Intelligence

Stay informed with the latest in cybersecurity intel, breaking news, threat analysis, data breaches, ransomware attacks, and expert insights. Whether you're a professional or enthusiast, we provide up-to-date information to keep you secure and ahead of cyber threats. Explore in-depth articles, reports, and advice to protect your digital world. Join our community and stay cyber-aware with us.

OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company
Intelligence

OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company

This article covers a post-incident OSINT investigation that linked a recent business email compromise back to an Australian carpet company, due to a DNS registration mishap by the attacker. Persistence and pivoting are key for investigators!

·SirPicklJohn
What IS the Dark Web Anyway?
Operations Security

What IS the Dark Web Anyway?

A bird's eye view of the Dark Web focused on the essentials. If the inner workings of the Dark Web remain a mystery to you, this post was made to change that.

·r3g1s
Intelphreak - February 28, 2025
Intelligence

Intelphreak - February 28, 2025

The Ghost/Cring Ransomware Gang's Unique Success; DMARC Required Under PCI DSS On March 31st of 2025; Apple Removes iCloud Encryption for UK; Recent High Efficacy Social Engineering Tactics; North Korean-Linked Attackers Stole $1.46 Billion in Crypto From Bybit Exchange

·ResidentGood
New Insights on the Ghost Ransomware Gang and their Peculiar Success
Research

New Insights on the Ghost Ransomware Gang and their Peculiar Success

This cyber threat intelligence investigation hunts ghosts - seeking to answer why the Ghost/Cring ransomware gang is so successful at eluding security researchers and being profitable, especially when they avoid phishing in favor of targeting known-vulnerabilities in internet-facing systems.

·SirPicklJohn
A Demonstration of the Potential for Modern LLM Abuse by Threat Actors
Research

A Demonstration of the Potential for Modern LLM Abuse by Threat Actors

This article details the findings of two studies that highlight how security vulnerabilities in publicly-accessible LLMs can present a threat to public security through the proliferation of malicious knowledge, guidance in committing illegal activities, and generation of malicious content.

·SirPicklJohn
Intelphreak - February 11, 2025
Intelligence

Intelphreak - February 11, 2025

Trump Disbands DHS Advisory Boards, LLM Jailbreaks Are Fueling Threats, DeepSeek Has Global Impact, Vulnerabilities in Contec Patient Monitors Allow PII Leakage & RCE, Subaru STARLINK Vulnerability Allowed Unauthorized Remote Control of Vehicles, 2 Vulnerabilities in Apple Hardware

·ResidentGood
Intelphreak - January 22, 2025
Intelligence

Intelphreak - January 22, 2025

Phishing Campaigns Target California Fires, TikTok Ban Delayed, UK Considers New Ransomware Laws, Critical MacOS Attacks & Security Bypasses, Treasury Attack Attributed to Silk Typhoon, Critical Aviatrix Exploit, Expired Domains Present New Security Threats, Patch Tuesday Fixes Major Security Issues

·ResidentGood
Intelphreak - January 8, 2025
Intelligence

Intelphreak - January 8, 2025

2024 Cybersecurity Recap, New Non-Social Engineering TTPs, Major Browser Extension Supply Chain Attack, Japan Airlines DDoS Attack, OpenAI Fined €15 Million, HHS Proposes Changes to HIPAA, Researchers Discover New Lazarus Group Malware Campaign, Chinese Nation-State Actors Breach US Treasury Data

·ResidentGood
2024 Recap of Cybersecurity, with Insights for the Future
Research

2024 Recap of Cybersecurity, with Insights for the Future

2024 saw record-breaking breaches, an incredible AI boom, novel techniques and attack chains, and highly sophisticated cybercrime & cyberwarfare operations. Cybersecurity came into the public purview due to the cascading effects of cyber incidents that affected millions of people worldwide.

·SirPicklJohn
Intelphreak - December 23, 2024
Intelligence

Intelphreak - December 23, 2024

Chinese APTs Target U.S. Infrastructure; IOCONTROL Malware Hits OT, IoT, SCADA Devices; Widespread WordPress Exploitation; Prometheus Toolkit Vulnerabilities; Latest On Social Engineering; PUMAKIT Malware Targets Linux Kernels; FTC Warning On Scam Task Jobs

·ResidentGood
Deeper Insights into the Recent U.S. Telecom Provider Hacks, and Chinese APT Activity
Research

Deeper Insights into the Recent U.S. Telecom Provider Hacks, and Chinese APT Activity

This cyber threat intelligence investigation covers the who, what, why, when, and how of the recent state-sponsored Chinese cyberattacks on U.S. telecommunications providers, as well as how they fit into a broader picture of cyber-espionage that displays years of rising geopolitical tensions.

·SirPicklJohn
Discord Users Beware: Lumma Stealer Malware Lurking in Your Communities
Research

Discord Users Beware: Lumma Stealer Malware Lurking in Your Communities

Cosmo Whales is an infostealer campaign masquerading as a Web3 videogame. Threat actors have been observed in the wild distributing malware via job advertisements for a Web3 game called Cosmo Whales.

·L0WK3Y
Intelphreak - 11:30Z September 18th, 2024
Intelligence

Intelphreak - 11:30Z September 18th, 2024

TfL Cyberattack Updates, Cloudflare Outage Leaves Some Websites Inaccessible, Chinese Aerospace Firm Employee Charged for Phishing Aerospace/Military Entities, TDSSKiller Used to Disable EDRs & Kawasaki Motors Europe Leak, Iran Tries to Hack Iraq, Port of Seattle Attack, New Oracle WebLogic Malware

·ResidentGood
Intelphreak - 10:00Z September 4th, 2024
Intelligence

Intelphreak - 10:00Z September 4th, 2024

IT Outages in Netherlands, PoorTry Windows Driver Evolves, Iran-Sponsored Threat Actor Engages in Intelligence Operations on US & UAE targets, FlyCASS Vulnerability Risks Security Bypass, NK Threat Actors Exploit Chrome Zero-Day, GitHub Comments Distributing Malware, Cicada3301 Targets ESXi Systems

·ResidentGood
Threat Intelligence vs. Threat Hunting: Distinct Roles, Unified Defense
Defensive Security

Threat Intelligence vs. Threat Hunting: Distinct Roles, Unified Defense

This blog aims to provide a clear and comprehensive understanding of threat intelligence and threat hunting, their differences and how they work together.

·L0WK3Y
Intelphreak - 4:00Z August 29th, 2024
Intelligence

Intelphreak - 4:00Z August 29th, 2024

The US Department of State & US Secret Service Have Issued a Reward of Up to $2.5 Million for Information Leading to the Arrest of Volodymyr Kadariya in Any Country

·ResidentGood
Intelphreak - 10:30Z July 29th, 2024
Intelligence

Intelphreak - 10:30Z July 29th, 2024

Threat Actors Use Cloud to Host Campaigns, LASC Network Compromise, E-Commerce Credit Card Skimmers, Evasive Panda Upgrades, “USDoD” CrowdStrike Breach, Videogame Used to Exfiltrate Data, Telegram Zero-Day, Selenium Grid Crypto Mining, Leidos Leak, New Report on North Korean Cyber Campaigns

·ResidentGood
Intelphreak - 10:30Z July 22nd, 2024
Intelligence

Intelphreak - 10:30Z July 22nd, 2024

CrowdStrike Outage, Delinea Fixes Privilege Vulnerability, Malicious NPM Packages Discovered, Cisco Patches Secure Email Gateway, Rite Aid Data Breach, Ransomware Group Continues ESXi Exploitation, FIN7 Rebrands to Sell Malicious Tools, New Research on APT41, Treasury Sanctions Russian Hacktivists

·ResidentGood
Intelphreak - 4:00Z July 15th, 2024
Intelligence

Intelphreak - 4:00Z July 15th, 2024

Increased Hacktivisim Until 2025, NSA Release on PRC APT, AllHere Faces Financial & Privacy Trouble, Shopify Data Breach Origin, Ticketmaster Leaks, RADIUS Vulnerability, Espionage Groups Using ORB Networks, OpenSSH Vulnerability Allows RCE, Research Says Attackers Exploited a Windows Zero-Day

·ResidentGood
Intelphreak - 12:30Z June 25th, 2024
Intelligence

Intelphreak - 12:30Z June 25th, 2024

EU Delays Vote on Surveillance Legislation, CDK Global Cyber Attacks, Espionage Actor Persists via Fortinet/Ivanti/VMWare CVEs, AI & Hydrogen Firms Partner with Nuclear Energy Companies, Army Debuts New AI Program, SneakyChef Deploys SugarGh0st Malware, US Government Clamps Down on Kaspersky

·ResidentGood
Intelphreak - 21:00Z June 18th, 2024
Intelligence

Intelphreak - 21:00Z June 18th, 2024

Microsoft Whistleblower, Sygnia Uncovers China-Linked Threat Actor, UK Hospitals Need Trainees’ Help After Cyber Attack, Talos Intelligence Has Identified a Pakistani APT Targeting Indian Entities, VulnCheck Report Shows 90% Increase in Disclosed Exploited Vulnerabilities Since April

·ResidentGood
Intelphreak - 20:00Z June 10th, 2024
Intelligence

Intelphreak - 20:00Z June 10th, 2024

Microsoft Recall Will Be Opt-In, Study Shows LLMS Can Exploit “Zero-Day” Vulnerabilities, CJEU Rules Copyright Over IP Privacy, Threat Actors Potentially Compromise Snowflake, Cyber Attacks on Russia & Belarus Companies, Global Operation “Endgame” Disrupts Over 100 Malicious Servers

·ResidentGood