Skip to content
Friday, June 26, 2026
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
  • MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
  • SocGholish Takedown Shows Website Trust Is Malware Infrastructure
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
  • MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
  • SocGholish Takedown Shows Website Trust Is Malware Infrastructure
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Home
  • Malware
  • Page 3

Malware

Editorial cybersecurity illustration of poisoned search and AI recommendations leading to fake utility downloads and remote access abuse.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Poisoned Search and AI Recommendations Turn Utility Downloads Into RMM Access

acint4 weeks ago04 mins

Microsoft reported a cryptojacking campaign that uses poisoned search results, AI-surfaced software recommendations, fake utility downloads, and abused ScreenConnect access. Here is what SMBs and government contractors should defend first.

Read More
Editorial cybersecurity illustration of a GitHub Actions CI/CD supply chain attack and credential defense
  • Cyber Security Blog
  • General CTI
  • Malware

Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield

acint1 month ago04 mins

The Megalodon GitHub campaign shows why CI/CD pipelines must be treated like production infrastructure: malicious workflow commits can harvest cloud credentials, OIDC tokens, SSH keys, and package secrets at scale.

Read More
Editorial cybersecurity illustration of a PHP Composer supply-chain compromise targeting CI/CD secrets and cloud credentials.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized

acint1 month ago03 mins

A Laravel-Lang package compromise shows why trusted dependency tags, Composer autoload behavior, and runtime secrets need security monitoring—not just engineering review.

Read More
Professional cybersecurity illustration of a water utility ransomware intrusion and SOC monitoring gaps.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Operational Technology (OT)
  • Privacy & Security

Cl0p’s South Staffs Water Case Shows SOC Coverage Must Be Proven

acint1 month ago04 mins

The South Staffordshire Water breach shows why outsourced SOC coverage, legacy server risk, and vulnerability management must be proven—not assumed—for SMBs, utilities, and government contractors.

Read More
Editorial cybersecurity illustration of Void Dokkaebi InvisibleFerret developer endpoint malware risk
  • Cyber Security Blog
  • Malware
  • North Korean Cyber Threat Intelligence

Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk

acint1 month ago03 mins

Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.

Read More
Editorial cybersecurity illustration of Iranian Nimbus Manticore APT tooling, fake installers, SEO poisoning, and backdoor command-and-control.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Malware

Nimbus Manticore Shows Iranian APTs Are Moving Faster With AI-Assisted Tooling

acint1 month ago04 mins

Check Point Research reports that IRGC-affiliated Nimbus Manticore resurfaced with fake Zoom and SQL Developer lures, SEO poisoning, AppDomain hijacking, and a new MiniFast backdoor. Here is what SMBs and government contractors should tighten first.

Read More
Editorial cybersecurity illustration of an IoT DDoS botnet being contained by defenders and law enforcement signal lines.
  • Cyber Security Blog
  • General CTI
  • Malware

Kimwolf Arrest Shows DDoS Risk Starts on Forgotten IoT

acint1 month ago03 mins

The alleged Kimwolf botmaster arrest is a useful reminder for SMBs and government contractors: DDoS resilience starts with asset visibility, upstream protection, and hardening forgotten IoT and edge devices.

Read More
Editorial cybersecurity illustration of trojanized productivity apps hiding malware command-and-control infrastructure.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

TamperedChef Shows Signed Productivity Apps Cannot Be Trusted by Default

acint1 month ago04 mins

TamperedChef-style malware hides inside convincing signed productivity apps. Here is what SMBs and government contractors should do about it.

Read More
Editorial cybersecurity illustration of npm supply-chain malware targeting CI/CD secrets and cloud credentials
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Mini Shai-Hulud Shows CI/CD Secrets Are the Real npm Supply-Chain Prize

acint1 month ago04 mins

Mini Shai-Hulud’s @antv npm compromise shows why dependency malware should be treated as a CI/CD credential-theft threat, not just a package hygiene problem.

Read More
Editorial cybersecurity illustration of P2Pinfect botnet activity across Kubernetes and Redis cloud workloads
  • Cyber Security Blog
  • General CTI
  • Malware

P2Pinfect Shows Exposed Redis in Kubernetes Can Become Dormant Botnet Infrastructure

acint1 month ago04 mins

Fortinet observed P2Pinfect infections inside GKE clusters where exposed Redis instances became long-lived botnet footholds. For SMBs and government contractors, the lesson is clear: cloud misconfiguration, runtime visibility, and egress monitoring matter as much as patching.

Read More
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 10

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

e6ea770770

2026 Powered By BlazeThemes.