Weekly Threat Advisory: APT Surge, Ransomware Full-Pivot, Messaging Weaponised — June 22-28, 2026
54,820 indicator observations across 87 adversary clusters this week. Four state-aligned APTs active in parallel (Gamaredon, Turla, MustangPanda, CL-STA-1062 + Silent Lynx + APT-C-35 + APT38). A ransomware operator rotated a full multi-pivot kill chain in 7 days (DragonForce). Direct-messaging platforms weaponised as initial-access surface (WhatsApp VBScript Campaign, 61 IOCs, tight 202.61.160.0/24 subnet anchor). Five concurrent supply-chain campaigns against the developer ecosystem (GhostShell, Miasma, Malicious npm Package, Operation FlutterBridge, Chrome ad-blocker extension cluster). A new RAT family arrived (ModeloRAT, 39 IOCs, full footprint). Full MITRE ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.
Indicators of Compromise and Threat Intelligence: A Practitioner Reference
A working analyst reference. 20 sections covering the Pyramid of Pain, the atomic / computed / behavioural indicator taxonomy, the four IOC domains with field-level detail, pivoting tradecraft (passive DNS, WHOIS, JA3/JA4/JARM, TLS SAN, ASN), the standards (STIX 2.1, TAXII 2.1, OpenIOC, MISP), detection content (Sigma + YARA), IOC vs IOA vs TTP, the four TI tiers with producer-consumer contracts, the six-phase lifecycle with F3EAD overlay, intelligence requirements (PIR/SIR/KIT/KIQ), the Diamond Model of Intrusion Analysis, the Cyber Kill Chain mapped to MITRE ATT&CK, the Admiralty source reliability code, Traffic Light Protocol 2.0, the Hunting Maturity Model, detection-engineering pipelines, SOAR integration patterns, KPIs (MTTD / MTTR / dwell time / coverage / hit rate), and the practitioner reference stack. Vendor-neutral. Twelve practitioner FAQs.
Weekly Threat Advisory: Cluster Analysis & Top IOCs, June 15 – 21, 2026
55,480 indicator observations across 89 adversary clusters this week. A ransomware operator rotated a full multi-pivot kill chain (Rhysida-Interlock, 219 indicators across 4 IOC types). Developer supply chain became this week’s preferred attack surface (15 typosquat code-editor plugins + 8 browser extensions + 6 marketing-CDN typosquats). AI platforms began appearing as adversary infrastructure (19 chat-share redirector domains + 39-indicator AI-generated lure campaign). Full MITRE ATT&CK mapping per cluster, subnet-clustering signals, top 15 IOCs per indicator type, and 4 production-ready Sigma rules.
The Complete AWS Threat Hunting Library: 27 Cloud Hunts, 7 Flagship Playbooks, and the Full Archive (2026)
The definitive AWS threat hunting reference — indexing all 27 published AWS hunting posts on hackforlab.com. 7 flagship 2026 hunts (CloudTrail blind spots, KMS ransomware, GuardDuty evasion, CI/CD compromise, native messaging C2, Athena data lake exfiltration, multi-account federation), plus 19 archive posts covering AWS identity attacks, Bedrock CloudTrail playbook, VPC Flow Log analytics, cloud malware case studies, and the foundational AWS attack-chain detection content.
AWS Organizations Compromise: Hunting the Multi-Account Federation Attack
AWS Organizations centralises governance — and that centralisation creates a high-value attack target. This article covers the four most-exploited multi-account compromise patterns, the cross-account telemetry stitching required to detect them, and the response strategies for organisation-level incident response.









