ATT-systeme Intrusion

05
Jul
The Art of Looking Innocent: Iran's Dual-Track Tradecraft Evolution- 198

The Art of Looking Innocent: Iran's Dual-Track Tradecraft Evolution- 198

June 23, 2026 Iran's most effective cyber operations in 2026 do not announce themselves. One looked like routine
4 min read
05
Jul
Humanitarian Cover: Operation HumanitarianBait and the Surveillance Campaign Nobody Has Attributed- 190

Humanitarian Cover: Operation HumanitarianBait and the Surveillance Campaign Nobody Has Attributed- 190

June 15, 2026 A humanitarian aid application form, written in Russian, realistic enough that someone waiting for assistance would read
3 min read
05
Jul
The Door Left Open: FamousSparrow's Three-Wave Intrusion into Azerbaijani Energy Infrastructure- 187

The Door Left Open: FamousSparrow's Three-Wave Intrusion into Azerbaijani Energy Infrastructure- 187

June 7, 2026 ProxyNotShell was publicly disclosed in October 2022. The Exchange server at the center of the FamousSparrow intrusion
3 min read
05
Jul
The Elected Leader: How Turla Rebuilt Kazuar as a Peer-to-Peer Espionage Botnet- 186

The Elected Leader: How Turla Rebuilt Kazuar as a Peer-to-Peer Espionage Botnet- 186

June 13, 2026 Turla has been running espionage operations for more than two decades. In that time, defenders have learned
3 min read
05
Jul
The Disgruntled Researcher and the Dead Man's Switch: Nightmare-Eclipse's Zero-Day Campaign- 184

The Disgruntled Researcher and the Dead Man's Switch: Nightmare-Eclipse's Zero-Day Campaign- 184

June 5, 2026 Five Windows zero-days in a single year, released by a single anonymous researcher, timed to maximally
2 min read
05
Jul
The Sleeper Strategy: GlassWorm's Evolution Into Delayed-Activation Supply Chain Attacks- 181

The Sleeper Strategy: GlassWorm's Evolution Into Delayed-Activation Supply Chain Attacks- 181

June 12, 2026 The extension passed every security check when it was uploaded. It was clean — because at the time
2 min read
05
Jul
The Invisible Guest: How QEMU Became a Ransomware Delivery Vehicle- 179

The Invisible Guest: How QEMU Became a Ransomware Delivery Vehicle- 179

June 10, 2026 Ransomware operators have found a hiding place inside one of the most ordinary tools in the enterprise
2 min read
05
Jul
The Authentication Trap: How Device Code Phishing Became the Credential Theft of Choice- 178

The Authentication Trap: How Device Code Phishing Became the Credential Theft of Choice- 178

June 8, 2026 Multifactor authentication was supposed to make credential phishing obsolete. It did not. It made credential phishers more
4 min read