Koi Security recently dove into the widely executed and highly coordinated GreedyBear crypto theft attack that used 150 weaponized Firefox extensions. According to the company, it utilized close to 500 malicious executables and dozens of phishing sites. The result? The threat actors have amassed more than US$1 million to date. more
WhoisXML API has halved the false positive rate of its malicious domain feed, enhancing detection precision. The update refines machine learning models, promising leaner cybersecurity operations and fewer interruptions from erroneous threat alerts. more
As AI agents gain delegated authority in enterprise systems, they introduce a new security frontier: ASM-AI. The real threat is no longer malicious code, but trusted bots making unsupervised, high-risk decisions. more
Cybercriminals are swapping standard image formats for SVG files to smuggle malware into systems. A detailed investigation uncovered a sprawling network of suspicious domains, IP addresses, and email-linked infrastructure used for espionage and cryptojacking. more
Despite falling IPv4 address prices throughout 2025, transaction volume and buyer activity remained strong. Expanding demand, growing liquidity, and healthy fundamentals suggest a stable, functioning market heading into 2026. more
An IoC deep dive into QakBot, newly ranked among 2026's top malware threats, reveals sprawling infrastructure, recycled domains, and fresh artifacts, underscoring how phishing-led access campaigns continue to endanger email-reliant enterprises worldwide. more
The IPv4 market continues to demonstrate healthy activity as August figures point to sustained transaction volume and steady pricing across most block sizes. Buyers and sellers alike remain engaged, with pricing dynamics showing signs of alignment across the spectrum. more
In 2025, IPv4 address prices declined to decade lows, but market activity remained strong. Rising buyer participation and steady transaction volume signaled a resilient, well-functioning market entering 2026 with confidence. more
After months of declining prices, the IPv4 market shows early signs of stabilisation, with firming prices, resilient global demand, and sustained transaction volume suggesting a gradual rebalancing rather than a structural downturn. more
Koi Security exposes the DNS infrastructure behind DarkSpectre's latest cyber campaign. Their investigation uncovers nearly 9,000 suspect domains and IP links, revealing how a stealthy browser extension compromised 2.2 million users. more
As generative AI accelerates deepfakes, counterfeit domains, and brand impersonation, legal teams are struggling to keep pace. Detection speed has become critical, forcing companies into an AI-driven arms race to protect intellectual property and corporate trust. more
The U.S. Department of Justice seized 114 domains connected to a major information-stealing campaign utilizing Lumma Stealer on 21 May 2025. The Cybersecurity and Infrastructure Security Agency (CISA) released the list of indicators of compromise (IoCs) on the same date. more
An analysis of 46 DNS indicators tied to seven of Q4 2025's most prevalent malware families reveals early warning signals, coordinated campaigns and hundreds of connected artifacts, underscoring the predictive power of proactive threat intelligence. more
Keenadu backdoor embedded in Android firmware exploits supply chains and OTA updates, while DNS analysis of its infrastructure reveals coordinated domains, IP links, and early warning signals pointing to premeditated, scalable cybercriminal operations globally distributed. more
State-sponsored and criminal groups exploited OAuth weaknesses using SquarePhish2 and Graphish to hijack Microsoft 365 accounts, prompting data theft and broader infiltration campaigns. Analysts uncovered 46 confirmed indicators and hundreds of related artifacts. more
Sponsored byVerisign
Sponsored byRadix
Sponsored byVerisign
Sponsored byDNIB.com
Sponsored byIPv4.Global
Sponsored byCSC
Sponsored byWhoisXML API