Skip to content
Saturday, June 13, 2026
  • Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries
  • Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls
  • Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults
  • MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries
  • Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls
  • Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults
  • MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Home
  • Privacy & Security

Privacy & Security

Editorial cybersecurity illustration showing poisoned package artifacts moving through a CI/CD pipeline while defenders isolate untrusted code from AI scanners.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Shai-Hulud Shows AI Package Scanners Need Prompt-Injection Boundaries

acint3 hours ago04 mins

Zscaler ThreatLabz says the Shai-Hulud campaign has expanded across package ecosystems and introduced prompt-injection tactics aimed at automated AI security triage. The defense lesson is simple: treat package content as hostile input, even when an LLM is doing the review.

Read More
Editorial cybersecurity illustration of a government breach notification portal being checked for fake disclosure submissions.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security
  • Social Engineering

Maine Breach Portal Hoax Shows Disclosure Systems Need Verification Controls

acint8 hours ago03 mins

Maine took its public breach notification database offline after fake disclosures were published. The lesson for SMBs and government contractors: public trust workflows need verification, moderation, and correction controls.

Read More
Editorial cybersecurity illustration showing Portainer container management risk and host takeover controls.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Portainer CVE-2026-33590 Shows Container Admin Tools Need Least Privilege Defaults

acint13 hours ago03 mins

intWave disclosed CVE-2026-33590 in Portainer, where insecure default Docker security settings could let regular users escalate toward host takeover. Here is what SMBs and government contractors should lock down.

Read More
Editorial cybersecurity illustration showing an AI browser extension side panel exposing authenticated web sessions.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

MaXSS and Spyder Show AI Browser Extensions Are an Endpoint Risk

acint1 day ago05 mins

Rebora disclosed MaXSS and Spyder, two critical flaws in AI browser-extension side panels. The lesson for SMBs and government contractors: browser extensions are endpoint software with identity-session reach and need governance.

Read More
Abstract cybersecurity illustration of AI agent memory, database checkpoints, and remote code execution risk.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

LangGraph Checkpointer Bugs Show AI Agent Memory Is Backend Attack Surface

acint2 days ago04 mins

Check Point Research disclosed LangGraph checkpointer flaws that could turn user-controlled state-history filters into SQL injection, unsafe deserialization, and remote code execution. The lesson for SMBs and government contractors: AI agent memory is application infrastructure, not magic middleware.

Read More
Editorial cybersecurity illustration of a legacy financial server breach and ransomware data theft risk.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

IMA Diligence Breach Shows Legacy Servers Are Still Third-Party Risk

acint2 days ago03 mins

A reported IMA Diligence breach affecting more than 525,000 people shows why legacy third-party servers need ownership, monitoring, decommissioning, and data-risk review.

Read More
Editorial cybersecurity illustration of a monitored file transfer server under malicious traffic pressure.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

SolarWinds Serv-U Exploitation Shows File Transfer Availability Is Security

acint6 days ago03 mins

CISA added actively exploited SolarWinds Serv-U CVE-2026-28318 to KEV. Here is what SMBs and government contractors should do about file-transfer availability risk.

Read More
Editorial cybersecurity illustration of Pink CL-CRI-1147 Microsoft 365 vishing extortion and cloud data defense.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security
  • Social Engineering

Pink Extortion Shows Microsoft 365 Defense Starts With Vishing Controls

acint6 days ago04 mins

Unit 42 is tracking Pink / CL-CRI-1147, a Com-affiliated extortion brand using vishing, credential theft, and Microsoft 365 data exfiltration. Here is what SMBs and government contractors should lock down now.

Read More
Professional cybersecurity illustration of an AI chat system protected by locked-down network egress controls.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

ChatGPT Lockdown Mode Shows Prompt Injection Defense Is About Egress Control

acint7 days ago03 mins

OpenAI’s ChatGPT Lockdown Mode is a useful reminder that prompt-injection defense is not just about model behavior. It is about limiting outbound paths, connector permissions, and tool access around sensitive work.

Read More
Editorial cybersecurity illustration of defenders reviewing GlobalProtect VPN logs after PAN-OS CVE-2026-0257 exploitation attempts.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

PAN-OS GlobalProtect Exploitation Shows VPN Access Needs Log Review, Not Just Patching

acint1 week ago03 mins

Unit 42 reports active exploitation attempts against PAN-OS GlobalProtect CVE-2026-0257. Defenders should patch, but also review VPN sessions, authentication override cookie behavior, and edge-device telemetry for signs of unauthorized access.

Read More
  • 1
  • 2
  • 3
  • …
  • 5

File Search

2
📁 Home → 📁 IOCs_YARA_TTPs_Posted_Articles ↓
ThumbNameSizeDate
Thumb AsyncRAT-loader-URL-Check.txt AsyncRAT loader URL Check.txt

text/plainAsyncRAT loader URL Check.txt

Open Download Copy Link 2.46 KB 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
2.46 KBJanuary 7, 2024
Thumb AsyncRAT-loader-hashes.txt AsyncRAT loader hashes.txt

text/plainAsyncRAT loader hashes.txt

Open Download Copy Link 662 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
662 BJanuary 7, 2024
Thumb Hackers-Modifying-Registry-Keys-to-Establish-Persistence-via-Scheduled-Tasks.txt Hackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks.txt

text/plainHackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks.txt

Open Download Copy Link 945 B 2024-01-12 January 12, 2024 2024-01-06 January 6, 2024
945 BJanuary 6, 2024
Thumb Hackers-target-Apache-RocketMQ-servers-vulnerable-to-RCE-attack.txt Hackers target Apache RocketMQ servers vulnerable to RCE attack.txt

text/plainHackers target Apache RocketMQ servers vulnerable to RCE attack.txt

Open Download Copy Link 77 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
77 BJanuary 5, 2024
Thumb IOC-and-TTPs-Backdoor_Win32-Carbanak-Anunak-Named-Pipe-Null-DACL.txt IOC and TTPs Backdoor.Win32 Carbanak (Anunak) - Named Pipe Null DACL.txt

text/plainIOC and TTPs Backdoor.Win32 Carbanak (Anunak) - Named Pipe Null DACL.txt

Open Download Copy Link 5.02 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
5.02 KBJanuary 11, 2024
Thumb IOCs-Chapter-84-In-depth-analysis-and-technical-analysis-of-LockBit-the-top-encryption-ransomware-organization-Part-1.txt IOCs Chapter 84 In-depth analysis and technical analysis of LockBit the top encryption ransomware organization Part 1.txt

text/plainIOCs Chapter 84 In-depth analysis and technical analysis of LockBit the top encryption ransomware organization Part 1.txt

Open Download Copy Link 236 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
236 BJanuary 7, 2024
Thumb IOCs-and-TTPs-Financially-motivated-threat-actors-misusing-App-Installer.txt IOCs and TTPs Financially motivated threat actors misusing App Installer.txt

text/plainIOCs and TTPs Financially motivated threat actors misusing App Installer.txt

Open Download Copy Link 7.26 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
7.26 KBJanuary 9, 2024
Thumb IOCs-and-TTPs_-Analysis-of-OT-cyberattacks-and-malwares.txt IOCs and TTPs_ Analysis of OT cyberattacks and malwares.txt

text/plainIOCs and TTPs_ Analysis of OT cyberattacks and malwares.txt

Open Download Copy Link 8.82 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
8.82 KBJanuary 9, 2024
Thumb IOCs-and-Yara-Hundreds-of-Thousands-of-Dollars-Worth-of-Solana-Cryptocurrency-Assets-Stolen-in-Recent-CLINKSINK-Drainer-Campaigns.txt IOCs and Yara Hundreds of Thousands of Dollars Worth of Solana Cryptocurrency Assets Stolen in Recent CLINKSINK Drainer Campaigns.txt

text/plainIOCs and Yara Hundreds of Thousands of Dollars Worth of Solana Cryptocurrency Assets Stolen in Recent CLINKSINK Drainer Campaigns.txt

Open Download Copy Link 1.38 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
1.38 KBJanuary 11, 2024
Thumb IOCs-and-other-AsyncRat.txt IOCs and other AsyncRat.txt

text/plainIOCs and other AsyncRat.txt

Open Download Copy Link 1.04 KB 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
1.04 KBJanuary 7, 2024
Thumb IOCs-Deceptive-Cracked-Software-Spreads-Lumma-Variant-on-YouTube.txt IOCs Deceptive Cracked Software Spreads Lumma Variant on YouTube.txt

text/plainIOCs Deceptive Cracked Software Spreads Lumma Variant on YouTube.txt

Open Download Copy Link 1.16 KB 2024-01-12 January 12, 2024 2024-01-08 January 8, 2024
1.16 KBJanuary 8, 2024
Thumb IOCs-DreamBus-Unleashes-Metabase-Mayhem-With-New-Exploit-Module.txt IOCs DreamBus Unleashes Metabase Mayhem With New Exploit Module.txt

text/plainIOCs DreamBus Unleashes Metabase Mayhem With New Exploit Module.txt

Open Download Copy Link 1.65 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
1.65 KBJanuary 11, 2024
Thumb IOCs-Hide-and-Seek-in-Windows-Closet-Unmasking-the-WinSxS-Hijacking-Hideout.txt IOCs Hide and Seek in Windows' Closet Unmasking the WinSxS Hijacking Hideout.txt

text/plainIOCs Hide and Seek in Windows' Closet Unmasking the WinSxS Hijacking Hideout.txt

Open Download Copy Link 415 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
415 BJanuary 5, 2024
Thumb IOCs-TTPs-and-yara-Opening-a-Can-of-Whoop-Ads-Detecting-and-Disrupting-a-Malvertising-Campaign-Distributing-Backdoors.txt IOCs TTPs and yara Opening a Can of Whoop Ads Detecting and Disrupting a Malvertising Campaign Distributing Backdoors.txt

text/plainIOCs TTPs and yara Opening a Can of Whoop Ads Detecting and Disrupting a Malvertising Campaign Distributing Backdoors.txt

Open Download Copy Link 15.56 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
15.56 KBJanuary 9, 2024
Thumb IOCs-Tackling-Anti-Analysis-Techniques-of-GuLoader-and-RedLine-Stealer.txt IOCs Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer.txt

text/plainIOCs Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer.txt

Open Download Copy Link 143 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
143 BJanuary 5, 2024
Thumb Prior-to-Cyber-Attack-Russian-Attackers-Spent-Months-Inside-the-Ukraine-Telecoms-Giant.txt Prior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant.txt

text/plainPrior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant.txt

Open Download Copy Link 168 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
168 BJanuary 7, 2024
Thumb yara-rules-from-100-Days-of-Yara-and-other-infor.txt yara rules from 100 Days of Yara and other infor.txt

text/plainyara rules from 100 Days of Yara and other infor.txt

Open Download Copy Link 49.69 KB 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
49.69 KBJanuary 5, 2024
Thumb Pig-butchering-is-an-evolution-of-a-social-engineering-tactic-weve-seen-for-years.txt Pig butchering is an evolution of a social engineering tactic we’ve seen for years.txt

text/plainPig butchering is an evolution of a social engineering tactic we’ve seen for years.txt

Open Download Copy Link 770 B 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
770 BMarch 22, 2024
Thumb IOCs-Curious-Serpens-FalseFont-Backdoor-Technical-Analysis-Detection-and-Prevention.txt IOCs Curious Serpens FalseFont Backdoor Technical Analysis Detection and Prevention.txt

text/plainIOCs Curious Serpens FalseFont Backdoor Technical Analysis Detection and Prevention.txt

Open Download Copy Link 501 B 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
501 BMarch 22, 2024
Thumb IOCs-The-Updated-APT-Playbook-Tales-from-the-Kimsuky-threat-actor-group.txt IOCs The Updated APT Playbook Tales from the Kimsuky threat actor group.txt

text/plainIOCs The Updated APT Playbook Tales from the Kimsuky threat actor group.txt

Open Download Copy Link 1.44 KB 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
1.44 KBMarch 22, 2024
https://bulwarkblack.com/category/privacy-security?eeFolder=IOCs_YARA_TTPs_Posted_Articles&ee=1&eeListID=2 0 1

1 - 20 21 - 21

Page: 1 of 2

20

68fbf9d2fe

2026 Powered By BlazeThemes.