Threat Intelligence

The simple shift that turns threat intel from noise into real insight

The simple shift that turns threat intel from noise into real insight 2025-12-09 at 08:02 By Help Net Security In this Help Net Security video, Alankrit Chona, CTO at Simbian, explains how security teams can put threat intelligence to work in a way that supports detection, response, and hunting. Chona walks through why many teams […]

The simple shift that turns threat intel from noise into real insight Read More »

In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor

In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor 2025-12-05 at 17:57 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Akamai patches HTTP smuggling vulnerability, Claude Skills used to execute ransomware, PickleScan flaws. The post In Other News: X Fined €120 Million, Array Flaw Exploited, New

In Other News: X Fined €120 Million, Array Flaw Exploited, New Iranian Backdoor Read More »

Threat intelligence programs are broken, here is how to fix them

Threat intelligence programs are broken, here is how to fix them 2025-12-03 at 07:12 By Anamarija Pogorelec Security teams often gather large amounts of threat data but still struggle to improve detection or response. Analysts work through long lists of alerts, leaders get unclear insights, and executives see costs that do not lead to better

Threat intelligence programs are broken, here is how to fix them Read More »

Fragmented tooling slows vulnerability management

Fragmented tooling slows vulnerability management 2025-11-28 at 07:32 By Anamarija Pogorelec Security leaders know vulnerability backlogs are rising, but new data shows how quickly the gap between exposures and available resources is widening, according to a new report by Hackuity. Fragmented detection and slow remediation Organizations use a formalized approach to manage vulnerabilities, but their

Fragmented tooling slows vulnerability management Read More »

Russian Hackers Target US Engineering Firm Because of Work Done for Ukrainian Sister City

Russian Hackers Target US Engineering Firm Because of Work Done for Ukrainian Sister City 2025-11-26 at 02:33 By Associated Press The attack on the engineering firm was identified by Arctic Wolf in September before it could disrupt the engineering company’s operations or spread further. The post Russian Hackers Target US Engineering Firm Because of Work

Russian Hackers Target US Engineering Firm Because of Work Done for Ukrainian Sister City Read More »

MI5 Warns Lawmakers That Chinese Spies Are Trying to Reach Them via LinkedIn

MI5 Warns Lawmakers That Chinese Spies Are Trying to Reach Them via LinkedIn 2025-11-18 at 18:36 By Associated Press Britain’s domestic intelligence agency warned that Chinese nationals were ”using LinkedIn profiles to conduct outreach at scale” on behalf of the Chinese Ministry of State Security. The post MI5 Warns Lawmakers That Chinese Spies Are Trying

MI5 Warns Lawmakers That Chinese Spies Are Trying to Reach Them via LinkedIn Read More »

Microsoft Issues Emergency Patch for Windows Server Update Services RCE Vulnerability CVE-2025-59287

Microsoft Issues Emergency Patch for Windows Server Update Services RCE Vulnerability CVE-2025-59287 2025-11-14 at 15:10 By Fernando Martinez LevelBlue Labs is tracking a severe vulnerability in Windows Server Update Services (WSUS), CVE-2025-59287, that allows attackers to remotely execute code without authentication and is being exploited by threat actors to compromise vulnerable Windows Server users. This

Microsoft Issues Emergency Patch for Windows Server Update Services RCE Vulnerability CVE-2025-59287 Read More »

Google adds Emerging Threats Center to speed detection and response

Google adds Emerging Threats Center to speed detection and response 2025-11-12 at 19:02 By Sinisa Markovic When a new vulnerability hits the news, security teams often scramble to find out if they are at risk. The process of answering that question can take days or weeks, involving manual research, rule-writing, and testing. Google Security Operations

Google adds Emerging Threats Center to speed detection and response Read More »

How TTP-based Defenses Outperform Traditional IoC Hunting

How TTP-based Defenses Outperform Traditional IoC Hunting 2025-11-12 at 18:16 By Etay Maor Behavioral detection allows defenders to recognize activity patterns like privilege escalation, credential theft, and lateral movement—often ahead of encryption or data exfiltration. The post How TTP-based Defenses Outperform Traditional IoC Hunting appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

How TTP-based Defenses Outperform Traditional IoC Hunting Read More »

LevelBlue Futures Report: Retail Leaders Reveal Security Concerns

LevelBlue Futures Report: Retail Leaders Reveal Security Concerns 2025-11-12 at 16:09 By The future of retail cybersecurity: Explore insights from 220 retail executives on managing AI-driven threats and closing the cyber resilience gap. 44% of retail organizations report a sharp increase in cyberattacks, underscoring the urgent need for stronger cybersecurity defenses across the sector. 34%

LevelBlue Futures Report: Retail Leaders Reveal Security Concerns Read More »

Dissecting and Understanding APT Threat Group Activity

Dissecting and Understanding APT Threat Group Activity 2025-11-06 at 16:45 By Trustwave SpiderLabs CTI APT Groups Prioritize Espionage and Data Theft: Approximately two-thirds of all Trustwave SpiderLabs-tracked APT group activity is motivated by espionage, targeting government, defense, and telecom sectors primarily in the US, Ukraine, and Russia. Top Attacker Nations: China (41%), Iran (12.5%), and

Dissecting and Understanding APT Threat Group Activity Read More »

Google uncovers malware using LLMs to operate and evade detection

Google uncovers malware using LLMs to operate and evade detection 2025-11-05 at 20:53 By Zeljka Zorz PromptLock, the AI-powered proof-of-concept ransomware developed by researchers at NYU Tandon and initially mistaken for an active threat by ESET, is no longer an isolated example: Google’s latest report shows attackers are now creating and deploying other malware that

Google uncovers malware using LLMs to operate and evade detection Read More »

Google introduces agentic threat intelligence for faster, conversational threat analysis

Google introduces agentic threat intelligence for faster, conversational threat analysis 2025-10-21 at 19:00 By Mirko Zorz Security teams spend much of their day pulling data from reports, forums, and feeds, trying to connect clues across multiple sources. Google says that work can now happen through a simple conversation. A new way to interact with threat

Google introduces agentic threat intelligence for faster, conversational threat analysis Read More »

Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US

Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US 2025-10-17 at 20:17 By Associated Press The U.S. is the top target for cyberattacks, with criminals and foreign adversaries targeting companies, governments and organizations. The post Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US appeared first on SecurityWeek. This

Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US Read More »

Maltrail: Open-source malicious traffic detection system

Maltrail: Open-source malicious traffic detection system 2025-10-15 at 08:30 By Sinisa Markovic Maltrail is an open-source network traffic detection system designed to spot malicious or suspicious activity. It works by checking traffic against publicly available blacklists, as well as static lists compiled from antivirus reports and user-defined sources. These “trails” can include domain names, URLs,

Maltrail: Open-source malicious traffic detection system Read More »

Notepad++ DLL Hijacking (CVE-2025-56383): CVSS 8.4 or CVSS 0.0?

Notepad++ DLL Hijacking (CVE-2025-56383): CVSS 8.4 or CVSS 0.0? 2025-10-04 at 01:35 By A vulnerability on a popular source-code editor has been recently released along with a proof-of-concept (POC) exploit, but the security community isn’t so sure that it’s a legitimate flaw. This article is an excerpt from SpiderLabs Blog View Original Source

Notepad++ DLL Hijacking (CVE-2025-56383): CVSS 8.4 or CVSS 0.0? Read More »

From Folding to Folded: Hacking High Volume Mailer Machines

From Folding to Folded: Hacking High Volume Mailer Machines 2025-09-30 at 16:00 By John Jackson The Quadient DS-700iQ is a high-volume folder-inserter machine designed for automating the process of assembling, folding, and inserting mail into envelopes for large mailing operations. It features a modular design that can handle complex mailing jobs, supports multiple feeders and

From Folding to Folded: Hacking High Volume Mailer Machines Read More »

Unit 221B Raises $5 Million for Threat Intel Aiding Hacker Arrests 

Unit 221B Raises $5 Million for Threat Intel Aiding Hacker Arrests  2025-09-23 at 16:05 By Ionut Arghire The company will expand its platform’s capabilities and accelerate investigative collaboration and go-to-market efforts. The post Unit 221B Raises $5 Million for Threat Intel Aiding Hacker Arrests  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Unit 221B Raises $5 Million for Threat Intel Aiding Hacker Arrests  Read More »

Silent Push Raises $10 Million for Threat Intelligence Platform

Silent Push Raises $10 Million for Threat Intelligence Platform 2025-09-15 at 17:53 By Eduard Kovacs Silent Push, which provides Indicators of Future Attack, has raised a total of $32 million in funding. The post Silent Push Raises $10 Million for Threat Intelligence Platform appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Silent Push Raises $10 Million for Threat Intelligence Platform Read More »

Static feeds leave intelligence teams reacting to irrelevant or late data

Static feeds leave intelligence teams reacting to irrelevant or late data 2025-09-15 at 07:12 By Anamarija Pogorelec Boards and executives are not asking for another feed of indicators. They want to know whether their organization is being targeted, how exposed they are, and what steps need to be taken. A new report from Flashpoint argues

Static feeds leave intelligence teams reacting to irrelevant or late data Read More »

Scroll to Top