Skip to content
Saturday, June 27, 2026
  • Splunk Enterprise RCE Shows SIEM Servers Are Tier-Zero Infrastructure
  • NAIC Breach Shows Why PeopleSoft Internet Exposure Needs Immediate Review
  • Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Splunk Enterprise RCE Shows SIEM Servers Are Tier-Zero Infrastructure
  • NAIC Breach Shows Why PeopleSoft Internet Exposure Needs Immediate Review
  • Hospitality Photo-ZIP Campaign Shows Front Desk Workflows Are Initial Access Paths
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Home
  • General CTI
  • Page 2

General CTI

Editorial cybersecurity illustration of stealth Linux malware hidden in telecom infrastructure
  • Chinese Cyber Threat Intelligence
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Showboat Malware Shows Telecom Linux Servers Need Rootkit-Level Monitoring

acint1 week ago03 mins

Showboat is a China-linked Linux post-exploitation framework aimed at telecom providers. The lesson for defenders: treat Linux server persistence, dynamic linker abuse, and low-noise C2 as first-class monitoring priorities.

Read More
Editorial cybersecurity illustration of an AI browsing agent being hijacked through localhost into remote code execution
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

AutoJack Shows AI Browsing Agents Need Localhost Boundaries

acint1 week ago04 mins

Microsoft’s AutoJack research shows how a malicious webpage can abuse an AI browsing agent’s access to localhost services. The defensive lesson: treat agent control planes, MCP servers, and local tool runners like privileged admin surfaces.

Read More
Editorial cybersecurity illustration of an API gateway identity bypass risk for Apache APISIX authentication plugins.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review

acint1 week ago04 mins

Apache disclosed a cluster of APISIX authentication and identity plugin CVEs. The defensive priority is patching, plugin inventory, and validating what backend services trust from the gateway.

Read More
Editorial cybersecurity illustration of compromised firewall perimeter devices leaking credential streams into command infrastructure.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

FortiBleed Shows Firewall Patching Is Not Compromise Recovery

acint1 week ago04 mins

FortiBleed is a reminder that edge firewall patching is necessary, but it does not prove a previously exposed appliance is clean. Defenders need compromise review, credential rotation, and rebuild plans for perimeter devices.

Read More
Professional cybersecurity illustration of Secure Boot, UEFI firmware, and DBX revocation defense.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Vendor-Signed UEFI Apps Show Secure Boot Still Depends on Revocation Hygiene

acint1 week ago03 mins

CERT/CC warns that multiple vendor-signed UEFI applications can be abused to bypass Secure Boot before the operating system and EDR controls ever load. For SMBs and government contractors, the fix is not just firmware patching; it is verifying DBX revocation coverage across managed endpoints.

Read More
Editorial cybersecurity illustration of a compromised e-commerce review widget supply-chain attack
  • Cyber Security Blog
  • General CTI
  • Malware
  • Social Engineering

SmartApeSG Okendo Compromise Shows Third-Party Widgets Are Supply-Chain Risk

acint1 week ago03 mins

Zscaler ThreatLabz reported that SmartApeSG injected malicious JavaScript into the Okendo Reviews widget, creating downstream exposure across e-commerce sites. Here is what SMBs and government contractors should do about third-party browser code risk.

Read More
Editorial cybersecurity illustration of a Tor-based crypto clipper spreading through USB shortcuts and stealing clipboard wallet data.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Tor-Based Crypto Clipper Shows Clipboard Theft Is Now Backdoor Activity

acint1 week ago05 mins

Microsoft research on a Tor-routed crypto clipper shows why defenders should connect USB shortcut execution, script interpreters, localhost proxy activity, and clipboard theft into one investigation path.

Read More
Abstract CTI illustration of defenders dismantling AI-powered phishing infrastructure and malicious URL networks.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Outsider Enterprise Shows AI-Powered Phishing Is Now Industrial Infrastructure

acint2 weeks ago03 mins

The Outsider Enterprise takedown shows AI-powered phishing is now industrial infrastructure. SMBs and government contractors should prioritize phishing-resistant MFA, identity recovery controls, and rapid session revocation.

Read More
Abstract cybersecurity illustration of protected water utility IT and OT network segmentation.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Operational Technology (OT)
  • Privacy & Security

Handala’s Cal Water Claim Shows OT Defense Starts With Segmentation

acint2 weeks ago03 mins

Handala’s California Water Service claim is a reminder that critical-infrastructure defense starts with proving separation between billing systems, telemetry platforms, and operational technology.

Read More
Editorial cybersecurity illustration of FortiPortal API access-control risk exposing network configuration data.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

FortiPortal CVE-2026-49938 Shows Network Configuration Data Is a High-Value Target

acint2 weeks ago04 mins

Fortinet CVE-2026-49938 is a medium-severity FortiPortal API access-control issue, but sensitive network configuration exposure can still give attackers a valuable map of the environment.

Read More
  • 1
  • 2
  • 3
  • 4
  • …
  • 17

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

0bd2c4ab56

2026 Powered By BlazeThemes.