
Weekly Intelligence Snapshot – Week 35, 2023
Mandiant describes how Chinese-nexus Threat Group UNC4841 maintains a presence in victims’ environments.

Mandiant describes how Chinese-nexus Threat Group UNC4841 maintains a presence in victims’ environments.

Microsoft adds functionality to run Python in Excel for Windows – has security implications with Malicious Script execution.

Microsoft released its monthly Patch Tuesday security update. Impacted products include Microsoft Windows, Outlook, Office.

QuoIntelligence analyzes the key points of the US’s National Cybersecurity Strategy Implementation Plan recently released by the Biden administration.

Researchers from Microsoft discovered a phishing campaign by the eCrime actor Storm-0978/RomCom targeting defense and government entities in Europe and

Major Spanish banks among specific targets for Neo_Net. We are tracking this Threat Actor on Telegram.

SentinelOne, Bitdefender & Elastic have reported on the emerging threat actor JokerSpy that targets enterprise MacOS devices with multistage spyware.

Pro-Russia Hacktivist group Anonymous Sudan attacked Microsoft Azure, disrupting services for two hours.

The National Security Agency (NSA) and partner agencies have identified the infrastructure for Snake malware, a Russian cyberespionage tool, in

QuoIntelligence observed a new backdoor called “Durtmovoy” that is currently in development by “Durt Team”, a newly observed Russian threat
Try searching our blog

The Gentlemen Accelerates Ransomware Operations Through Scalable Affiliate Model | Russia Threatens European Drone Producers, Publishes Addresses Online

Famous Chollima Abused npm Dependency Chaining to Deliver OtterCookie and Install SSH Backdoors | Italian National Cybersecurity Agency Publishes Resolution on NIS2 Directive Compliance
Anthropic’s Mythos Preview can reportedly discover and exploit software vulnerabilities autonomously. But the claims remain unverified, and the real challenge is operational: accelerating patch cycles, automating incident response, and preparing for disclosure volumes that manual processes cannot absorb. We assess what organizations need to do now.

Iranian-Linked Threat Actors Target Programmable Logic Controllers Across US Critical Infrastructure | US-Iran Ceasefire Falters Within Hours as Lebanon Death Toll Mounts and Gulf Strikes Continue