Skip to content
Friday, June 26, 2026
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
  • MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • CL-STA-1062 Shows Critical Infrastructure Intrusions Still Start With Web Shells
  • Turla’s STOCKSTAY Backdoor Shows Why Espionage Defense Needs Egress Visibility
  • StrikeShark Shows Loader Malware Is an Edge-Exposure Problem
  • MuddyWater’s Chaos Masquerade Shows Ransomware Response Needs Attribution Discipline
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Home
  • Privacy & Security
  • Page 6

Privacy & Security

Editorial cybersecurity illustration showing fraudulent code signing and malware disguised as trusted software.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Fox Tempest Shows Code Signing Trust Can Be Weaponized

acint1 month ago03 mins

Microsoft disrupted Fox Tempest, a malware-signing-as-a-service operation that helped ransomware crews make malicious binaries look trusted. Here is what SMBs and government contractors should review now.

Read More
Cybersecurity illustration of exposed government cloud credentials in a public code repository
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

CISA GovCloud Leak Shows Secret Scanning Cannot Be Optional

acint1 month ago03 mins

A reported CISA contractor GitHub leak shows why secret scanning, token rotation, and CI/CD hardening need to be enforced controls, not optional developer hygiene.

Read More
Editorial cybersecurity illustration of a compromised cloud identity expanding across Microsoft 365 and Azure services.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Storm-2949 Shows Cloud Breaches Start With Identity, Not Malware

acint1 month ago04 mins

Microsoft’s Storm-2949 case study is a clean warning for SMBs and government contractors: once cloud identity and control-plane access are compromised, attackers can steal data without deploying traditional malware.

Read More
Cybersecurity illustration of AI agent governance with scoped permissions, approval gates, and audit evidence.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

AI Agent Governance Is Becoming a Security Control, Not a Nice-to-Have

acint1 month ago04 mins

AI agents now operate with real credentials inside business systems. Here is how SMBs and government contractors should govern identity, authority, action, and evidence before agentic workflows become unmanaged risk.

Read More
Editorial cybersecurity illustration of a GitHub token breach leading to codebase theft and extortion risk.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Grafana GitHub Token Breach Shows Why Source Code Access Needs Guardrails

acint1 month ago03 mins

Grafana disclosed unauthorized GitHub access tied to a leaked token and codebase download. Here is what SMBs and government contractors should tighten around source-code access, CI/CD tokens, and extortion readiness.

Read More
Editorial cybersecurity illustration of Microsoft Exchange OWA zero-day exploitation and defensive mitigation.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Exchange OWA Zero-Day Shows Why Email Servers Need Emergency Mitigation

acint1 month ago04 mins

CISA added Microsoft Exchange Server CVE-2026-42897 to KEV after evidence of active exploitation. For SMBs and government contractors, the lesson is simple: internet-facing email infrastructure needs emergency mitigation playbooks before the patch lands.

Read More
Editorial cybersecurity illustration of device code phishing and OAuth token theft.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Device Code Phishing Turns Legitimate Login Flows Into Token Theft

acint1 month ago03 mins

Device code phishing is scaling because it abuses legitimate OAuth flows instead of simply stealing passwords. Here is what SMBs and government contractors should review now.

Read More
Abstract CTI illustration of vishing, cloud identity compromise, and SaaS data exfiltration for BlackFile extortion analysis
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

BlackFile Vishing Campaign Shows Why MFA Alone Is Not Enough

acint1 month ago04 mins

GTIG reports UNC6671 / BlackFile is using vishing, AiTM phishing, and SaaS data theft to extort organizations. Here is what SMBs and government contractors should harden now.

Read More
  • 1
  • …
  • 4
  • 5
  • 6

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

e6ea770770

2026 Powered By BlazeThemes.