Tag: Threat Hunting

0 14
Posted in Threat Intelligence

Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)

54,763 unique indicators across 107 tracked clusters this cycle. Dominant signal: framework-C2 infrastructure surge with 25+ concentrated /24 subnet anchors. Emerging supply-chain wave — fake npm packages, fake installers, developer-ecosystem targeting. macOS malware surge across three concurrent families. Three ransomware operators active. Iranian-linked APT clusters continue. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per type.

Weekly Threat Advisory cover for May 18-24 2026
0 73
Posted in Threat Intelligence

Weekly Threat Advisory: Top Cyber Adversaries May 18 – 24, 2026

Weekly Threat Advisory | Supply Chain | INJ3CTOR3 | BadIIS | AMOS | Anatsa | SD-WAN CVE-2026-20182

Weekly Threat Advisory: Top Cyber Adversaries May 11 - 17, 2026 — HACKFORLAB cover image
0 98
Posted in Threat Intelligence

Weekly Threat Advisory: Top Cyber Adversaries May 11 – 17, 2026

Weekly Threat Advisory | DPRK | The Gentlemen Ransomware | FrostyNeighbor | FamousSparrow | CVE-2026-41940 | EtherRAT

Living-off-the-Cloud Attack Chain Detection — CloudTrail and VPC Flow fusion for malware-free intrusions
0 82
Posted in Cyber Threat

Living-off-the-Cloud Attack-Chain Detection: CloudTrail and VPC Flow Fusion

Living off the cloud | LotC | CloudTrail | VPC Flow | fusion | malware-free

Insider Threat UEBA from VPC Flow Logs — Network-only user behaviour analytics without endpoint telemetry
0 69
Posted in Cyber Threat

Insider Threat Detection from VPC Flow Logs (UEBA Without Endpoints)

Insider threat | UEBA | identity | peer baseline | VPC Flow Logs | behavioral