Skip to content
Wednesday, June 3, 2026
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
  • FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
  • FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration showing global phishing, remote access tooling, and defensive monitoring for TA4922-style campaigns.

    TA4922’s Global Expansion Shows HR and Tax Lures Are Initial Access Infrastructure

    1 hour ago
  • Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.

    Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

    6 hours ago
  • Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.

    AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

    20 hours ago
  • Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.

    FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

    1 day ago
  • Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain

    Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

    1 day ago
  • Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.

    FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

    2 days ago
  • Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA

    Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

    2 days ago
  • Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.

    SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

    2 days ago
  • Editorial cybersecurity illustration of telecom network intrusion using Linux and Windows backdoors with defender tracing covert proxy tunnels.

    Showboat and JFMBackdoor Show Telecom Intrusions Are Built for Pivoting

    3 days ago
  • Illustration of a WordPress plugin vulnerability being exploited to create rogue administrator accounts while defenders patch and investigate.

    WP Maps Pro Exploitation Shows Why Plugin Support Features Need Security Review

    3 days ago
Abstract cybersecurity illustration of cloud identity token abuse, rogue device registration, and defender investigation workflows.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

ROADtools Abuse Shows Cloud Identity Is the New Attack Surface

acint1 week ago04 mins

Unit 42’s ROADtools research shows why Microsoft Entra ID token abuse, rogue device registration, and Graph API enumeration need to be treated as core incident-response signals for SMBs and government contractors.

Read More
Editorial cybersecurity illustration of defenders monitoring web application exploitation attempts against Drupal PostgreSQL sites.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Drupal CVE-2026-9082 Shows Web Asset Inventory Is Emergency Response

acint2 weeks ago03 mins

Drupal CVE-2026-9082 is already being scanned and exploited in the wild. The lesson for SMBs and government contractors: know where your Drupal sites are, verify PostgreSQL exposure, patch fast, and review logs before probing turns into compromise.

Read More
Editorial cybersecurity illustration of Void Dokkaebi InvisibleFerret developer endpoint malware risk
  • Cyber Security Blog
  • Malware
  • North Korean Cyber Threat Intelligence

Void Dokkaebi’s InvisibleFerret Shift Shows Developer Endpoints Are Production Risk

acint2 weeks ago03 mins

Trend Micro reports North Korea-aligned Void Dokkaebi has moved InvisibleFerret into Cython-compiled Python extension modules. For SMBs and government contractors, the real risk is developer endpoint access to CI/CD, cloud, and production secrets.

Read More
Editorial cybersecurity illustration of Iranian Nimbus Manticore APT tooling, fake installers, SEO poisoning, and backdoor command-and-control.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Malware

Nimbus Manticore Shows Iranian APTs Are Moving Faster With AI-Assisted Tooling

acint2 weeks ago04 mins

Check Point Research reports that IRGC-affiliated Nimbus Manticore resurfaced with fake Zoom and SQL Developer lures, SEO poisoning, AppDomain hijacking, and a new MiniFast backdoor. Here is what SMBs and government contractors should tighten first.

Read More
Editorial cybersecurity illustration of an edge appliance compromise pivoting into Linux, Confluence, and identity systems
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

F5-to-Confluence Intrusion Shows Edge Devices Are Identity Attack Paths

acint2 weeks ago05 mins

Microsoft analyzed an intrusion where an F5 BIG-IP edge appliance led to Linux access, Confluence compromise, credential theft, and identity relay attempts. Here is what SMBs and government contractors should tighten first.

Read More
Editorial cybersecurity illustration of Iranian APT Screening Serpens recruitment-lure espionage and RAT command-and-control.
  • Cyber Security Blog
  • General CTI
  • Iranian Cyber Threat Intelligence
  • Privacy & Security

Screening Serpens Shows Recruiting Is Now an Espionage Attack Surface

acint2 weeks ago04 mins

Iran-nexus Screening Serpens used recruitment and meeting lures, new RAT variants, and .NET AppDomainManager hijacking. Here is what SMBs and government contractors should tighten now.

Read More
Editorial cybersecurity illustration of an IoT DDoS botnet being contained by defenders and law enforcement signal lines.
  • Cyber Security Blog
  • General CTI
  • Malware

Kimwolf Arrest Shows DDoS Risk Starts on Forgotten IoT

acint2 weeks ago03 mins

The alleged Kimwolf botmaster arrest is a useful reminder for SMBs and government contractors: DDoS resilience starts with asset visibility, upstream protection, and hardening forgotten IoT and edge devices.

Read More
Editorial cybersecurity illustration of trojanized productivity apps hiding malware command-and-control infrastructure.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

TamperedChef Shows Signed Productivity Apps Cannot Be Trusted by Default

acint2 weeks ago04 mins

TamperedChef-style malware hides inside convincing signed productivity apps. Here is what SMBs and government contractors should do about it.

Read More
Editorial cybersecurity illustration of AI-assisted influence operations, credential theft, and crypto fraud infrastructure.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Patriot Bait Shows AI-Enabled Fraud Can Turn Trust Into Attack Surface

acint2 weeks ago04 mins

Trend Micro’s Patriot Bait research shows how one operator used AI assistance, social trust, WordPress credential attacks, and crypto fraud infrastructure to scale a low-cost cybercrime operation.

Read More
Editorial cybersecurity illustration of npm supply-chain malware targeting CI/CD secrets and cloud credentials
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Mini Shai-Hulud Shows CI/CD Secrets Are the Real npm Supply-Chain Prize

acint2 weeks ago04 mins

Mini Shai-Hulud’s @antv npm compromise shows why dependency malware should be treated as a CI/CD credential-theft threat, not just a package hygiene problem.

Read More
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 33

File Search

2
ThumbNameSizeDate
Thumb IOCs_YARA_TTPs_Posted_Articles/ IOCs_YARA_TTPs_Posted_Articles

IOCs_YARA_TTPs_Posted_Articles

Open 99.71 KB 2024-01-12 January 12, 2024 2024-03-22 March 22, 2024
21 Items
99.71 KB
March 22, 2024

0

9c7306c2b7

2026 Powered By BlazeThemes.