REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2333 reports · page 57 of 59
eset · tlp:amber · 3/19/2026, 9:55:08 AM
EDR killers explained: Beyond the drivers ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers EDR killers explained: Beyond the drivers Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital secu…
Read original ↗https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-driversmandiant · tlp:amber · 3/18/2026, 2:00:00 PM
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors Introduction Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors…
checkpoint_research · tlp:amber · 3/16/2026, 3:09:00 PM
16th March – Threat Intelligence Report For the latest discoveries in cyber research for the week of 16th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES United States-based medical technology company Stryker has suffered a cyberattack that caused a global disruption to its environment. The company said its surgical robotics, clinical communications platform, and life support monitors are […] The post 16th March – Threat Intelligence R…
Read original ↗https://research.checkpoint.com/2026/16th-march-threat-intelligence-reportmandiant · tlp:amber · 3/16/2026, 2:00:00 PM
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark Introduction Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ra…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscapeeset · tlp:amber · 3/13/2026, 10:00:00 AM
Face value: What it takes to fool facial recognition ESET’s Jake Moore used smart glasses, deepfakes and face swaps to ‘hack’ widely-used facial recognition systems – and he'll demo it all at RSAC 2026 Face value: What it takes to fool facial recognition Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat…
Read original ↗https://www.welivesecurity.com/en/privacy/face-value-what-takes-fool-facial-recognitioncheckpoint_research · tlp:amber · 3/12/2026, 5:21:23 PM
“Handala Hack” – Unveiling Group’s Modus Operandi Key Findings Introduction Handala Hack, also tracked by Check Point Research as Void Manticore, is an Iranian threat actor that is known for multiple destructive wiping attacks combined with “hack and leak” operations. The threat actor operates several online personas, with the most prominent among them being Homeland Justice, maintained from mid-2022 specifically for multiple attacks […] The post “Handala Hack” &#…
Read original ↗https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandieset · tlp:amber · 3/12/2026, 2:17:33 PM
Cyber fallout from the Iran war: What to have on your radar The cybersecurity implications of the war in the Middle East extend far beyond the region. Here’s where to focus your defenses. Cyber fallout from the Iran war: What to have on your radar Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat report…
Read original ↗https://www.welivesecurity.com/en/business-security/cyber-fallout-iran-war-what-have-radartrail_of_bits · tlp:amber · 3/11/2026, 11:00:00 AM
Six mistakes in ERC-4337 smart accounts Account abstraction transforms fixed “private key can do anything” models into programmable systems that enable batching, recovery and spending limits, and flexible gas payment. But that programmability introduces risks: a single bug can be as catastrophic as leaking a private key. After auditing dozens of ERC‑4337 smart accounts, we’ve identified six vulnerability patterns that frequently appear. By the end of this post, you’ll be abl…
Read original ↗https://blog.trailofbits.com/2026/03/11/six-mistakes-in-erc-4337-smart-accountscheckpoint_research · tlp:amber · 3/10/2026, 4:54:53 PM
Iranian MOIS Actors & the Cyber Crime Connection Key Points Iran-linked actors are increasingly engaging with the cyber crime ecosystem. Their activity suggests a growing reliance on criminal tools, services, and operational models in support of state objectives. Iranian actors have long used cyber crime and hacktivism as cover for destructive activity, but the trend now suggests direct engagement with the criminal ecosystem. […] The post Iranian MOIS Actors & the …
Read original ↗https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connectioneset · tlp:amber · 3/10/2026, 9:58:00 AM
Sednit reloaded: Back in the trenches The resurgence of one of Russia’s most notorious APT groups Sednit reloaded: Back in the trenches Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security resource center WeLiveProgress COVID-19 Resources Vid…
Read original ↗https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenchesmandiant · tlp:amber · 3/6/2026, 2:00:00 PM
Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platforms . Background Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable. Destructive cyberatt…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attackseset · tlp:amber · 3/6/2026, 10:00:00 AM
What cybersecurity actually does for your business The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed What cybersecurity actually does for your business Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Thre…
Read original ↗https://www.welivesecurity.com/en/business-security/what-cybersecurity-actually-does-for-your-businessmandiant · tlp:amber · 3/5/2026, 2:00:00 PM
Look What You Made Us Patch: 2025 Zero-Days in Review Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan Executive Summary Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-revieweset · tlp:amber · 3/5/2026, 10:00:00 AM
How SMBs use threat research and MDR to build a defensive edge We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses How SMBs use threat research and MDR to build a defensive edge Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH Abou…
Read original ↗https://www.welivesecurity.com/en/business-security/how-smbs-use-threat-research-mdr-build-defensive-edgegoogle_project_zero · tlp:amber · 3/4/2026, 11:00:00 PM
On the Effectiveness of Mutational Grammar Fuzzing Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still adhere to the grammar rules, thus the structure of the samples gets maintained by the mutation process. In case of coverage-guided grammar fuzzing, if the resulting sample (after the mutation…
Read original ↗https://projectzero.google/2026/03/mutational-grammar-fuzzing.htmlmandiant · tlp:amber · 3/3/2026, 2:00:00 PM
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Introduction Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023) . The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehen…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kitgoogle_project_zero · tlp:amber · 2/25/2026, 11:00:00 PM
A Deep Dive into the GetProcessHandleFromHwnd API In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading the documentation for an API I don’t know about, assuming it’s documented at all. It can give you an idea of how long the API has…
Read original ↗https://projectzero.google/2026/02/gphfh-deep-dive.htmlmandiant · tlp:amber · 2/25/2026, 2:00:00 PM
Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign Introduction Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecommunications and government organizations in dozens of nations across four continents. The threat actor, UNC2814, is a suspected People's Republic of China (PRC)-nexus cyber espionage group that GTIG has tracked since 2017. This prolific, el…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaigntrail_of_bits · tlp:amber · 2/25/2026, 12:00:00 PM
mquire: Linux memory forensics without external dependencies If you’ve ever done Linux memory forensics, you know the frustration: without debug symbols that match the exact kernel version, you’re stuck. These symbols aren’t typically installed on production systems and must be sourced from external repositories, which quickly become outdated when systems receive updates. If you’ve ever tried to analyze a memory dump only to discover that no one has published symbols for tha…
Read original ↗https://blog.trailofbits.com/2026/02/25/mquire-linux-memory-forensics-without-external-dependenciestrail_of_bits · tlp:amber · 2/20/2026, 4:00:00 PM
Using threat modeling and prompt injection to audit Comet Before launching their Comet browser, Perplexity hired us to test the security of their AI-powered browsing features. Using adversarial testing guided by our TRAIL threat model, we demonstrated how four prompt injection techniques could extract users’ private information from Gmail by exploiting the browser’s AI assistant. The vulnerabilities we found reflect how AI agents behave when external content isn’…
Read original ↗https://blog.trailofbits.com/2026/02/20/using-threat-modeling-and-prompt-injection-to-audit-comettrail_of_bits · tlp:amber · 2/18/2026, 12:00:00 PM
Carelessness versus craftsmanship in cryptography Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. These bugs potentially affect thousands of downstream projects. When we shared one of these bugs with an affected vendor, strongSwan, the maintainer provided a model response for security vendors. The aes-js/pyaes maintainer, on the other hand, has taken a more… cavalier approach.…
Read original ↗https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptographymandiant · tlp:amber · 2/17/2026, 2:00:00 PM
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day Written by: Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson, Jr., Rich Reece Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines , tracked as CVE-2026-22769 , with a CVSSv3.1 score of 10.0 . Analysis of incident response en…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-daymandiant · tlp:amber · 2/12/2026, 2:00:00 PM
GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Introduction In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (AI) to accelerate the attack lifecycle, achieving productivity gains in reconnaissance, social engineering, and malware development. This report serves as an update to our November 2025 findings regarding the advan…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-usegoogle_project_zero · tlp:amber · 2/11/2026, 11:00:00 PM
Bypassing Administrator Protection by Abusing UI Access In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exist. I described one of the ways I was able to bypass the feature before it was released. In total I found 9 bypasses during my research that have now all been fixed. In this blog post I wanted to describe the root cause of 5 of those 9 issues, specifically the imple…
Read original ↗https://projectzero.google/2026/02/windows-administrator-protection.htmlmandiant · tlp:amber · 2/10/2026, 2:00:00 PM
Beyond the Battlefield: Threats to the Defense Industrial Base Introduction In modern warfare, the front lines are no longer confined to the battlefield; they extend directly into the servers and supply chains of the industry that safeguards the nation. Today, the defense sector faces a relentless barrage of cyber operations conducted by state-sponsored actors and criminal groups alike. In recent years, Google Threat Intelligence Group (GTIG) has observed several distinct ar…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-basemandiant · tlp:amber · 2/9/2026, 2:00:00 PM
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to UNC1069 , a financially motivated threat actor active since at least 2018. This investigation r…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineeringmandiant · tlp:amber · 1/30/2026, 2:00:00 PM
Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS Introduction Mandiant is tracking a significant expansion and escalation in the operations of threat clusters associated with ShinyHunters-branded extortion. As detailed in our companion report, 'Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft' , these campaigns leverage evolved voice phishing (vishing) and victim-branded credential harves…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saasmandiant · tlp:amber · 1/30/2026, 2:00:00 PM
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft Introduction Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) cred…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-thefttrail_of_bits · tlp:amber · 1/30/2026, 12:00:00 PM
Celebrating our 2025 open-source contributions Last year, our engineers submitted over 375 pull requests that were merged into non–Trail of Bits repositories, touching more than 90 projects from cryptography libraries to the Rust compiler. This work reflects one of our driving values: “share what others can use.” The measure isn’t whether you share something, but whether it’s actually useful to someone else. This principle is why we publish handbooks …
Read original ↗https://blog.trailofbits.com/2026/01/30/celebrating-our-2025-open-source-contributionsgoogle_project_zero · tlp:amber · 1/29/2026, 11:00:00 PM
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process o…
Read original ↗https://projectzero.google/2026/01/sound-barrier-2.htmltrail_of_bits · tlp:amber · 1/29/2026, 12:00:00 PM
Building cryptographic agility into Sigstore Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustworthy within 10 years. SHA-1 certificates become worthless, weak RSA keys are banned, and quantum computers may crack today’s elliptic curve cryptography. The question isn’t whether our current signatures will fail, but wh…
Read original ↗https://blog.trailofbits.com/2026/01/29/building-cryptographic-agility-into-sigstoremandiant · tlp:amber · 1/28/2026, 2:00:00 PM
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network Introduction This week Google and partners took action to disrupt what we believe is one of the largest residential proxy networks in the world, the IPIDEA proxy network. IPIDEA’s proxy infrastructure is a little-known component of the digital ecosystem leveraged by a wide array of bad actors. This disruption, led by Google Threat Intelligence Group (GTIG) in partnership with other teams, in…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-networkmandiant · tlp:amber · 1/27/2026, 2:00:00 PM
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 Introduction The Google Threat Intelligence Group (GTIG) has identified widespread, active exploitation of the critical vulnerability CVE-2025-8088 in WinRAR, a popular file archiver tool for Windows, to establish initial access and deliver diverse payloads. Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated threat actors …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerabilitygoogle_project_zero · tlp:amber · 1/25/2026, 11:00:00 PM
Bypassing Windows Administrator Protection A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the…
Read original ↗https://projectzero.google/2026/26/windows-administrator-protection.htmlgoogle_project_zero · tlp:amber · 1/14/2026, 9:01:00 AM
A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is p…
Read original ↗https://projectzero.google/2026/01/pixel-0-click-part-3.htmlgoogle_project_zero · tlp:amber · 1/14/2026, 9:00:00 AM
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using…
Read original ↗https://projectzero.google/2026/01/pixel-0-click-part-2.htmlgoogle_project_zero · tlp:amber · 1/14/2026, 8:59:00 AM
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Goo…
Read original ↗https://projectzero.google/2026/01/pixel-0-click-part-1.htmltrail_of_bits · tlp:amber · 1/13/2026, 12:00:00 PM
Lack of isolation in agentic browsers resurfaces old vulnerabilities With browser-embedded AI agents, we’re essentially starting the security journey over again. We exploited a lack of isolation mechanisms in multiple agentic browsers to perform attacks ranging from the dissemination of false information to cross-site data leaks. These attacks, which are functionally similar to cross-site scripting (XSS) and cross-site request forgery (CSRF), resurface decades-old patt…
Read original ↗https://blog.trailofbits.com/2026/01/13/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilitiestrail_of_bits · tlp:amber · 12/31/2025, 12:00:00 PM
Detect Go’s silent arithmetic bugs with go-panikint Go’s arithmetic operations on standard integer types are silent by default, meaning overflows “wrap around” without panicking. This behavior has hidden an entire class of security vulnerabilities from fuzzing campaigns. Today we’re changing that by releasing go-panikint , a modified Go compiler that turns silent integer overflows into explicit panics. We used it to find a live integer overflow in the Cosmos SDK’s RPC pagina…
Read original ↗https://blog.trailofbits.com/2025/12/31/detect-gos-silent-arithmetic-bugs-with-go-panikinttrail_of_bits · tlp:amber · 12/19/2025, 12:00:00 PM
Can chatbots craft correct code? I recently attended the AI Engineer Code Summit in New York, an invite-only gathering of AI leaders and engineers. One theme emerged repeatedly in conversations with attendees building with AI: the belief that we’re approaching a future where developers will never need to look at code again. When I pressed these proponents, several made a similar argument: Forty years ago, when high-level programming languages like C became increasingly popul…
Read original ↗https://blog.trailofbits.com/2025/12/19/can-chatbots-craft-correct-code