Hide the threat โ GPO lateral movement
www.intrinsec.com/hide-the-thr...
@marktsec.bsky.social
๐ซThreat Intel๐ซ Automation๐ซ Threat Analysis ๐ซOSINT๐ซ Testing ๐ซNetwork Security๐ซ https://github.com/marktsec
Hide the threat โ GPO lateral movement
www.intrinsec.com/hide-the-thr...
Sophisticated Water Gamayun APT Group Attack
www.zscaler.com/blogs/securi...
Youโre invited: Four phishing lures in campaigns dropping RMM tools
redcanary.com/blog/threat-...
Meet Rey, the Admin of โScattered Lapsus$ Huntersโ
krebsonsecurity.com/2025/11/meet...
Inside DPRKโs Fake Job Platform Targeting U.S. AI Talent
www.validin.com/blog/inside_...
APT41 Cyber Attacks: History, Operations, and Full TTP Analysis
www.picussecurity.com/resource/blo...
Deep scan for bad NPM packages nested across projects - DFIR for Shai-Hulud cyberattack
gist.github.com/alexgreenlan...
When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446)
labs.watchtowr.com/when-the-imp...
Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High
www.greynoise.io/blog/palo-al...
๐จ Stealc v2.8.0 update observed:
โข Updated Edge module to extract the new v20 key
โข Expanded crypto-wallet targeting (incl. LTC/Dash Core, Trezor Suite, MEW Desktop, AtomicDEX & more)
โข Improved C2 marker parsing + performance fixes
#ThreatIntel #InfoSec
LSASS Dump โ Windows Error Reporting
ipurple.team/2025/11/18/l...
XFiles Spyware Update
20.11.2025 05:43 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0License to Encrypt: โThe Gentlemenโ Make Their Move
www.cybereason.com/blog/the-gen...
Russian alleged cyber-hacker faces extradition to US after arrest in Thailand.
Denis Obrezko is allegedly part of the notorious group Void Blizzard
edition.cnn.com/2025/11/15/a...
Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery
blog.nviso.eu/2025/11/13/c...
Path confusion vulnerability in GUI
fortiguard.fortinet.com/psirt/FG-IR-...
Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446)
16.11.2025 12:09 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Detection Artifact Generator for FortiWeb Authentication Bypass
github.com/watchtowrlab...
Operation Endgame - The actions targeted one of the biggest infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium.
13.11.2025 12:46 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Rhadamanthys infostealer disrupted as cybercriminals lose server access
www.bleepingcomputer.com/news/securit...
Phishing kit targeting MS login pages
intelinsights.substack.com/p/intel-drop...
Post claiming a โ100% working EDR/XDR killerโ
#ThreatIntel #InfoSec
Phishing Campaigns โI Paid Twiceโ Targeting Booking.com Hotels and Customers
blog.sekoia.io/phishing-cam...
Meta is earning a fortune on a deluge of fraudulent ads, documents show
www.reuters.com/investigatio...
Matanbuchus loader now ships as shellcode (BIN), supports in-memory .NET execution and payloads from ZIPs; sideload techniques refreshed. Operators added 2FA+CAPTCHA to the C2 and claim an unprecedented โwhite injectโ #InfoSec #threatintel
06.11.2025 17:51 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0CLOP RANSOMWARE: DISSECTING NETWORK
theravenfile.com/2025/11/04/c...
Alleged Jabber Zeus Coder โMrICQโ in U.S. Custody
krebsonsecurity.com/2025/11/alle...
Kubernetes Penetration Testing: Methodology & Guide
deepstrike.io/blog/kuberne...
๐จ New KATREUS Miner (Silent XMR Miner)
Advertised on underground forums with:
โข Anti-kill, watchdog, persistence & injection modules
โข AV evasion claims (C + ASM)
โข Targets Windows 8.1 โ Server 2025
โข Seller offering only 5 โlicensesโ
#ThreatIntel #Cryptomining #InfoSec