Topic
Emerging Issue

CTI Roundup: Malicious Python Packages, PipeMagic, Noodlophile Stealer
Researchers uncover malicious Python packages, PipeMagic masquerades as a ChatGPT desktop app, and Noodlophile Stealer targets enterprises through social media

CTI Roundup: EDR Killer, PS1Bot, Charon Ransomware
Ransomware groups adopt shared EDR-killing tool, PS1Bot spreads via malvertising, and Charon ransomware uses APT-style tactics to target critical sectors

CTI Roundup: ClickFix, New Attacker Insights, PXA Stealer
Discover how attackers hijack CAPTCHAs, why CVE activity spikes matter, and global PXA threats.

CTI Roundup: Katz Stealer, Lumma, NailaoLocker
Katz Stealer seeks credentials and crypto assets, Lumma Stealer returns after a disruption, NailaoLocker ransomware targets Windows

CTI Roundup: BlackSuit, AsyncRAT, HazyBeacon
BlackSuit ransomware combines data exfiltration and encryption, AsyncRAT spawns multiple forks, and HazyBeacon abuses AWS Lambda for command and control

CTI Roundup: BERT Ransomware, TGR-CRI-0045, XWorm
Get the latest on BERT ransomware, TGR-CRI-0045 exploits, and XWorm’s stealthy evolution in this week’s CTI roundup.

CTI Roundup: GIFTEDCROOK, H1 2025 Threats, Jasper Sleet
Get the latest on GIFTEDCROOK’s evolution, Jasper Sleet’s infiltration tactics, and rising cyber threats in ESET’s H1 2025 report.

The Davidson Window: An Urgent Cyber Call to Action
Understand the Davidson Window’s 2027 warning and how Tanium enables real-time cyber defense across federal IT.

CTI Roundup: Rogue Tools, ClickFix, and BlueNoroff
Cyber attackers exploit legitimate tools, ClickFix attacks accelerate, and BlueNoroff targets macOS devices

CTI Roundup: UNC6032, APT41, Void Blizzard
The latest on UNC6032 fake AI websites, APT41’s use of Google Calendar, and Void Blizzard targeting critical sectors.

CTI Roundup: Hazy Hawk, Remcos RAT, and npm Phishing
Recent news on Hazy Hawk using DNS records, a fileless Remcos RAT campaign, and the use of AES encryption with malicious npm packages in phishing attack.

CTI Roundup: Marbled Dust, Horabot, and TA406
Learn about Marbled Dust exploiting a zero-day vulnerability in Output Messenger, a new phishing campaign using Horabot malware, and TA406 changing targets.