8 min read
Cyber Threat Intelligence Report
This week, we briefed our clients on a new ClickFix variant, TerminalFix, that establishes a Websocket tunnel to the threat actor's C2 domain.
On October 3, Daniel Stenberg (@badger) announced a forthcoming patch for cURL (version 8.4.0) that will be released on October 11, which includes a fix for a still unknown "high severity CVE".
Due to the widespread usage of curl, this vulnerability has the potential to be a major security risk.
Organizations are strongly encouraged to begin identifying where curl is used within their environment so that patches can be applied in a timely manner once they are released.
PacketWatch's Andrew Oesterheld has created several queries that can be used across various platforms to help identify where cURL is used.

You can download a copy of the .pdf file by filling out the form below:
8 min read
This week, we briefed our clients on a new ClickFix variant, TerminalFix, that establishes a Websocket tunnel to the threat actor's C2 domain.
8 min read
This week, we briefed our clients on CISA's recently published TTP updates for the Medusa RaaS group, originally published in March 2025.
9 min read
This week, we briefed our clients on recent data extortion campaigns targeting numerous industry verticals with fake technical support vishing...