Back to Blog

Threat Hunting & Intel

32 posts
Oracle PeopleSoft alert follows breach claims at 100+ organizations

Oracle PeopleSoft alert follows breach claims at 100+ organizations

Oracle PeopleSoft alert follows breach claims at 100+ organizations Claims of mass compromise across Oracle PeopleSoft environments were already serious on June...

June 11, 2026
7 min read
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure

LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure

LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure | 2026 Executive Summary Push Security disclosed a live campaign it tracks as LLMShare, w...

June 3, 2026
7 min read
GlassWorm takedown shows how developer malware becomes supply-chain risk

GlassWorm takedown shows how developer malware becomes supply-chain risk

GlassWorm takedown shows how developer malware becomes supply-chain risk Executive Summary The coordinated disruption of GlassWorm on May 26, 2026 is useful bec...

May 30, 2026
6 min read
AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking

AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking

AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking Executive Summary Microsoft disclosed an active campaign on May 26, 2026 in which attackers push...

May 28, 2026
7 min read
Kazuar’s redesign turns a familiar backdoor into a harder-to-hunt botnet

Kazuar’s redesign turns a familiar backdoor into a harder-to-hunt botnet

Kazuar’s redesign turns a familiar backdoor into a harder-to-hunt botnet Microsoft’s latest research on Kazuar matters because it reframes the malware from a we...

May 17, 2026
5 min read
TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels

TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels

TCLBANKER turns WhatsApp and Outlook into trusted malware delivery channels The most important detail in Elastic's new TCLBANKER research is not just that a Bra...

May 9, 2026
5 min read
DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path The most important part of the DAEMON Tools incident is not that malware...

May 6, 2026
5 min read
CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets

CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets

CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets CVE-2026-41940 is a critical authentication bypass in cPanel and WHM, an...

April 30, 2026
5 min read
Firestarter leaves patched Cisco firewalls at continued risk

Firestarter leaves patched Cisco firewalls at continued risk

Firestarter leaves patched Cisco firewalls at continued risk A newly detailed persistence mechanism called Firestarter changes the defender story around last ye...

April 26, 2026
5 min read
AgingFly campaign hits Ukrainian government and hospital networks

AgingFly campaign hits Ukrainian government and hospital networks

AgingFly campaign hits Ukrainian government and hospital networks A newly reported campaign centered on the AgingFly backdoor is a reminder that targeted intrus...

April 16, 2026
5 min read
CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path Executive summary A compromise of the CPUID website briefly turned trusted download links f...

April 13, 2026
5 min read
Iranian PLC Attacks Disrupt U.S. Critical Infrastructure

Iranian PLC Attacks Disrupt U.S. Critical Infrastructure

Iranian PLC Attacks Disrupt U.S. Critical Infrastructure Executive Summary Iranian-affiliated [advanced persistent threat](https://invaders.ie/resources/glossar...

April 9, 2026
7 min read