Skip to content
Thursday, June 4, 2026
  • Fuel Tank Gauge Attacks Show Why Small OT Still Needs Internet Exposure Control
  • Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Fuel Tank Gauge Attacks Show Why Small OT Still Needs Internet Exposure Control
  • Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Industrial fuel storage tanks and monitoring screens representing cyber risk to automatic tank gauge systems.

    Fuel Tank Gauge Attacks Show Why Small OT Still Needs Internet Exposure Control

    6 minutes ago
  • Editorial cybersecurity illustration of executive mailbox espionage and cloud data exfiltration around a stock exchange.

    Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure

    14 hours ago
  • Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.

    TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

    19 hours ago
  • Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.

    Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

    1 day ago
  • Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.

    AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

    2 days ago
  • Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.

    FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

    2 days ago
  • Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain

    Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

    2 days ago
  • Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.

    FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

    3 days ago
  • Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA

    Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

    3 days ago
  • Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.

    SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

    3 days ago
Industrial fuel storage tanks and monitoring screens representing cyber risk to automatic tank gauge systems.
  • Cyber Security Blog
  • General CTI
6 minutes ago

Fuel Tank Gauge Attacks Show Why Small OT Still Needs Internet Exposure Control

Federal agencies warn that attackers are compromising internet-exposed automatic tank gauge systems. The lesson for SMBs, fuel operators, farms, logistics firms, and gov contractors is simple: small OT is still operational infrastructure.

Editorial cybersecurity illustration of executive mailbox espionage and cloud data exfiltration around a stock exchange.
  • Cyber Security Blog
  • General CTI
14 hours ago

Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure

A five-month espionage campaign against a stock exchange executive mailbox shows why senior email accounts need privileged-asset controls, cloud exfiltration monitoring, and scheduled-task hunting.

Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
19 hours ago

TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

Proofpoint’s TA4922 reporting shows how localized HR, payroll, tax, and invoice lures can become full initial-access infrastructure through DLL sideloading, loaders, RATs, RMM tools, and browser credential theft.

Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.
  • Cyber Security Blog
  • General CTI
1 day ago

Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

A Red Hat Cloud Services npm compromise shows why signed releases and trusted publishing must be paired with install-time controls, CI/CD isolation, and fast credential rotation.

Rapid7 2026 Global Threat Landscape Report: Exploited Vulnerabilities Surge 105% as Attack Timelines Collapse
  • General CTI

Rapid7 2026 Global Threat Landscape Report: Exploited Vulnerabilities Surge 105% as Attack Timelines Collapse

AI-Fueled Supply Chain Attacks Surge in Asia-Pacific: Group-IB Report Exposes Self-Reinforcing Cybercrime Ecosystem
  • General CTI

AI-Fueled Supply Chain Attacks Surge in Asia-Pacific: Group-IB Report Exposes Self-Reinforcing Cybercrime Ecosystem

Patriot Bait Shows AI-Enabled Fraud Can Turn Trust Into Attack Surface
  • AI (General)
  • Cyber Security Blog

Patriot Bait Shows AI-Enabled Fraud Can Turn Trust Into Attack Surface

ClawHavoc Supply Chain Attack Poisons OpenClaw ClawHub With 1,184 Malicious AI Agent Skills
  • Malware

ClawHavoc Supply Chain Attack Poisons OpenClaw ClawHub With 1,184 Malicious AI Agent Skills

Industrial fuel storage tanks and monitoring screens representing cyber risk to automatic tank gauge systems.
  • Cyber Security Blog
  • General CTI
  • Operational Technology (OT)

Fuel Tank Gauge Attacks Show Why Small OT Still Needs Internet Exposure Control

acint6 minutes ago03 mins

Federal agencies warn that attackers are compromising internet-exposed automatic tank gauge systems. The lesson for SMBs, fuel operators, farms, logistics firms, and gov contractors is simple: small OT is still operational infrastructure.

Read More
Editorial cybersecurity illustration of executive mailbox espionage and cloud data exfiltration around a stock exchange.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Stock Exchange Mailbox Espionage Shows Executive Email Is Strategic Infrastructure

acint14 hours ago04 mins

A five-month espionage campaign against a stock exchange executive mailbox shows why senior email accounts need privileged-asset controls, cloud exfiltration monitoring, and scheduled-task hunting.

Read More
Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

acint19 hours ago04 mins

Proofpoint’s TA4922 reporting shows how localized HR, payroll, tax, and invoice lures can become full initial-access infrastructure through DLL sideloading, loaders, RATs, RMM tools, and browser credential theft.

Read More
Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

acint1 day ago05 mins

A Red Hat Cloud Services npm compromise shows why signed releases and trusted publishing must be paired with install-time controls, CI/CD isolation, and fast credential rotation.

Read More
Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

acint2 days ago04 mins

Sophos observed ransomware-linked operators using AI-assisted development workflows to accelerate EDR evasion testing and Active Directory discovery. The defensive lesson: validate controls, harden identity, and monitor behavior before attackers iterate around your tooling.

Read More
Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.
  • Cyber Security Blog
  • General CTI
  • Malware

FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

acint2 days ago04 mins

Unit 42’s FlutterBridge research shows macOS malvertising evolving from adware into FlutterShell backdoor delivery. Here is what SMBs and government contractors should tighten first.

Read More
Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Malware

Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

acint2 days ago04 mins

Mustang Panda’s fake browser updater chain shows why defenders still need to hunt LNK-to-PowerShell execution, DLL sideloading, user-context persistence, and suspicious HTTPS beaconing.

Read More
Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.
  • Cyber Security Blog
  • General CTI
  • Malware

FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

acint3 days ago03 mins

Attackers are abusing CVE-2026-35616 in FortiClient EMS to push a credential stealer through trusted endpoint management workflows. Here is what defenders should check first.

Read More
Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

acint3 days ago04 mins

Attackers reportedly abused Meta’s AI support assistant during Instagram account recovery. The lesson for SMBs and contractors: recovery workflows are identity infrastructure and need MFA, monitoring, and guardrails.

Read More
Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.
  • Cyber Security Blog
  • General CTI
  • Malware

SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

acint3 days ago04 mins

SolyxImmortal combines persistence, browser credential theft, document collection, screenshots, keylogging, and webhook exfiltration. Here is what SMB and government-contractor defenders should do about it.

Read More
  • 1
  • 2
  • 3
  • …
  • 34

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

6ca66b5a6d

You May Have Missed

  • Digital Assets

How to Avoid the Coming Trap: Digital IDs, Social Credit Scores, and Government-Controlled Crypto

bulwarkblack 1 year ago1 year ago
  • Chinese Cyber Threat Intelligence

Chinese APT Groups Leverage PeckBirdy JavaScript C2 Framework Since 2023

acint 4 months ago
  • General CTI

Hackers Weaponize Claude Code AI to Steal 150GB from Mexican Government in Month-Long Campaign

acint 3 months ago3 months ago
  • North Korean Cyber Threat Intelligence

Infostealer Infection Unmasks DPRK Operative Behind Polyfill.io Supply Chain Attack and US Crypto Exchange Infiltration

acint 3 months ago
  • Iranian Cyber Threat Intelligence

FBI Confirms Handala Hackers Breached Director Patel’s Personal Email Account

acint 2 months ago
  • Bug Bounty
  • Offensive Devices / Tactics

Detecting API endpoints and source code with JS Miner

bulwarkblack 2 years ago2 years ago
  • Malware

Phorpiex Botnet Resurfaces: Phishing Campaign Delivers Offline-Capable Global Group Ransomware

acint 4 months ago
  • Operational Technology (OT)
  • Russian Cyber Threat Intelligence

Russian Cyberattacks Shift to Intelligence Gathering for Missile Strike Guidance on Ukraine Power Grid

acint 3 months ago3 months ago
2026 Powered By BlazeThemes.