The Art of Looking Innocent: Iran's Dual-Track Tradecraft Evolution- 198
June 23, 2026
Iran's most effective cyber operations in 2026 do not announce themselves. One looked like routine
Humanitarian Cover: Operation HumanitarianBait and the Surveillance Campaign Nobody Has Attributed- 190
June 15, 2026
A humanitarian aid application form, written in Russian, realistic enough that someone waiting for assistance would read
The Door Left Open: FamousSparrow's Three-Wave Intrusion into Azerbaijani Energy Infrastructure- 187
June 7, 2026
ProxyNotShell was publicly disclosed in October 2022. The Exchange server at the center of the FamousSparrow intrusion
The Elected Leader: How Turla Rebuilt Kazuar as a Peer-to-Peer Espionage Botnet- 186
June 13, 2026
Turla has been running espionage operations for more than two decades. In that time, defenders have learned
The Disgruntled Researcher and the Dead Man's Switch: Nightmare-Eclipse's Zero-Day Campaign- 184
June 5, 2026
Five Windows zero-days in a single year, released by a single anonymous researcher, timed to maximally
The Sleeper Strategy: GlassWorm's Evolution Into Delayed-Activation Supply Chain Attacks- 181
June 12, 2026
The extension passed every security check when it was uploaded. It was clean — because at the time
The Invisible Guest: How QEMU Became a Ransomware Delivery Vehicle- 179
June 10, 2026
Ransomware operators have found a hiding place inside one of the most ordinary tools in the enterprise
The Authentication Trap: How Device Code Phishing Became the Credential Theft of Choice- 178
June 8, 2026
Multifactor authentication was supposed to make credential phishing obsolete. It did not. It made credential phishers more