Flying Eagle Android RAT traced across 170 servers
Researchers found Flying Eagle Android RAT infrastructure fingerprints on 170 servers. We analyse scope, capabilities, detection and response.
Current campaigns, ransomware, malware, breaches and incidents with impact assessment, detection signals and practical response actions.
Researchers found Flying Eagle Android RAT infrastructure fingerprints on 170 servers. We analyse scope, capabilities, detection and response.
A real LinkedIn recruitment incident led to a DMG, LaunchAgent and in-memory JXA. We explain the chain, impact, detection and response.
A coordinated cyberattack reached technology at more than 30 Minnesota water systems. We separate confirmed impact from speculation and outline OT/SCADA priorities.
Kaspersky uncovered new Mirage Kitten tools: the NightLedger backdoor and ArcBridge and BridgeHead tunnelers. We analyse the techniques and detection.
Sysdig documented JadePuffer — the first ransomware attack carried out end to end by an LLM agent. We analyse the chain and what defenders should do.
Spirals ransomware encrypted an IT firm's network in under 24 hours. We break down the attack timeline and show where it could have been stopped.
A 0-day in Oracle PeopleSoft (CVE-2026-35273) hit 100+ organisations including NAIC. Analysis, and a lesson in reading extortion groups' claims.
The Anubis attack on Coca-Cola's Fairlife halted US production, and entry came through a third party. An analysis of an OT incident and SEC disclosure.
Dolphin X steals data from over 300 applications and advertises AI victim profiling. We separate the confirmed analysis from the criminals' marketing.
Group-IB detailed a China-nexus operation, JadeProx, and the TriBack loader, exposed via a misconfigured cloud server. Targets, techniques and defensive lessons.
Cisco Talos detailed msaRAT — a Chaos-group trojan that runs C2 through Chrome/Edge and WebRTC to evade network detection. We explain the mechanism and defence.
A joint government advisory detailed a campaign abusing an XSS in Zimbra (CVE-2025-66376) to steal mail, passwords and 2FA codes. Who it hits and what to do.
Build essential SOC analyst skills in triage, logs, SIEM, networking, detection, incident response, communication, and portfolio evidence.
HOLLOWGRAPH uses Microsoft Graph, 2050 calendar events and DNS tunneling for C2 and exfiltration. Review confirmed TTPs, IOCs and detection.
GigaWiper combines remote access, espionage and three data-destruction paths. Review confirmed IOCs, detection logic and a Windows recovery plan.
Authorities warn that Russian actors are exploiting poorly secured routers. Review the observed risk, hardening priorities and an evidence-led edge-device checklist.
Operation Endgame targeted 326 servers and 142 domains linked to SocGholish, Amadey and StealC. What the action achieved and defenders should do.
Run a tabletop exercise that exposes response gaps without disrupting production. Design scenarios, injects, decisions and corrective actions.
Compare SIEM, XDR and EDR across telemetry, detection, retention, response and cost, then design an architecture without duplicate alerts and data.
Cyber threat intelligence turns threat data into decisions. Build requirements, sources, analysis, distribution and metrics for an effective CTI loop.
A SQL injection reached guest data held for thousands of Polish hotels. Learn what reportedly leaked, why authenticated access is no defence and how guests, hotels and SaaS providers should respond.
Purple teaming turns adversary techniques into measurable detection tests. Scope exercises safely, improve controls and prove the gaps are closed.
Black Kite reports disclosed ransomware in Europe rose 55% in 2026, with manufacturing the top target. What it means for companies across the EU.
Improvising during an incident costs the most. We show NIST's six phases of response, ready-made playbooks, and what to prepare before the phone rings.
You don't need a million-dollar SOC to detect attacks. How a mid-sized company builds monitoring: what to log, what to alert on, when to get help.
A ransomware attack on Conduent exposed data on 62M+ people. What it says about third-party risk and what to do when a processor holds your data.
Infostealers are the most common malware stealing passwords, cookies and wallets. How they infect, why they bypass MFA and how to protect yourself.
Ransomware attacks rarely start with encryption. We break the attack chain into its parts and show where it's cheapest to break it.
A backup nobody has tested is just an assumption. The 3-2-1 rule, immutable copies that survive ransomware and restores that actually work.
Your passwords and data are almost certainly in some breach. How to check it safely, what a leak really means and what steps to take.
What to do when a data breach happens — from confirming the incident, through limiting the impact, to GDPR obligations.
Engineer reliable Sigma rules for SIEM: hypotheses, logsource contracts, correlation, filters, backend tests, tuning, metrics and purple-team validation.
Detect DNS tunneling and C2 beaconing through label entropy, query length, NXDOMAIN ratios, record types, timing and endpoint-to-resolver correlation.
In spring 2026 several Polish hospitals were hit by ransomware in quick succession. Why healthcare is a target and how to limit the impact.
Polish cybercrime police identified seven minors who allegedly sold DDoS tools. We explain booter infrastructure, evidence and resilient service design.
Technical Coruna exploit-kit analysis: WebKit RCE, PAC/PPL bypasses, ChaCha20 blobs, PlasmaLoader, seed-phrase theft, Lockdown Mode and hunting.
Polish cybercrime police detained a 47-year-old suspected of handling tools and access data and communicating with Phobos. A technical RaaS ecosystem analysis.
Polish cybercrime police detained a water utility breach suspect. We analyse the technical account, darknet publication and critical-infrastructure controls.
A destructive attack on Poland's energy sector and pro-Russian DDoS show critical infrastructure is a target — what it means for companies.
Microsoft and law enforcement disrupted RedVDS. We analyse 7,300 IPs, homoglyph domains, a shared Windows image and behaviour-based cybercrime detection.
2025 was a record year for Poland: attacks on hospitals, DDoS on infrastructure and disinformation. We summarise the threats and lessons for businesses.
In 2025 Scattered Spider paralysed UK retail. The weapon wasn't a 0-day but a helpdesk call. We break down the technique and the defence.
In February 2025, $1.5bn in crypto vanished from Bybit. We break down the Lazarus attack and what failed despite a cold wallet.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.