The Certificate Authority's Blind Spot: How a Trusted Signing Chain Became a Weapon- 255
July 18, 2026
In April 2026, a routine support interaction at DigiCert — a customer service chat, a screenshot-disguised ZIP
North Korea just made its malware payload host itself on the blockchain- 252
July 5, 2026
North Korean threat actors behind the long-running Contagious Interview campaign have distributed more than 100 malicious
Three times through the same door: FamousSparrow's patient campaign against Azerbaijan's energy sector- 239
December 25, 2025
A China-linked espionage group returned to the exact same compromised Microsoft Exchange server three separate times
The Door Left Open: FamousSparrow's Three-Wave Intrusion into Azerbaijani Energy Infrastructure- 187
June 7, 2026
ProxyNotShell was publicly disclosed in October 2022. The Exchange server at the center of the FamousSparrow intrusion
North Korea’s KONNI Cluster Weaponizes Google’s Find My Device: A New Phase in DPRK Android Targeting- 117
November 18, 2025
North Korean operators from the KONNI activity cluster—affiliated with Kimsuky and APT37—have begun exploiting Google’
Atroposia Malware Offers Attackers Built-In Tools to Spy, Steal, and Scan Systems- 87
November 7, 2025
Atroposia is a modular RAT that enables remote control of infected systems and data exfiltration for a