Topic
Emerging Issue

CTI roundup: Astaroth, TA585, Microsoft tech support scams
Astaroth trojan uses GitHub to host malware configurations, TA585 delivers MonsterV2 malware in phishing campaigns, and threat actors exploit Microsoft’s logo in tech support scams

CTI roundup: XWorm, Microsoft Teams, Storm-1175
XWorm malware reemerges with ransomware, Microsoft disrupts multiple threats targeting Teams, and Storm-1175 exploits a critical GoAnywhere MFT vulnerability

CTI roundup: DarkCloud, Trinity of Chaos, WARMCOOKIE
Check out the latest insights on DarkCloud malware, the “Trinity of Chaos” alliance, and WARMCOOKIE updates.

CTI Roundup: SystemBC, ShinyHunters, AI-obfuscated Phishing
SystemBC botnet targets VPS infrastructure, ShinyHunters targets enterprise cloud applications, and a phishing campaign uses AI-generated code to avoid detection

Cisco CVEs: What You Need to Know About These Zero-Day Vulnerabilities
Details from Tanium’s Guardian research team on CVE-2025-20333, -20362, and -20363—and RAYINITIATOR & LINE VIPER.

CTI Roundup: AMOS, TAG-150, GPUGate
AMOS Stealer campaign targets macOS, TAG-150 deploys new CastleRAT malware, and GPUGate targets IT firms in Western Europe

CTI Roundup: HexStrike AI, TinkyWinkey, Silver Fox APT
The latest on HexStrike AI, TinkyWinkey’s keylogging, and Silver Fox APT’s driver abuse bypassing endpoint defenses.

Modernizing federal cryptography in the quantum age: From urgency to unified action
Quantum computing is no longer a distant threat. It’s now a real, operational risk to cybersecurity’s foundations.

CTI Roundup: Linux Malware, UNC5518, PRC-Nexus
New Linux malware evades antivirus detection, UNC5518 deploys CORNFLAKE.V3 using ClickFix and fake CAPTCHA pages, and a PRC-Nexus campaign hijacks web traffic.

Salesloft Drift Data Breach: What We Know and What We're Doing
Hackers breached Salesloft in a major data theft, stealing OAuth and refresh tokens from Drift AI.

CTI Roundup: Malicious Python Packages, PipeMagic, Noodlophile Stealer
Researchers uncover malicious Python packages, PipeMagic masquerades as a ChatGPT desktop app, and Noodlophile Stealer targets enterprises through social media

CTI Roundup: EDR Killer, PS1Bot, Charon Ransomware
Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors