Threat Intelligence

Cyble Named a Challenger in the Inaugural 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies

Cyble Named a Challenger in the Inaugural 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies 2026-05-19 at 16:58 By Mihir Bagwe In a digital landscape that moves at the speed of AI, we feel recognition is more than just a market positioning—it is a validation of vision. We are proud to announce that Cyble has […]

Cyble Named a Challenger in the Inaugural 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies Read More »

Cyble Named a Challenger in the Inaugural 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies

Cyble Named a Challenger in the Inaugural 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies 2026-05-19 at 12:47 By Mihir Bagwe In a digital landscape that moves at the speed of AI, we feel recognition is more than just a market positioning—it is a validation of vision. We are proud to announce that Cyble has

Cyble Named a Challenger in the Inaugural 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies Read More »

Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026

Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026 2026-05-14 at 12:48 By Ashish Khaitan In 2026, opportunistic assaults and isolated breaches will no longer characterize Australia’s cyber risk environment. Industrialized data theft, in which stolen data is packaged, repackaged, and marketed on

Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026 Read More »

Threat Analysis: Backdoored Electron Apps Evading Defenses

Threat Analysis: Backdoored Electron Apps Evading Defenses 2026-05-08 at 18:03 By Michael Morose This Threat Analysis report is part of the “Purple Team Series” in which the LevelBlue Global Security Operations Center (GSOC) provides a technical overview of some of the methods that threat actors are using to compromise their victims. This article is an

Threat Analysis: Backdoored Electron Apps Evading Defenses Read More »

Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication

Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication 2026-05-07 at 17:34 By Mahadev Joshi LevelBlue’s Security Services issues Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them. This article is an excerpt from LevelBlue SpiderLabs Blog View

Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication Read More »

AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours

AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours 2026-04-30 at 22:46 By Kevin Townsend Industrialized cybercrime delivers attacks with greater scale, speed and success. Defenders must match this with use of AI and automation. The post AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours appeared first on SecurityWeek. This article is an excerpt

AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours Read More »

How Cyble Blaze AI Turns Billions of Threat Signals into Actionable Intelligence

How Cyble Blaze AI Turns Billions of Threat Signals into Actionable Intelligence 2026-04-29 at 16:13 By Ashish Khaitan Modern cyberattacks no longer follow predictable patterns or slow timelines. They unfold at machine speed, often moving from initial access to data exfiltration in minutes. In this environment, security teams face a paradox: they are surrounded by vast amounts

How Cyble Blaze AI Turns Billions of Threat Signals into Actionable Intelligence Read More »

ANZ Organizations Are in the Ransomware Crosshairs— What the Dark Web Is Telling Us

ANZ Organizations Are in the Ransomware Crosshairs— What the Dark Web Is Telling Us 2026-04-28 at 14:02 By Ashish Khaitan The conversation around ANZ ransomware threats has shifted noticeably over the past year. What once looked like sporadic, high-profile incidents has evolved into a sustained and structured campaign against organizations across Australia and New Zealand. Signals emerging from underground forums

ANZ Organizations Are in the Ransomware Crosshairs— What the Dark Web Is Telling Us Read More »

Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems

Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems 2026-04-23 at 17:11 By Serhii Melnyk, King Orande, Cris Tomboc, Sean Shirley LevelBlue SpiderLabs’ Cyber Threat Intelligence Team continues to observe a progressive convergence between traditional cybercrime activity and attacks targeting cryptocurrency users. This article is an excerpt from LevelBlue SpiderLabs Blog View

Crypto Drainers as a Converging Threat: Insights into Emerging Hybrid Attack Ecosystems Read More »

Why AI Cybersecurity Is No Longer Optional for Australian Organizations: Moving from Reactive to Predictive Defense

Why AI Cybersecurity Is No Longer Optional for Australian Organizations: Moving from Reactive to Predictive Defense 2026-04-23 at 16:07 By Ashish Khaitan Cybersecurity is no longer a luxury or an afterthought for Australian organizations; it is a necessity. The scale and complexity of cyberattacks have reached unprecedented levels, and businesses, government bodies, and critical infrastructure

Why AI Cybersecurity Is No Longer Optional for Australian Organizations: Moving from Reactive to Predictive Defense Read More »

Why Indian Enterprises Are a Prime Target for Dark Web Credential Markets

Why Indian Enterprises Are a Prime Target for Dark Web Credential Markets 2026-04-22 at 13:48 By Ashish Khaitan The underground economy of stolen credentials has matured into a structured, high-volume marketplace, and Indian enterprises are at the center. What makes this trend notable is not just the scale of cyber incidents in India, but the

Why Indian Enterprises Are a Prime Target for Dark Web Credential Markets Read More »

Go With the Flow: Abusing OAuth Device Code Flow

Go With the Flow: Abusing OAuth Device Code Flow 2026-04-20 at 17:03 By Jakub Wiewiorski In early 2026, phishing attacks are still among the top contributors to the true positive detections in security operation centers (SOCs). Adversaries constantly come up with new ways of luring users into traps, concealing their actual intents and stacking anti-detection

Go With the Flow: Abusing OAuth Device Code Flow Read More »

Threat Landscape March 2026: Ransomware Dominance, Access Brokers, Data Leaks, and Critical Exploitation Trends

Threat Landscape March 2026: Ransomware Dominance, Access Brokers, Data Leaks, and Critical Exploitation Trends 2026-04-20 at 14:37 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) in its monthly threat landscape analysis observed a highly active threat environment throughout March 2026, shaped by large-scale ransomware campaigns, persistent data breach activity, growing initial access brokerage markets,

Threat Landscape March 2026: Ransomware Dominance, Access Brokers, Data Leaks, and Critical Exploitation Trends Read More »

How to spot a North Korean fake in a job interview

How to spot a North Korean fake in a job interview 2026-04-20 at 08:17 By Help Net Security North Korean operatives are getting hired at companies by passing job interviews using fake identities and AI tools. In this Help Net Security video, Adrian Cheek, a senior cybercrime researcher at Flare, outlines several ways organizations can

How to spot a North Korean fake in a job interview Read More »

Four Nationally Significant Cyberattacks Every Week — Is the UK Ready?

Four Nationally Significant Cyberattacks Every Week — Is the UK Ready? 2026-04-17 at 17:52 By Ashish Khaitan The tempo of UK cyberattacks has shifted from sporadic disruption to something far more systemic. When incidents reach a frequency of four national events each week, the issue stops being purely technical and becomes structural. It raises a more uncomfortable

Four Nationally Significant Cyberattacks Every Week — Is the UK Ready? Read More »

The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure

The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure 2026-04-16 at 15:04 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) in its weekly vulnerability report tracked 1,431 bugs last week. Of these, over 270 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating exploitation timelines and increasing real-world attack likelihood.

The Week in Vulnerabilities: Azure AI, Spring AI, Fortinet, and Critical ICS Exposure Read More »

How Cyble Blaze AI Delivers 360° Threat Visibility Across Dark Web and Enterprise Systems

How Cyble Blaze AI Delivers 360° Threat Visibility Across Dark Web and Enterprise Systems 2026-04-15 at 16:17 By Ashish Khaitan Modern cybersecurity no longer suffers from a lack of data; it suffers too much of it, scattered across systems that rarely speak the same language. Security teams today must monitor endpoints, cloud workloads, SaaS applications, and an ever-expanding universe

How Cyble Blaze AI Delivers 360° Threat Visibility Across Dark Web and Enterprise Systems Read More »

Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead

Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead 2026-04-13 at 17:31 By Jamie Mamroe One of the fastest growing initial access techniques we are seeing right now is Okta vishing: voice-based social engineering designed to compromise the identity provider rather than the inbox. This article is an excerpt from LevelBlue SpiderLabs Blog View

Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead Read More »

Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet

Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet 2026-04-11 at 02:20 By Sean Shirley Overview Recent reporting has identified a trojanized version of the CPUID HWMonitor installer being used to deliver a multi-stage, fileless malware chain leveraging trusted Windows binaries. Upon execution, the installer initiates a sequence involving PowerShell, MSBuild, and

Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet Read More »

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign 2026-04-09 at 16:17 By King Orande and Cris Tomboc TLP: AMBER+STRICT The LevelBlue SpiderLabs team examined the latest version of ErrTraffic, which emerged in early 2026. In a recently observed campaign, the team found that ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign Read More »

Scroll to Top