Our Director of #ThreatIntel was also at #DomainPulse today with a deeper dive into the threats faced by Switzerland, in particular.
Our Director of #ThreatIntel was also at #DomainPulse today with a deeper dive into the threats faced by Switzerland, in particular.
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
RE: https://infosec.exchange/@greynoise/116002702711084624
My latest pet project, an RSS feed to alert you to the silent KEV knownRansomwareCampaignUse flips!
(Did you know there were four CVEs flipped last week?) #threatintel
In 2025, 59 CVEs quietly flipped to “known ransomware use” in CISA’s KEV...no alerts, no fanfare. 🧐
We dug through a year of JSON to catch every silent flip and built an RSS feed so you don’t miss the next one.
Read the blog + grab the feed 🗞️
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
RE: https://infosec.exchange/@greynoise/116002702711084624
My latest pet project, an RSS feed to alert you to the silent KEV knownRansomwareCampaignUse flips!
(Did you know there were four CVEs flipped last week?) #threatintel
In 2025, 59 CVEs quietly flipped to “known ransomware use” in CISA’s KEV...no alerts, no fanfare. 🧐
We dug through a year of JSON to catch every silent flip and built an RSS feed so you don’t miss the next one.
Read the blog + grab the feed 🗞️
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
One of our AI threat team pointed me at this:
https://zenodo.org/records/18444900
Interesting analysis of Moltshite.
One of our AI threat team pointed me at this:
https://zenodo.org/records/18444900
Interesting analysis of Moltshite.
CISA's KEV hit 1,500 yesterday. I'm working on a cool #threatintel blog (yes, I'm biased) about additional hidden intel in KEV that should be published soon, along with a helpful tool hosted by GreyNoise! :)
I put together a hands-on guide to deploying an OpenCTI OSINT stack for cybersecurity research — focused on why you’d architect it certain ways, not just copy-paste YAML.
If you’re a student, homelabber, or security practitioner who wants real CTI experience instead of theory, this one’s for you.
https://blog.jmhill.me/deploying-an-opencti-osint-stack-for-cybersecurity-research/
#CyberSecurity #OSINT #ThreatIntel #OpenCTI #Homelab #BlueTeam #SOC #Infosec #SelfHosted
I put together a hands-on guide to deploying an OpenCTI OSINT stack for cybersecurity research — focused on why you’d architect it certain ways, not just copy-paste YAML.
If you’re a student, homelabber, or security practitioner who wants real CTI experience instead of theory, this one’s for you.
https://blog.jmhill.me/deploying-an-opencti-osint-stack-for-cybersecurity-research/
#CyberSecurity #OSINT #ThreatIntel #OpenCTI #Homelab #BlueTeam #SOC #Infosec #SelfHosted
Snagged what looks like attempted phish/CSRF
Portrayed itself as a secure banking message. Initial hyperlink directed to
petroleuminvestigations[.]com
Looks like a VPS with openresty doing some lua-based filtering. Then user's kicked to an AWS address impersonating finance documents, and cookies are pulled in from bin.dreatrithoo[.]online common across finance scam sites today per LookyLoo.
34 more domains associated by MX IP address. CSV for all 36:
ThreatLandscape.ai is live Natural language AI copilot for threat intelligence that answers security questions with continuously updated intel, so teams get insights fast without hunting data manually.
Oh well that's fucking clever. A threat actor is sending out phishing emails pretending to be SendGrid, and explaining that all their emails will include "Support ICE" banners in order to trigger ragebait clicks through to the phishing kit.
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
Back in the saddle with my Cybersecurity Weekly Roundup for 2026.
This week’s signal: CISA moves (KEV + retired Emergency Directives), critical patching for Veeam/Trend Micro/n8n/Cisco ISE, legacy edge gear still getting farmed, “internal-looking” phishing tricks, and malicious browser extensions stealing AI chats.
15 stories, quick briefs, and my practitioner take:
https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-january-2-9-2026/
#Cybersecurity #InfoSec #VulnManagement #ThreatIntel #Ransomware #BlueTeam #CybersecurityWeeklyRoundup #CybersecKyle
More Subjects to search on for that Sendgrid thing mentioned by Ian here.
https://masto.deoan.org/@neurovagrant/115865145438282370
API Authentication Issue
API Endpoint Communication Failed
API Endpoint Disabled
API Endpoint Failure
API Endpoint Issue
API Endpoint Issue
API Error Detected
API Request Failures Detected
API Request Status Update
Action required by January 13
Holiday Email Volume
ICE Support Initiative
Issue with Your API Request
JSON Payload Error
Language Preference Updated
Malformed JSON Payload
Migration to Sinch Authentication
New Pride Template
Pride Month Theme Update
We Couldn't Process Your Request
Your API endpoint has been rate limited
Your request couldn't be completed
More Subjects to search on for that Sendgrid thing mentioned by Ian here.
https://masto.deoan.org/@neurovagrant/115865145438282370
API Authentication Issue
API Endpoint Communication Failed
API Endpoint Disabled
API Endpoint Failure
API Endpoint Issue
API Endpoint Issue
API Error Detected
API Request Failures Detected
API Request Status Update
Action required by January 13
Holiday Email Volume
ICE Support Initiative
Issue with Your API Request
JSON Payload Error
Language Preference Updated
Malformed JSON Payload
Migration to Sinch Authentication
New Pride Template
Pride Month Theme Update
We Couldn't Process Your Request
Your API endpoint has been rate limited
Your request couldn't be completed