Skip to content
Tuesday, May 26, 2026
  • Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield
  • Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud
  • KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius
  • Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield
  • Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud
  • KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius
  • Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration of a GitHub Actions CI/CD supply chain attack and credential defense

    Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield

    2 hours ago
  • Cybersecurity illustration of real-time phishing-as-a-service intercepting OTP codes and digital wallet tokens.

    Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud

    22 hours ago
  • Cybersecurity illustration of ASP.NET ViewState deserialization and shared machine key risk in a web application environment.

    KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius

    1 day ago
  • Editorial cybersecurity illustration of a PHP Composer supply-chain compromise targeting CI/CD secrets and cloud credentials.

    Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized

    2 days ago
  • Professional cybersecurity illustration of a water utility ransomware intrusion and SOC monitoring gaps.

    Cl0p’s South Staffs Water Case Shows SOC Coverage Must Be Proven

    2 days ago
  • Abstract cybersecurity illustration of cloud identity token abuse, rogue device registration, and defender investigation workflows.

    ROADtools Abuse Shows Cloud Identity Is the New Attack Surface

    2 days ago
  • Editorial cybersecurity illustration of defenders monitoring web application exploitation attempts against Drupal PostgreSQL sites.

    Drupal CVE-2026-9082 Shows Web Asset Inventory Is Emergency Response

    3 days ago
  • Editorial cybersecurity illustration of Void Dokkaebi InvisibleFerret developer endpoint malware risk

    Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk

    3 days ago
  • Editorial cybersecurity illustration of Iranian Nimbus Manticore APT tooling, fake installers, SEO poisoning, and backdoor command-and-control.

    Nimbus Manticore Shows Iranian APTs Are Moving Faster With AI-Assisted Tooling

    4 days ago
  • Editorial cybersecurity illustration of an edge appliance compromise pivoting into Linux, Confluence, and identity systems

    F5-to-Confluence Intrusion Shows Edge Devices Are Identity Attack Paths

    4 days ago
Editorial cybersecurity illustration of a GitHub Actions CI/CD supply chain attack and credential defense
  • Cyber Security Blog
  • General CTI
2 hours ago

Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield

The Megalodon GitHub campaign shows why CI/CD pipelines must be treated like production infrastructure: malicious workflow commits can harvest cloud credentials, OIDC tokens, SSH keys, and package secrets at scale.

Cybersecurity illustration of real-time phishing-as-a-service intercepting OTP codes and digital wallet tokens.
  • Cyber Security Blog
  • General CTI
22 hours ago

Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud

Google’s reporting on Chinese-language phishing-as-a-service shows why MFA bypass, real-time OTP interception, and digital wallet fraud require phishing-resistant authentication and session monitoring.

Cybersecurity illustration of ASP.NET ViewState deserialization and shared machine key risk in a web application environment.
  • Cyber Security Blog
  • General CTI
1 day ago

KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius

Mandiant’s KnowledgeDeliver CVE-2026-5426 report shows how shared ASP.NET machine keys can turn ViewState into unauthenticated RCE and user-facing malware delivery.

Editorial cybersecurity illustration of a PHP Composer supply-chain compromise targeting CI/CD secrets and cloud credentials.
  • Cyber Security Blog
  • General CTI
2 days ago

Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized

A Laravel-Lang package compromise shows why trusted dependency tags, Composer autoload behavior, and runtime secrets need security monitoring—not just engineering review.

Backdoor.Win32 Carbanak (Anunak) / Named Pipe Null DACL
  • Global Cyber Threat Intelligence
  • Russian Cyber Threat Intelligence

Backdoor.Win32 Carbanak (Anunak) / Named Pipe Null DACL

Chapter 84: In-depth analysis and technical analysis of LockBit, the top encryption ransomware organization (Part 1)
  • Malware

Chapter 84: In-depth analysis and technical analysis of LockBit, the top encryption ransomware organization (Part 1)

The Updated APT Playbook: Tales from the Kimsuky threat actor group
  • North Korean Cyber Threat Intelligence

The Updated APT Playbook: Tales from the Kimsuky threat actor group

Hackers Weaponize Claude Code AI to Steal 150GB from Mexican Government in Month-Long Campaign
  • General CTI

Hackers Weaponize Claude Code AI to Steal 150GB from Mexican Government in Month-Long Campaign

Editorial cybersecurity illustration of a GitHub Actions CI/CD supply chain attack and credential defense
  • Cyber Security Blog
  • General CTI
  • Malware

Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield

acint2 hours ago04 mins

The Megalodon GitHub campaign shows why CI/CD pipelines must be treated like production infrastructure: malicious workflow commits can harvest cloud credentials, OIDC tokens, SSH keys, and package secrets at scale.

Read More
Cybersecurity illustration of real-time phishing-as-a-service intercepting OTP codes and digital wallet tokens.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security
  • Social Engineering

Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud

acint22 hours ago04 mins

Google’s reporting on Chinese-language phishing-as-a-service shows why MFA bypass, real-time OTP interception, and digital wallet fraud require phishing-resistant authentication and session monitoring.

Read More
Cybersecurity illustration of ASP.NET ViewState deserialization and shared machine key risk in a web application environment.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius

acint1 day ago04 mins

Mandiant’s KnowledgeDeliver CVE-2026-5426 report shows how shared ASP.NET machine keys can turn ViewState into unauthenticated RCE and user-facing malware delivery.

Read More
Editorial cybersecurity illustration of a PHP Composer supply-chain compromise targeting CI/CD secrets and cloud credentials.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized

acint2 days ago03 mins

A Laravel-Lang package compromise shows why trusted dependency tags, Composer autoload behavior, and runtime secrets need security monitoring—not just engineering review.

Read More
Professional cybersecurity illustration of a water utility ransomware intrusion and SOC monitoring gaps.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Operational Technology (OT)
  • Privacy & Security

Cl0p’s South Staffs Water Case Shows SOC Coverage Must Be Proven

acint2 days ago04 mins

The South Staffordshire Water breach shows why outsourced SOC coverage, legacy server risk, and vulnerability management must be proven—not assumed—for SMBs, utilities, and government contractors.

Read More
Abstract cybersecurity illustration of cloud identity token abuse, rogue device registration, and defender investigation workflows.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

ROADtools Abuse Shows Cloud Identity Is the New Attack Surface

acint2 days ago04 mins

Unit 42’s ROADtools research shows why Microsoft Entra ID token abuse, rogue device registration, and Graph API enumeration need to be treated as core incident-response signals for SMBs and government contractors.

Read More
Editorial cybersecurity illustration of defenders monitoring web application exploitation attempts against Drupal PostgreSQL sites.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Drupal CVE-2026-9082 Shows Web Asset Inventory Is Emergency Response

acint3 days ago03 mins

Drupal CVE-2026-9082 is already being scanned and exploited in the wild. The lesson for SMBs and government contractors: know where your Drupal sites are, verify PostgreSQL exposure, patch fast, and review logs before probing turns into compromise.

Read More
Editorial cybersecurity illustration of Void Dokkaebi InvisibleFerret developer endpoint malware risk
  • Cyber Security Blog
  • Malware
  • North Korean Cyber Threat Intelligence

Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk

acint3 days ago03 mins

Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.

Read More
Editorial cybersecurity illustration of Iranian Nimbus Manticore APT tooling, fake installers, SEO poisoning, and backdoor command-and-control.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Malware

Nimbus Manticore Shows Iranian APTs Are Moving Faster With AI-Assisted Tooling

acint4 days ago04 mins

Check Point Research reports that IRGC-affiliated Nimbus Manticore resurfaced with fake Zoom and SQL Developer lures, SEO poisoning, AppDomain hijacking, and a new MiniFast backdoor. Here is what SMBs and government contractors should tighten first.

Read More
Editorial cybersecurity illustration of an edge appliance compromise pivoting into Linux, Confluence, and identity systems
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

F5-to-Confluence Intrusion Shows Edge Devices Are Identity Attack Paths

acint4 days ago05 mins

Microsoft analyzed an intrusion where an F5 BIG-IP edge appliance led to Linux access, Confluence compromise, credential theft, and identity relay attempts. Here is what SMBs and government contractors should tighten first.

Read More
  • 1
  • 2
  • 3
  • …
  • 32

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

72d16cd13e

You May Have Missed

  • General CTI

Global Coalition Dismantles Tycoon 2FA Phishing Platform: 87 Million Emails, 330 Domains Seized

acint 3 months ago
Professional cybersecurity illustration of a water utility ransomware intrusion and SOC monitoring gaps.
  • Cyber Security Blog
  • General CTI

Cl0p’s South Staffs Water Case Shows SOC Coverage Must Be Proven

acint 2 days ago
  • Chinese Cyber Threat Intelligence

Google Disrupts Chinese APT UNC2814’s GRIDTIDE Backdoor Campaign Targeting 42 Countries

acint 3 months ago
  • Russian Cyber Threat Intelligence

New AcidPour Wiper Targeting Linux Devices Spotted in Ukraine

bulwarkblack 2 years ago2 years ago
  • Malware
  • Russian Cyber Threat Intelligence

Russian Threat Actor Deploys CANFAIL Malware Against Ukrainian Organizations

acint 3 months ago
  • North Korean Cyber Threat Intelligence

North Korean Hackers Deploy AI-Generated Deepfakes and Seven Malware Families in Targeted Cryptocurrency Attacks

acint 4 months ago4 months ago
  • Russian Cyber Threat Intelligence

NoName on Rampage! Claims DDoS Attacks on Ukrainian Government Sites

bulwarkblack 2 years ago2 years ago
  • Business

Google Disrupts World’s Largest Residential Proxy Botnet

acint 4 months ago4 months ago
2026 Powered By BlazeThemes.