Skip to content
Wednesday, June 3, 2026
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
  • FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware
  • Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
  • Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary
  • AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem
  • FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware
  • Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter
Register / Sign Up
RSS
Bulwark Black LLC

Bulwark Black LLC

Cyber Security | Software Development | Consulting Services

  • Cyber Threat Intelligence
    • Russian Cyber Threat Intelligence
      • Russian Actors and Alias’s 09JAN2024
    • Chinese Cyber Threat Intelligence
      • Chinese Actors and Alias’s
    • North Korean Cyber Threat Intelligence
      • North Korean Actors and Alias’s
    • Iranian Cyber Threat Intelligence
      • Iranian Actors and Alias’s
    • Malware
      • Top 200 Malware of January 2024
    • Global Cyber Threat Intelligence
      • Global Threat Actors
  • Defensive Security
    • Detection
  • Offensive Security
    • Bug Bounty
    • Offensive Devices / Tactics
    • Red Teaming
  • AI (Artificial Intelligence)
    • AI (General)
  • Privacy & Security
    • Becoming Self Sufficient
    • Digital Assets
    • Makes you Think
    • Social Engineering
  • Research Papers
  • Training / Projects
    • Projects
    • Training
  • Blog
    • Cyber Security Blog
  • Contact
  • About
  • Donations
  • Products
    • VA Disability Calc & Track App
  • Services
  • Operational Technology (OT)
Recent
  • Editorial cybersecurity illustration of an npm supply-chain compromise moving through CI/CD pipelines and cloud credentials.

    Red Hat’s Miasma npm Compromise Shows Trusted Publishing Is Not a Control Boundary

    5 hours ago
  • Editorial illustration of AI-assisted ransomware tooling testing EDR evasion and Active Directory discovery workflows.

    AI-Assisted Ransomware Tooling Shows EDR Evasion Is Now an Iteration Problem

    19 hours ago
  • Cyber threat intelligence illustration of macOS malvertising delivering a FlutterShell backdoor through fake desktop applications.

    FlutterBridge Shows Why macOS Malvertising Is Backdoor Delivery, Not Just Adware

    24 hours ago
  • Editorial cybersecurity illustration of Mustang Panda PlugX fake browser updater intrusion chain

    Mustang Panda’s Fake Browser Updater Shows Why LNK Files Still Matter

    1 day ago
  • Editorial cybersecurity illustration of FortiClient EMS exploitation delivering an infostealer through endpoint management workflows.

    FortiClient EMS Exploitation Turns Endpoint Management Into an Infostealer Delivery System

    2 days ago
  • Editorial cybersecurity illustration of AI support bot account recovery abuse defended by passkeys and MFA

    Meta AI Support Bot Abuse Shows Account Recovery Is Part of the Identity Perimeter

    2 days ago
  • Abstract cybersecurity illustration of an information stealer moving endpoint data through webhook infrastructure.

    SolyxImmortal Shows Why Python Infostealers Are a Business Risk, Not Just Malware Noise

    2 days ago
  • Editorial cybersecurity illustration of telecom network intrusion using Linux and Windows backdoors with defender tracing covert proxy tunnels.

    Showboat and JFMBackdoor Show Telecom Intrusions Are Built for Pivoting

    3 days ago
  • Illustration of a WordPress plugin vulnerability being exploited to create rogue administrator accounts while defenders patch and investigate.

    WP Maps Pro Exploitation Shows Why Plugin Support Features Need Security Review

    3 days ago
  • Abstract cybersecurity illustration of spear phishing delivering XenoRAT malware against government finance networks.

    SideCopy’s XenoRAT Campaign Shows Why Localized Lures Beat Generic Phishing Defenses

    3 days ago
Editorial cybersecurity illustration of P2Pinfect botnet activity across Kubernetes and Redis cloud workloads
  • Cyber Security Blog
  • General CTI
  • Malware

P2Pinfect Shows Exposed Redis in Kubernetes Can Become Dormant Botnet Infrastructure

acint2 weeks ago04 mins

Fortinet observed P2Pinfect infections inside GKE clusters where exposed Redis instances became long-lived botnet footholds. For SMBs and government contractors, the lesson is clear: cloud misconfiguration, runtime visibility, and egress monitoring matter as much as patching.

Read More
Cyber threat intelligence illustration showing defenders prioritizing exploited vulnerabilities across exposed systems.
  • Cyber Security Blog
  • General CTI

Verizon DBIR 2026 Shows Vulnerability Exploitation Is Now the Breach Priority

acint2 weeks ago04 mins

Verizon’s 2026 DBIR shows vulnerability exploitation overtaking credential abuse as the top breach access vector. Here is what SMBs and government contractors should fix first.

Read More
Editorial cybersecurity illustration showing fraudulent code signing and malware disguised as trusted software.
  • Cyber Security Blog
  • General CTI
  • Malware
  • Privacy & Security

Fox Tempest Shows Code Signing Trust Can Be Weaponized

acint2 weeks ago03 mins

Microsoft disrupted Fox Tempest, a malware-signing-as-a-service operation that helped ransomware crews make malicious binaries look trusted. Here is what SMBs and government contractors should review now.

Read More
Cybersecurity illustration of exposed government cloud credentials in a public code repository
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

CISA GovCloud Leak Shows Secret Scanning Cannot Be Optional

acint2 weeks ago03 mins

A reported CISA contractor GitHub leak shows why secret scanning, token rotation, and CI/CD hardening need to be enforced controls, not optional developer hygiene.

Read More
Editorial cybersecurity illustration of a compromised cloud identity expanding across Microsoft 365 and Azure services.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Storm-2949 Shows Cloud Breaches Start With Identity, Not Malware

acint2 weeks ago04 mins

Microsoft’s Storm-2949 case study is a clean warning for SMBs and government contractors: once cloud identity and control-plane access are compromised, attackers can steal data without deploying traditional malware.

Read More
Cybersecurity illustration of AI agent governance with scoped permissions, approval gates, and audit evidence.
  • AI (General)
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

AI Agent Governance Is Becoming a Security Control, Not a Nice-to-Have

acint2 weeks ago04 mins

AI agents now operate with real credentials inside business systems. Here is how SMBs and government contractors should govern identity, authority, action, and evidence before agentic workflows become unmanaged risk.

Read More
Editorial cybersecurity illustration of segmented AI inference infrastructure under remote code execution risk.
  • AI (General)
  • Cyber Security Blog
  • General CTI

SGLang RCE Flaws Show AI Inference Servers Need Real Network Isolation

acint2 weeks ago03 mins

CERT/CC disclosed three SGLang vulnerabilities affecting AI inference deployments, including remote code execution and path traversal risks. Here is what SMBs and government contractors should do now.

Read More
Editorial cybersecurity illustration of a GitHub token breach leading to codebase theft and extortion risk.
  • Cyber Security Blog
  • General CTI
  • Privacy & Security

Grafana GitHub Token Breach Shows Why Source Code Access Needs Guardrails

acint2 weeks ago03 mins

Grafana disclosed unauthorized GitHub access tied to a leaked token and codebase download. Here is what SMBs and government contractors should tighten around source-code access, CI/CD tokens, and extortion readiness.

Read More
Editorial illustration of AI literacy, database fundamentals, and rural cybersecurity support.
  • AI (General)
  • Cyber Security Blog

AI Literacy Needs Fundamentals: Teaching Technology in the Real World

acint2 weeks ago2 weeks ago07 mins

Albert LaScola reflects on teaching database systems, governance, risk management, and AI literacy through a fundamentals-first approach shaped by Navy operations, security work, Bulwark Black, and Rural Tech and Support.

Read More
Editorial cybersecurity illustration of an npm supply-chain compromise leaking CI and cloud secrets through DNS signals.
  • Cyber Security Blog
  • General CTI
  • Malware

node-ipc Backdoor Shows Why CI Secrets Need Supply Chain Controls

acint2 weeks ago03 mins

Malicious node-ipc npm releases turned a package update into a credential-exposure event. Here is what SMBs and government contractors should check first.

Read More
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • …
  • 33

File Search

2
📁 Home → 📁 IOCs_YARA_TTPs_Posted_Articles ↓
ThumbNameSizeDate
Thumb AsyncRAT-loader-URL-Check.txt AsyncRAT loader URL Check.txt

text/plainAsyncRAT loader URL Check.txt

Open Download Copy Link 2.46 KB 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
2.46 KBJanuary 7, 2024
Thumb AsyncRAT-loader-hashes.txt AsyncRAT loader hashes.txt

text/plainAsyncRAT loader hashes.txt

Open Download Copy Link 662 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
662 BJanuary 7, 2024
Thumb Hackers-Modifying-Registry-Keys-to-Establish-Persistence-via-Scheduled-Tasks.txt Hackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks.txt

text/plainHackers Modifying Registry Keys to Establish Persistence via Scheduled Tasks.txt

Open Download Copy Link 945 B 2024-01-12 January 12, 2024 2024-01-06 January 6, 2024
945 BJanuary 6, 2024
Thumb Hackers-target-Apache-RocketMQ-servers-vulnerable-to-RCE-attack.txt Hackers target Apache RocketMQ servers vulnerable to RCE attack.txt

text/plainHackers target Apache RocketMQ servers vulnerable to RCE attack.txt

Open Download Copy Link 77 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
77 BJanuary 5, 2024
Thumb IOC-and-TTPs-Backdoor_Win32-Carbanak-Anunak-Named-Pipe-Null-DACL.txt IOC and TTPs Backdoor.Win32 Carbanak (Anunak) - Named Pipe Null DACL.txt

text/plainIOC and TTPs Backdoor.Win32 Carbanak (Anunak) - Named Pipe Null DACL.txt

Open Download Copy Link 5.02 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
5.02 KBJanuary 11, 2024
Thumb IOCs-Chapter-84-In-depth-analysis-and-technical-analysis-of-LockBit-the-top-encryption-ransomware-organization-Part-1.txt IOCs Chapter 84 In-depth analysis and technical analysis of LockBit the top encryption ransomware organization Part 1.txt

text/plainIOCs Chapter 84 In-depth analysis and technical analysis of LockBit the top encryption ransomware organization Part 1.txt

Open Download Copy Link 236 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
236 BJanuary 7, 2024
Thumb IOCs-and-TTPs-Financially-motivated-threat-actors-misusing-App-Installer.txt IOCs and TTPs Financially motivated threat actors misusing App Installer.txt

text/plainIOCs and TTPs Financially motivated threat actors misusing App Installer.txt

Open Download Copy Link 7.26 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
7.26 KBJanuary 9, 2024
Thumb IOCs-and-TTPs_-Analysis-of-OT-cyberattacks-and-malwares.txt IOCs and TTPs_ Analysis of OT cyberattacks and malwares.txt

text/plainIOCs and TTPs_ Analysis of OT cyberattacks and malwares.txt

Open Download Copy Link 8.82 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
8.82 KBJanuary 9, 2024
Thumb IOCs-and-Yara-Hundreds-of-Thousands-of-Dollars-Worth-of-Solana-Cryptocurrency-Assets-Stolen-in-Recent-CLINKSINK-Drainer-Campaigns.txt IOCs and Yara Hundreds of Thousands of Dollars Worth of Solana Cryptocurrency Assets Stolen in Recent CLINKSINK Drainer Campaigns.txt

text/plainIOCs and Yara Hundreds of Thousands of Dollars Worth of Solana Cryptocurrency Assets Stolen in Recent CLINKSINK Drainer Campaigns.txt

Open Download Copy Link 1.38 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
1.38 KBJanuary 11, 2024
Thumb IOCs-and-other-AsyncRat.txt IOCs and other AsyncRat.txt

text/plainIOCs and other AsyncRat.txt

Open Download Copy Link 1.04 KB 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
1.04 KBJanuary 7, 2024
Thumb IOCs-Deceptive-Cracked-Software-Spreads-Lumma-Variant-on-YouTube.txt IOCs Deceptive Cracked Software Spreads Lumma Variant on YouTube.txt

text/plainIOCs Deceptive Cracked Software Spreads Lumma Variant on YouTube.txt

Open Download Copy Link 1.16 KB 2024-01-12 January 12, 2024 2024-01-08 January 8, 2024
1.16 KBJanuary 8, 2024
Thumb IOCs-DreamBus-Unleashes-Metabase-Mayhem-With-New-Exploit-Module.txt IOCs DreamBus Unleashes Metabase Mayhem With New Exploit Module.txt

text/plainIOCs DreamBus Unleashes Metabase Mayhem With New Exploit Module.txt

Open Download Copy Link 1.65 KB 2024-01-12 January 12, 2024 2024-01-11 January 11, 2024
1.65 KBJanuary 11, 2024
Thumb IOCs-Hide-and-Seek-in-Windows-Closet-Unmasking-the-WinSxS-Hijacking-Hideout.txt IOCs Hide and Seek in Windows' Closet Unmasking the WinSxS Hijacking Hideout.txt

text/plainIOCs Hide and Seek in Windows' Closet Unmasking the WinSxS Hijacking Hideout.txt

Open Download Copy Link 415 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
415 BJanuary 5, 2024
Thumb IOCs-TTPs-and-yara-Opening-a-Can-of-Whoop-Ads-Detecting-and-Disrupting-a-Malvertising-Campaign-Distributing-Backdoors.txt IOCs TTPs and yara Opening a Can of Whoop Ads Detecting and Disrupting a Malvertising Campaign Distributing Backdoors.txt

text/plainIOCs TTPs and yara Opening a Can of Whoop Ads Detecting and Disrupting a Malvertising Campaign Distributing Backdoors.txt

Open Download Copy Link 15.56 KB 2024-01-12 January 12, 2024 2024-01-09 January 9, 2024
15.56 KBJanuary 9, 2024
Thumb IOCs-Tackling-Anti-Analysis-Techniques-of-GuLoader-and-RedLine-Stealer.txt IOCs Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer.txt

text/plainIOCs Tackling Anti-Analysis Techniques of GuLoader and RedLine Stealer.txt

Open Download Copy Link 143 B 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
143 BJanuary 5, 2024
Thumb Prior-to-Cyber-Attack-Russian-Attackers-Spent-Months-Inside-the-Ukraine-Telecoms-Giant.txt Prior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant.txt

text/plainPrior to Cyber Attack, Russian Attackers Spent Months Inside the Ukraine Telecoms Giant.txt

Open Download Copy Link 168 B 2024-01-12 January 12, 2024 2024-01-07 January 7, 2024
168 BJanuary 7, 2024
Thumb yara-rules-from-100-Days-of-Yara-and-other-infor.txt yara rules from 100 Days of Yara and other infor.txt

text/plainyara rules from 100 Days of Yara and other infor.txt

Open Download Copy Link 49.69 KB 2024-01-12 January 12, 2024 2024-01-05 January 5, 2024
49.69 KBJanuary 5, 2024
Thumb Pig-butchering-is-an-evolution-of-a-social-engineering-tactic-weve-seen-for-years.txt Pig butchering is an evolution of a social engineering tactic we’ve seen for years.txt

text/plainPig butchering is an evolution of a social engineering tactic we’ve seen for years.txt

Open Download Copy Link 770 B 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
770 BMarch 22, 2024
Thumb IOCs-Curious-Serpens-FalseFont-Backdoor-Technical-Analysis-Detection-and-Prevention.txt IOCs Curious Serpens FalseFont Backdoor Technical Analysis Detection and Prevention.txt

text/plainIOCs Curious Serpens FalseFont Backdoor Technical Analysis Detection and Prevention.txt

Open Download Copy Link 501 B 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
501 BMarch 22, 2024
Thumb IOCs-The-Updated-APT-Playbook-Tales-from-the-Kimsuky-threat-actor-group.txt IOCs The Updated APT Playbook Tales from the Kimsuky threat actor group.txt

text/plainIOCs The Updated APT Playbook Tales from the Kimsuky threat actor group.txt

Open Download Copy Link 1.44 KB 2024-03-22 March 22, 2024 2024-03-22 March 22, 2024
1.44 KBMarch 22, 2024
https://bulwarkblack.com/page/4?ee=1&eeFolder=IOCs_YARA_TTPs_Posted_Articles&eeListID=2 0 1

1 - 20 21 - 21

Page: 1 of 2

20

9c7306c2b7

2026 Powered By BlazeThemes.