Cyber Threat Intelligence
Articles about cyber threat intelligence, APT groups, and nation-state malware campaigns
Mini Shai-Hulud: The Python Startup Hook Powering the Hades Supply Chain Attack
How a tiny *-setup.pth file and the Bun JavaScript runtime became the delivery mechanism for one of 2026's most sophisticated PyPI poisoning campaigns — and why the Mini Shai-Hulud loader is now the default weapon for supply chain attackers.
AryStinger: The Silent Botnet Hijacking 4,000 Routers Worldwide
Qianxin’s XLab uncovers AryStinger—a previously unknown botnet that’s turned thousands of end-of-life D-Link routers into proxy nodes for scanning, tunneling, and traffic interception. Here’s what you need to know.
JDY Botnet: How a Reconnaissance Network Became the Eyes of China’s Cyber Offense
The JDY botnet, linked to Chinese threat actors like Volt Typhoon, has grown significantly, mapping global SOHO/IoT devices to target U.S. military networks for state-sponsored reconnaissance.
How a Client-Controlled Byte Broke Check Point’s VPN — And Why Qilin Ransomware Won
A critical authentication bypass in Check Point’s legacy IKEv1 implementation allowed Qilin ransomware affiliates to gain unauthenticated access — and it wasn’t a zero-day exploit, it was an ignored warning.
Unauthenticated Remote Code Execution in Fortinet FortiSandbox Under Active Exploitation by Threat Actors
Attackers are actively exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox platform, including unauthenticated command injection flaws that allow remote code execution without user interaction.
How Crypto Clipper Malware Hides Behind Tor's SOCKS5 Proxy to Steal Crypto Wallets
A deep dive into how the Crypto Clipper malware campaign uses a local SOCKS5 proxy at localhost:9050 to route all command-and-control traffic through Tor, evading traditional network defenses while stealing cryptocurrency seed phrases, private keys, and swapping wallet addresses.
Your Bluetooth Speaker Just Became a Remote Code Execution Vector
A security flaw in the Sound Blaster Katana V2X lets attackers upload custom firmware and turn the speaker into a HID keyboard proxy, executing arbitrary commands on any connected PC from Bluetooth range.
Contactless Card Harvesters: Inside the Latest NFCShare Android Campaigns Targeting European Banks
Security researchers have tracked the evolution of the NFCShare Android trojan, which has transitioned from localized campaigns to distributing malicious APK updates through GitHub repositories while employing anti-analysis tricks.
Unmasking AryStinger: A New Threat to Outdated Network Hardware
Analyze the AryStinger botnet: learn how this malicious threat targets outdated D-Link routers, its operational techniques, and essential steps to secure your network hardware. (Keywords: AryStinger, botnet, D-Link, router security, malware infection, IoT security)
Disguising Command-and-Control: How DragonForce Exploits Microsoft Teams Relays
An investigation into the techniques used by the DragonForce ransomware gang, specifically their utilization of a custom 'Backdoor.Turn' malware to tunnel malicious traffic through Microsoft Teams relay infrastructure. Includes verified attack chain details, BYOVD evasion techniques, and Backdoor.Turn capabilities from Symantec research.
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
The latest Mini-Shai-hulud payload introduces Hades-themed GitHub exfiltration markers and AI analyst misdirection. TeamPCP compromised 19 PyPI packages (37 malicious wheels) via wheel startup hooks, deploying cross-platform memory scrapers and a token-revocation wiper. Read more about understanding supply chain risk in our Cyber Threat Intelligence category. Learn more about Supply Chain Security. Python Security Essentials.
Unraveling the HTTP/2 Rapid Reset: A Threat to Large-Scale Web Infrastructure
This article explores the mechanics of CVE-2023-44487, commonly known as the HTTP/2 Rapid Reset vulnerability, and its severe impact on organizations with extensive, distributed web footprints.