Skip to content
Friday, June 26, 2026
  • Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Home
  • AI (General)

AI (General)

Abstract cybersecurity illustration of an AI software supply-chain compromise affecting package dependencies and developer pipelines.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • North Korean Cyber Threat Intelligence
  • Privacy & Security

Mastra npm Compromise Shows AI Frameworks Are Supply-Chain Targets

acint6 days ago04 mins

Microsoft linked the Mastra AI npm package compromise to North Korean actor Sapphire Sleet. Here is what SMBs and government contractors should do about AI framework supply-chain risk.

Read More
Editorial cybersecurity illustration of an AI browsing agent being hijacked through localhost into remote code execution
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

AutoJack Shows AI Browsing Agents Need Localhost Boundaries

acint7 days ago04 mins

Microsoft’s AutoJack research shows how a malicious webpage can abuse an AI browsing agent’s access to localhost services. The defensive lesson: treat agent control planes, MCP servers, and local tool runners like privileged admin surfaces.

Read More
Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

acint2 weeks ago03 mins

The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

Read More
Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

acint2 weeks ago04 mins

Zscaler ThreatLabz says the Shai-Hulud campaign has expanded across package ecosystems and introduced prompt-injection tactics aimed at automated AI security triage. The defense lesson is simple: treat package content as hostile input, even when an LLM is doing the review.

Read More
Editorial cybersecurity illustration showing an AI browser extension side panel exposing authenticated web sessions.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk

acint2 weeks ago05 mins

Rebora disclosed MaXSS and Spyder, two critical flaws in AI browser-extension side panels. The lesson for SMBs and government contractors: browser extensions are endpoint software with identity-session reach and need governance.

Read More
Abstract cybersecurity illustration of AI agent memory, database checkpoints, and remote code execution risk.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

LangGraph Checkpointer Bugs Show AI Agent Memory Is Backend Attack Surface

acint2 weeks ago04 mins

Check Point Research disclosed LangGraph checkpointer flaws that could turn user-controlled state-history filters into SQL injection, unsafe deserialization, and remote code execution. The lesson for SMBs and government contractors: AI agent memory is application infrastructure, not magic middleware.

Read More
Professional cybersecurity illustration of an AI chat system protected by locked-down network egress controls.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

ChatGPT Lockdown Mode Shows Prompt Injection Defense Is About Egress Control

acint3 weeks ago03 mins

OpenAI’s ChatGPT Lockdown Mode is a useful reminder that prompt-injection defense is not just about model behavior. It is about limiting outbound paths, connector permissions, and tool access around sensitive work.

Read More
Editorial cybersecurity illustration of defenders hardening agentic AI systems against prompt injection, plugin abuse, and context contamination.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Agentic AI Failure Modes Show Why AI Tools Need Supply-Chain Controls

acint3 weeks ago03 mins

Microsoft’s updated agentic AI failure-mode taxonomy turns AI agents into a practical security architecture problem: plugins, prompts, memory, browser use, and human approvals all need controls.

Read More
Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

acint3 weeks ago04 mins

Sophos observed ransomware-linked operators using AI-assisted development workflows to accelerate EDR evasion testing and Active Directory discovery. The defensive lesson: validate controls, harden identity, and monitor behavior before attackers iterate around your tooling.

Read More
Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

acint4 weeks ago04 mins

Attackers reportedly abused Meta’s AI support assistant during Instagram account recovery. The lesson for SMBs and contractors: recovery workflows are identity infrastructure and need MFA, monitoring, and guardrails.

Read More
  • 1
  • 2
  • 3

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

00ea754c66

2026 Powered By BlazeThemes.