8 min read
Cyber Threat Intelligence Report
This week, we briefed our clients on a new ClickFix variant, TerminalFix, that establishes a Websocket tunnel to the threat actor's C2 domain.
Read MoreRead our latest threat intelligence, produced by our team of battle-hardened analysts and experts.
8 min read
This week, we briefed our clients on a new ClickFix variant, TerminalFix, that establishes a Websocket tunnel to the threat actor's C2 domain.
Read More
8 min read
This week, we briefed our clients on CISA's recently published TTP updates for the Medusa RaaS group, originally published in March 2025.
9 min read
This week, we briefed our clients on recent data extortion campaigns targeting numerous industry verticals with fake technical support vishing calls.
6 min read
This week, we briefed our clients on "Certighost", a Domain Controller Impersonation Exploit that allows standard users to obtain valid DC certificates.
7 min read
This week, we briefed our clients on details of the Progress ShareFile shutdown on Friday, July 10th, and other vulnerabilities from the past two weeks.
6 min read
This week, we briefed our clients on details of the widespread FortiBleed credential compromise and the breach that exposed data from the LastPass CRM.
8 min read
This week, we briefed our clients on the new Ghost-sender Email Spoofing research from InfoGuard Labs. Be sure to test your domain for the vulnerability.
7 min read
This week, we briefed our clients on new social engineering attacks targeting law firms. The Silent Ransomware Group has been showing up in person.
7 min read
This week, we briefed our clients on the recent increase in Device Code Phishing attacks and how to protect themselves, starting with Microsoft 365.
6 min read
This week, we briefed our clients on the second-most-active Ransomware-as-a-Service organization, The Gentleman. We describe their observed TTPs.