Threat Intelligence

AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirement

AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirement 2026-09-04 at 19:25 By Ashish Khaitan Six hours. That’s the incident notification window under the UAE’s Information Assurance Standard v2. Once a breach is detected, the framework requires incident notifications within 6 hours of detection, alongside quarterly compliance updates and annual […]

AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirement Read More »

Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works

Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works 2026-09-03 at 11:21 By Ashish Khaitan Supply chain attacks in 2026 are no longer an edge-case risk buried in a vendor questionnaire — they are a primary breach vector that regulators, incident responders, and CISOs now treat as a

Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works Read More »

Your threat feed is someone else’s database: What ingesting malware intel at scale takes

Your threat feed is someone else’s database: What ingesting malware intel at scale takes 2026-09-03 at 08:30 By Help Net Security The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is

Your threat feed is someone else’s database: What ingesting malware intel at scale takes Read More »

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers 2026-09-01 at 08:30 By Mirko Zorz Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup,

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers Read More »

Surveillance – Everything You Wanted to Know, But Were Afraid to Ask

Surveillance – Everything You Wanted to Know, But Were Afraid to Ask 2026-08-20 at 17:30 By Kevin Townsend We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it. The post Surveillance – Everything You Wanted to Know, But Were Afraid to Ask appeared first

Surveillance – Everything You Wanted to Know, But Were Afraid to Ask Read More »

Release the RAVEN: Destruction and Discipline

Release the RAVEN: Destruction and Discipline 2026-08-18 at 19:53 By Karl Biron In Part 4, we stole every document from every index, planted a rogue superuser account, created credential-independent API keys, and planted three persistence mechanisms that survive password rotations. Everything was logged. Now we answer two final questions: how much worse could it get,

Release the RAVEN: Destruction and Discipline Read More »

Release the RAVEN: Kibana Under Siege

Release the RAVEN: Kibana Under Siege 2026-08-13 at 16:36 By Karl Biron In Parts 1 and 2, every command targeted port 9200. Every exploit, every reconnaissance query, every credential test hit the Elasticsearch REST API directly. But Elasticsearch rarely operates alone. Sitting alongside it on most deployments is Kibana, the visualization and management interface, quietly

Release the RAVEN: Kibana Under Siege Read More »

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months 2026-08-12 at 16:51 By Mirko Zorz Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months Read More »

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain 2026-08-10 at 16:55 By Rodel Mendrez This post is the result of an investigation into a case we worked on, in which we traced a loader chain that ended where we didn’t expect. This article is an excerpt from LevelBlue SpiderLabs Blog View Original

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain Read More »

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors 2026-08-07 at 13:58 By Mihir Bagwe Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs (CRIL), the region

Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors Read More »

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action 2026-08-06 at 17:00 By Kenneth Ng When people hear the word cybersecurity, they often picture analysts racing to stop an attack in real time. Those roles are absolutely critical, but a lot of effective security happens long before an alert ever appears.  This

Day in the Life of a Cybersecurity Director: Turning Intelligence into Action Read More »

What stops attackers wrecking industrial plants is knowing how

What stops attackers wrecking industrial plants is knowing how 2026-08-05 at 07:30 By Mirko Zorz Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The

What stops attackers wrecking industrial plants is knowing how Read More »

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes 2026-07-29 at 22:22 By Karl Biron You have almost certainly interacted with Elasticsearch today. The search bar on your company’s internal wiki. The autocomplete on the e-commerce site where you ordered lunch. The log aggregation dashboard your SOC team stares at for eight

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes Read More »

Google changes how it names cyber threat actors

Google changes how it names cyber threat actors 2026-07-27 at 16:08 By Sinisa Markovic Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes

Google changes how it names cyber threat actors Read More »

APTs Top the List of Most Active Threat Actors in H1 2026

APTs Top the List of Most Active Threat Actors in H1 2026 2026-07-27 at 15:38 By Ashish Khaitan You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof?  We do.  Cyble Research and Intelligence Labs (CRIL) closed out its tracking for the first half of 2026 with a deep analysis

APTs Top the List of Most Active Threat Actors in H1 2026 Read More »

Still Circling: Blind Eagle’s Toolkit Keeps Evolving

Still Circling: Blind Eagle’s Toolkit Keeps Evolving 2026-07-17 at 16:57 By Serhii Melnyk In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, in which we assessed with high confidence that Blind Eagle (also tracked as APT-C-36, APT-Q-98, TAG-144, AguilaCiega), a threat actor focused on Latin America, had moved part of its VBScript delivery

Still Circling: Blind Eagle’s Toolkit Keeps Evolving Read More »

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites 2026-07-16 at 16:43 By Rodel Mendrez You’re browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: “Verify you are human.” It asks you to open Terminal, paste a code, and press Enter. You’ve seen this before. You follow the steps.

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites Read More »

Scroll to Top