Skip to content
Wednesday, June 3, 2026
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
  • FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
  • FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.

    TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

    1 hour ago
  • Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.

    Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

    6 hours ago
  • Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.

    AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

    20 hours ago
  • Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.

    FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

    1 day ago
  • Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain

    Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

    1 day ago
  • Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.

    FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

    2 days ago
  • Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA

    Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

    2 days ago
  • Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.

    SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

    2 days ago
  • Editorial cybersecurity illustration of telecom network intrusion using Linux and Windows backdoors with defender tracing covert proxy tunnels.

    Showboat and JFMBackdoor Show Telecom Intrusions Are Built for Pivoting

    3 days ago
  • Illustration of a WordPress plugin vulnerability being exploited to create rogue administrator accounts while defenders patch and investigate.

    WP Maps Pro Exploitation Shows Why Plugin Support Features Need Security Review

    3 days ago
Abstract cybersecurity illustration of spear phishing delivering XenoRAT malware against government finance networks.
  • Cyber Security Blog
  • General CTI
  • Malware

SideCopy’s XenoRAT Campaign Shows Why Localized Lures Beat Generic Phishing Defenses

acint3 days ago04 mins

SideCopy/APT36 targeted Afghanistan finance officials with Pashto-language lures and XenoRAT. Here is what SMBs and government contractors should take from the campaign.

Read More
Editorial cybersecurity illustration of npm dependency confusion targeting developer and CI/CD environments.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Dependency Confusion Campaign Shows Reconnaissance Is the First Supply-Chain Payload

acint4 days ago03 mins

Microsoft found 33 malicious npm packages abusing dependency confusion to profile developer and build environments. The defender lesson: treat package installation as code execution and lock down internal namespace hygiene before attackers do reconnaissance at scale.

Read More
Professional cybersecurity illustration of malicious media files entering a protected parser sandbox.
  • Cyber Security Blog
  • General CTI

MediaInfoLib Parser Bugs Show File Metadata Is an Execution Boundary

acint1 week ago03 mins

Cisco Talos disclosed four patched MediaInfoLib heap-based buffer overflow vulnerabilities. The bigger lesson: automated media metadata parsing belongs inside a sandboxed, monitored execution boundary.

Read More
Editorial cybersecurity illustration of poisoned search and AI recommendations leading to fake utility downloads and remote access abuse.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Poisoned Search and AI Recommendations Turn Utility Downloads Into RMM Access

acint1 week ago04 mins

Microsoft reported a cryptojacking campaign that uses poisoned search results, AI-surfaced software recommendations, fake utility downloads, and abused ScreenConnect access. Here is what SMBs and government contractors should defend first.

Read More
Editorial cybersecurity illustration of LiteSpeed cPanel privilege escalation risk in shared hosting infrastructure.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

LiteSpeed cPanel KEV Shows Shared Hosting Is Privilege Escalation Terrain

acint1 week ago04 mins

CISA added CVE-2026-48172 to KEV after active exploitation of a LiteSpeed cPanel user-end plugin flaw that can let compromised hosting accounts execute scripts as root.

Read More
Editorial cybersecurity illustration of a GitHub Actions CI/CD supply chain attack and credential defense
  • Cyber Security Blog
  • General CTI
  • Malware

Megalodon GitHub Actions Backdoor Shows CI/CD Is Now a Credential Battlefield

acint1 week ago04 mins

The Megalodon GitHub campaign shows why CI/CD pipelines must be treated like production infrastructure: malicious workflow commits can harvest cloud credentials, OIDC tokens, SSH keys, and package secrets at scale.

Read More
Cybersecurity illustration of real-time phishing-as-a-service intercepting OTP codes and digital wallet tokens.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security
  • Social Engineering

Chinese-Language PhaaS Shows MFA Bypass Is Becoming Real-Time Fraud

acint1 week ago04 mins

Google’s reporting on Chinese-language phishing-as-a-service shows why MFA bypass, real-time OTP interception, and digital wallet fraud require phishing-resistant authentication and session monitoring.

Read More
Cybersecurity illustration of ASP.NET ViewState deserialization and shared machine key risk in a web application environment.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

KnowledgeDeliver RCE Shows Shared Machine Keys Are Shared Blast Radius

acint1 week ago04 mins

Mandiant’s KnowledgeDeliver CVE-2026-5426 report shows how shared ASP.NET machine keys can turn ViewState into unauthenticated RCE and user-facing malware delivery.

Read More
Editorial cybersecurity illustration of a PHP Composer supply-chain compromise targeting CI/CD secrets and cloud credentials.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Laravel-Lang Compromise Shows Dependency Tags Can Be Weaponized

acint1 week ago03 mins

A Laravel-Lang package compromise shows why trusted dependency tags, Composer autoload behavior, and runtime secrets need security monitoring—not just engineering review.

Read More
Professional cybersecurity illustration of a water utility ransomware intrusion and SOC monitoring gaps.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Operational Technology (OT)
  • Privacy & Security

Cl0p’s South Staffs Water Case Shows SOC Coverage Must Be Proven

acint1 week ago04 mins

The South Staffordshire Water breach shows why outsourced SOC coverage, legacy server risk, and vulnerability management must be proven—not assumed—for SMBs, utilities, and government contractors.

Read More
  • 1
  • 2
  • 3
  • 4
  • …
  • 33

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

9c7306c2b7

2026 Powered By BlazeThemes.