Cyber Threat Intelligence
Daily threat reporting, custom software, and remote tech help from a veteran-owned (SDVOSB) studio.
Updated most weekdays
Our Software
Explore all software →Nation-State Tracking
Intelligence by Region
Russian Threat Intelligence
View all Russian intel →CaptiveCrunch Shows Why Travel Wi-Fi Is Now an Identity Attack Surface
Microsoft says a Midnight Blizzard sub-cluster is abusing captive-portal Wi-Fi environments to deliver malware and steal credentials from travelers. Here is what SMBs and government contractors should defend first.
TA488 Turns Outlook Web Access Into a Stealthy Persistence Layer
Proofpoint reports Russia-aligned TA488 abused an Outlook Web Access XSS flaw to deploy OWAReaper, a browser-based implant that can persist beyond passwords and endpoint rebuilds.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
Chinese Threat Intelligence
View all Chinese intel →Pakistani Police Intrusions Show Why Public-Sector Data Systems Are Strategic Targets
SentinelLabs reporting on rival espionage activity against Pakistani law enforcement is a reminder that public-sector portals, case systems, and citizen-data apps are strategic intelligence targets — even when they are not classified systems.
UAT-7810 Shows Edge Devices Are Becoming China-Nexus Relay Infrastructure
Cisco Talos reports UAT-7810 is expanding ORB relay infrastructure using compromised edge and embedded devices. Here is what SMBs and government contractors should do now.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
North Korean Threat Intelligence
View all North Korean intel →DPRK npm Compromises Show Why Dependency Trust Is Now Identity Risk
Amazon linked compromises of popular npm packages to a DPRK-linked actor. The defensive lesson for SMBs and government contractors: dependency risk is no longer just code review — it is maintainer identity, build-pipeline behavior, and runtime trust.
Mastra npm Compromise Shows AI Frameworks Are Supply-Chain Targets
Microsoft linked the Mastra AI npm package compromise to North Korean actor Sapphire Sleet. Here is what SMBs and government contractors should do about AI framework supply-chain risk.
Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk
Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.
Iranian Threat Intelligence
View all Iranian intel →HOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 Battlefield
Group-IB’s HOLLOWGRAPH research shows how attackers can turn Microsoft 365 calendars, Graph API traffic, and DNS into covert command-and-control. Here is what SMBs and government contractors should hunt for now.
Water Systems Are Becoming Nation-State Pressure Points
Nation-state targeting of water systems shows why exposed OT, weak credentials, remote access, and poor IT/OT segmentation remain practical business risks—not just utility-sector problems.
MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
Iran-linked MuddyWater activity shows why ransomware response needs to examine identity compromise, remote access, and adversary objectives instead of trusting the ransom note at face value.
Browse by category
Beyond the feed
Bulwark Black also builds
All services →Websites & Web Apps
Fast, clean marketing sites and custom web apps built for your business, not a template you have to fight. Designed, built, and deployed by the person who will maintain it.
Custom iOS Apps
Native iPhone and iPad apps built for businesses and published to the App Store. From a focused single-purpose tool to a full product, designed, developed, and shipped end to end.
AI & Automation
Practical AI setup and quiet automation that saves you real hours. We pick the right tools, wire them into how you actually work, and skip the hype when it does not fit.
Small-Business IT + Cybersecurity
Right-sized IT support and security fundamentals for small teams, delivered remotely. Backups that actually restore, hardened accounts, and someone honest to call.
You may have missed
Bad Epoll Shows Linux Kernel LPEs Belong in the Patch Priority Queue
Bad Epoll CVE-2026-46242 is a Linux kernel epoll race-condition LPE. Here is why SMBs and government contractors should prioritize kernel patching, developer endpoint hardening, and post-compromise controls.
Fake Payment SDKs Show Why Dependency Risk Is Credential Risk
Socket uncovered malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs. Here is what SMBs and government contractors should do now to protect CI secrets, developer machines, and payment integrations.
Critical UniFi Flaws Put Network Control Planes Back in the Patch Queue
Ubiquiti patched critical UniFi Connect, Talk, Access, Protect, and UniFi OS flaws. Here is what SMBs and government contractors should patch, restrict, and review now.
Vidar Stealer Campaign Shows Why File Size and Fake Signatures Still Beat Weak Controls
Unit 42 reported a Vidar stealer and XMRig campaign using malvertising, fake cracked-software lures, misleading certificate metadata, oversized binaries, and commodity loader infrastructure. Here is what SMBs and government contractors should take away.
Newsletter
The House-Of-L Brief.
Two short reads a day. Mornings cover markets, cyber threats, and what changed overnight. Evenings cover how AI, energy, and geopolitics are moving the world. A "why it matters" line on every story. A roundup every Sunday.
readers get The Brief
Double opt-in. One-click unsubscribe on every issue. We never share your address.