
Weekly Intelligence Snapshot – Week 35, 2023
Mandiant describes how Chinese-nexus Threat Group UNC4841 maintains a presence in victims’ environments.
Explore our comprehensive archive organized by taxonomy. Discover a wealth of information categorized by subject, theme, or type to enhance your research and understanding.

Mandiant describes how Chinese-nexus Threat Group UNC4841 maintains a presence in victims’ environments.

Microsoft adds functionality to run Python in Excel for Windows – has security implications with Malicious Script execution.

After Storm-0558 obtained Microsoft MSA keys to access some US government accounts, we analyze the impact of the incident.

Microsoft released its monthly Patch Tuesday security update. Impacted products include Microsoft Windows, Outlook, Office.

New Malware Alert: WikiLoader Targets Italian Organizations plus the main points of the European Sustainability Reporting Standards (ESRS) adopted this

Mandiant has uncovered a supply chain compromise affecting US-based software solutions company JumpCloud. The intrusion — attributed to North Korean

QuoIntelligence analyzes the key points of the US’s National Cybersecurity Strategy Implementation Plan recently released by the Biden administration.

Researchers from Microsoft discovered a phishing campaign by the eCrime actor Storm-0978/RomCom targeting defense and government entities in Europe and

Major Spanish banks among specific targets for Neo_Net. We are tracking this Threat Actor on Telegram.

SentinelOne, Bitdefender & Elastic have reported on the emerging threat actor JokerSpy that targets enterprise MacOS devices with multistage spyware.
Try searching our blog

Iran-Linked MuddyWater Targets Nine Organizations Globally in Espionage Campaign | Middle East Conflict Update: Kinetic Attacks, Maritime Incidents, and Diplomatic Deadlock

Suspected Chinese APT Salt Typhoon Targets Italian IT Service Provider | US Treasury Warns Shippers Not To Pay Hormuz Tolls, Even In Form of Charity

TeamPCP Deploys Self-Replicating npm Worm Across Multiple Software Supply Chain Vectors | China Bans Dual-Use Item Exports To Seven European Entities Over Taiwan Arms Sales

The Gentlemen Accelerates Ransomware Operations Through Scalable Affiliate Model | Russia Threatens European Drone Producers, Publishes Addresses Online