as-code plugins run on developer and CI/CD systems, so they need endpoint controls, provenance checks, and egress monitoring.
Web3 C2 Shows Why Build Pipelines Need Egress Controls
Unit 42 warns that supply-chain malware is using Web3 infrastructure to hide command-and-control while stealing cloud credentials from developer workstations and CI/CD runners.
Ted Backdoor Shows Why Edge Load Balancers Need Compromise Review
Rapid7’s DPRK-attributed ted backdoor and curlRAT research shows why HAProxy, SSH, cron, and other Linux edge services need integrity checks, centralized logs, and post-compromise review.
Iranian Threat Intelligence
View all Iranian intel →Blinder Tunnel Shows How Developer Trust Becomes Critical Infrastructure Risk
Unit 42 reports an Iran-nexus campaign using fake Dubai Airports recruitment lures, weaponized Visual Studio projects, GitHub-based command-and-control, and tunneling tools against Iraqi critical infrastructure. The lesson for SMBs and government contractors: developer workflows need the same identi
NodeRabbit and PollCat Show Why Developer Workstations Need Recruiting-Lure Controls
Mirage Kitten’s NodeRabbit and PollCat malware campaigns show why fake recruiter coding tests are a practical workstation, credential, and supply-chain risk for SMBs and government contractors.
HOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 Battlefield
Group-IB’s HOLLOWGRAPH research shows how attackers can turn Microsoft 365 calendars, Graph API traffic, and DNS into covert command-and-control. Here is what SMBs and government contractors should hunt for now.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
Apache Thrift 61-CVE Patch Shows Why RPC Frameworks Need Inventory
Apache Thrift 0.25.0 fixes 61 vulnerabilities across multiple language bindings. Defenders should treat this as an RPC exposure and software-inventory problem, not just another library bump.
NIST OT Zero Trust Guidance Shows Segmentation Must Reach Below Level 3
NIST SP 800-82r4 brings zero trust into OT guidance, but defenders need local segmentation and access controls below Purdue Level 3 where controllers, HMIs, and engineering authority live.
Milk Dragon Shows Social Commerce Phishing Needs Identity and Payment Controls
Group-IB’s Milk Dragon research shows how shopping-discount lures on social media can become adversary-in-the-middle phishing and payment-card theft. SMBs and government contractors should treat social commerce fraud as an identity, brand, and payment-risk problem — not just user awareness.
Cisco SD-WAN Auth Bypass Shows Edge Control Planes Need Emergency Review
Cisco says CVE-2026-76504 is being actively exploited against Catalyst SD-WAN Manager, giving unauthenticated attackers admin-level API access. Edge management systems need emergency patching, exposure reduction, and compromise review.
Newsletter
The House-Of-L Brief.
Two short reads a day. Mornings cover markets, cyber threats, and what changed overnight. Evenings cover how AI, energy, and geopolitics are moving the world. A "why it matters" line on every story. A roundup every Sunday.
readers get The Brief
Double opt-in. One-click unsubscribe on every issue. We never share your address.



