One Regime, Four Fronts: Inside North Korea's Parallel Cyber Enterprise- 302
August 8, 2026
It would be easier to track North Korea's state-linked cyber activity if it all
The Long Wire: How Beijing Builds Access That Outlasts Its Cover Stories- 297
August 12, 2026
Four episodes surfaced within days of each other in August 2026, and none of them, on its
Borrowed Trust: How Moscow Turns Everyday Software Into an Access Network- 296
August 5, 2026
A fake job offer, a hijacked hotel Wi-Fi login, a criminal marketplace listing, and an advertising
When cybercrime borrows a spy's toolkit: the UAT-11795 campaign hiding inside everyday software- 292
July 18, 2026
A financially motivated, Russian-speaking hacking crew has spent over a year quietly trojanizing the installers of
Tax season as an attack surface: how a suspected Chinese hacking cluster is running parallel RAT campaigns across India, Japan, and China- 283
July 7, 2026
A suspected China-nexus threat cluster has spent the current Indian tax filing season running a precisely-
The Certificate Authority's Blind Spot: How a Trusted Signing Chain Became a Weapon- 255
July 18, 2026
In April 2026, a routine support interaction at DigiCert — a customer service chat, a screenshot-disguised ZIP
North Korea just made its malware payload host itself on the blockchain- 252
July 5, 2026
North Korean threat actors behind the long-running Contagious Interview campaign have distributed more than 100 malicious
Three times through the same door: FamousSparrow's patient campaign against Azerbaijan's energy sector- 239
December 25, 2025
A China-linked espionage group returned to the exact same compromised Microsoft Exchange server three separate times
The Door Left Open: FamousSparrow's Three-Wave Intrusion into Azerbaijani Energy Infrastructure- 187
June 7, 2026
ProxyNotShell was publicly disclosed in October 2022. The Exchange server at the center of the FamousSparrow intrusion
North Korea’s KONNI Cluster Weaponizes Google’s Find My Device: A New Phase in DPRK Android Targeting- 117
November 18, 2025
North Korean operators from the KONNI activity cluster—affiliated with Kimsuky and APT37—have begun exploiting Google’