Threat Intelligence

On July 26 and 27, 2026, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water and wastewater utilities across Minnesota. Attackers disrupted automated control functions, forcing some plants to switch…

Simon White, Incident Response Team Lead
August 4, 2026 4 Min Read

OpenAI put two of its most advanced models inside a locked room to test how well they could hack. The models picked the lock, opened the doo...

Thrive
July 31, 2026 3 Min Read

On July 28, 2026, JFrog confirmed what the security industry had been speculating about for a week, the package-registry proxy that OpenAI&...

Simon White, Incident Response Team Lead
July 26, 2026 5 Min Read
Subscribe Via Email

Something we track in the Adversary Operations Group is residential proxy networks. Infoblox uncovered an operation they call Lurking Lizard, running since at least August 2022, that uses fake software installers to conscript devices as…

Simon White, Incident Response Analyst
July 20, 2026 2 Min Read

Someone pretending to be an Adidas recruiter sent me a meeting invitation last week. At least, that is what the email looked like. The branding was right.   The recruiter’s name was real. The company logo…

Simon White, Incident Response Analyst
July 18, 2026 2 Min Read

Microsoft released an emergency patch on July 9, 2026, for a Microsoft Defender zero-day vulnerability dubbed “RoguePlanet” (CVE-2026-50656) that allows attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11 devices (BleepingComputer,…

Simon White, Incident Response Analyst
July 16, 2026 < 1 Min Read

We track vulnerabilities in the Adversary Operations Group that have a clear exploitation path and no viable workaround. This pair on the S...

Simon White, Incident Response Analyst
July 15, 2026 2 Min Read

The European Union and the United Kingdom jointly sanctioned dozens of Russian intelligence officers and affiliated entities on 13 July 202...

Simon White, Incident Response Analyst
July 15, 2026 3 Min Read

A joint advisory from 19 allied cybersecurity agencies published on 13 July 2026 warns that Russian state hackers are systematically comprom...

Simon White, Incident Response Analyst
July 14, 2026 2 Min Read

We track caller ID spoofing platforms in the Adversary Operations Group. Russian Coms was one of the biggest. On July 13, 2026, the National Crime Agency charged five people across London for their roles in…

Simon White, Incident Response Analyst
July 13, 2026 2 Min Read

Insight into Cybersecurity Risks for Financial Services Financial services remains one of the most heavily targeted sectors in the threat landscape, and the pressure is accelerating rather than leveling off. Ransomware incidents against financial institutions climbed sharply…

July 13, 2026 < 1 Min Read