<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">

Third segment: threat-intelligence
  
  <channel>

  <title><![CDATA[CircleID]]></title>
  <link>https://circleid.com/topics/threat-intelligence</link>
  <description>CircleID - Threat Intelligence</description>
  <dc:language>en</dc:language>
  <dc:rights>Copyright 2026, unless where otherwise noted.</dc:rights>
  <dc:date>2026-09-22T18:08:00+00:00</dc:date>

  
    <item>
      <title><![CDATA[DNS Spotlight: Silver Fox Strikes Anew with a Fake Installer Campaign]]></title>
      <link>https://circleid.com/posts/dns&#45;spotlight&#45;silver&#45;fox&#45;strikes&#45;anew&#45;with&#45;a&#45;fake&#45;installer&#45;campaign</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;spotlight&#45;silver&#45;fox&#45;strikes&#45;anew&#45;with&#45;a&#45;fake&#45;installer&#45;campaign</guid>

      <description><![CDATA[A Silver Fox-style fake installer campaign used deceptive software download sites to distribute malware, while DNS and WHOIS analysis uncovered typosquatting domains, potential victim traffic and more than 1,500 campaign-connected artifacts.]]></description>
      <dc:date>2026-10-02T08:48:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Jewelbug Targets the Middle East and Asia via Cyber Espionage and Crypto Fraud Campaigns]]></title>
      <link>https://circleid.com/posts/jewelbug&#45;targets&#45;the&#45;middle&#45;east&#45;and&#45;asia&#45;via&#45;cyber&#45;espionage&#45;and&#45;crypto&#45;fraud&#45;campaigns</link>
      <guid isPermaLink="true">https://circleid.com/posts/jewelbug&#45;targets&#45;the&#45;middle&#45;east&#45;and&#45;asia&#45;via&#45;cyber&#45;espionage&#45;and&#45;crypto&#45;fraud&#45;campaigns</guid>

      <description><![CDATA[Researchers linked Jewelbug's cyber espionage and crypto fraud operations to shared infrastructure, while DNS analysis uncovered thousands of connected domains, hundreds of potential victim IP addresses and additional malicious artifacts.]]></description>
      <dc:date>2026-09-28T10:51:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[3 Russian Threat Groups Target Persons of Interest]]></title>
      <link>https://circleid.com/posts/3&#45;russian&#45;threat&#45;groups&#45;target&#45;persons&#45;of&#45;interest</link>
      <guid isPermaLink="true">https://circleid.com/posts/3&#45;russian&#45;threat&#45;groups&#45;target&#45;persons&#45;of&#45;interest</guid>

      <description><![CDATA[A DNS investigation into indicators linked to three Russian threat groups uncovered potentially victim-owned IP addresses and thousands of connected domains, including infrastructure already associated with malicious activity.]]></description>
      <dc:date>2026-09-21T08:49:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Why Container Security Is Still Fighting Yesterday&#8217;s Battle]]></title>
      <link>https://circleid.com/posts/why&#45;container&#45;security&#45;is&#45;still&#45;fighting&#45;yesterdays&#45;battle</link>
      <guid isPermaLink="true">https://circleid.com/posts/why&#45;container&#45;security&#45;is&#45;still&#45;fighting&#45;yesterdays&#45;battle</guid>

      <description><![CDATA[Rule-based container security can miss attacks that evade predefined patterns, prompting an argument for behavioral detection that models activity across Kubernetes workloads and control planes while retaining rules for known threats.]]></description>
      <dc:date>2026-09-18T09:30:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[UK, US and Dutch Agencies Expose Iranian Spyware Targeting Dissidents and Journalists]]></title>
      <link>https://circleid.com/posts/uk&#45;us&#45;and&#45;dutch&#45;agencies&#45;expose&#45;iranian&#45;spyware&#45;targeting&#45;dissidents&#45;and&#45;journalists</link>
      <guid isPermaLink="true">https://circleid.com/posts/uk&#45;us&#45;and&#45;dutch&#45;agencies&#45;expose&#45;iranian&#45;spyware&#45;targeting&#45;dissidents&#45;and&#45;journalists</guid>

      <description><![CDATA[UK, US and Dutch agencies have exposed Iranian state-linked spyware that uses personalized social engineering to compromise Windows devices and surveil dissidents, activists and journalists, capturing communications, files, audio and other sensitive data.]]></description>
      <dc:date>2026-09-16T10:11:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[How CZDS Zone Data Helps Detect Domain Abuse]]></title>
      <link>https://circleid.com/posts/how&#45;czds&#45;zone&#45;data&#45;helps&#45;detect&#45;domain&#45;abuse</link>
      <guid isPermaLink="true">https://circleid.com/posts/how&#45;czds&#45;zone&#45;data&#45;helps&#45;detect&#45;domain&#45;abuse</guid>

      <description><![CDATA[Daily CZDS zone data can help brand owners and investigators detect suspicious domain registrations earlier, trace related infrastructure, monitor expired names, and shift enforcement from reactive disputes toward faster, evidence-based intervention.]]></description>
      <dc:date>2026-09-16T08:46:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Cyberattackers Are Using AI Across More of the Kill Chain, Anthropic Reports]]></title>
      <link>https://circleid.com/posts/cyberattackers&#45;are&#45;using&#45;ai&#45;across&#45;more&#45;of&#45;the&#45;kill&#45;chain&#45;anthropic&#45;reports</link>
      <guid isPermaLink="true">https://circleid.com/posts/cyberattackers&#45;are&#45;using&#45;ai&#45;across&#45;more&#45;of&#45;the&#45;kill&#45;chain&#45;anthropic&#45;reports</guid>

      <description><![CDATA[Anthropic says attackers are increasingly using AI agents to orchestrate cyber operations, automating reconnaissance, exploitation, data theft and malware adaptation while lowering the expertise and resources previously required for sophisticated attacks.]]></description>
      <dc:date>2026-09-14T12:50:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Footprinting: SourTrade Distributes Unfinished Malware through Malvertising]]></title>
      <link>https://circleid.com/posts/dns&#45;footprinting&#45;sourtrade&#45;distributes&#45;unfinished&#45;malware&#45;through&#45;malvertising</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;footprinting&#45;sourtrade&#45;distributes&#45;unfinished&#45;malware&#45;through&#45;malvertising</guid>

      <description><![CDATA[DNS analysis of 96 SourTrade domains uncovered hundreds of connected domains and IP addresses, many flagged as malicious, while identifying indicators that appeared months before researchers formally linked them to the malvertising campaign.]]></description>
      <dc:date>2026-09-11T08:33:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Spotlight: 2026&#8217;s 5 Most Notorious Ransomware]]></title>
      <link>https://circleid.com/posts/dns&#45;spotlight&#45;2026s&#45;5&#45;most&#45;notorious&#45;ransomware</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;spotlight&#45;2026s&#45;5&#45;most&#45;notorious&#45;ransomware</guid>

      <description><![CDATA[DNS analysis of 84 network indicators tied to LockBit, Cl0p, Akira, Medusa, and Qilin uncovered thousands of connected domains and IP addresses, including additional artifacts already identified as malicious.]]></description>
      <dc:date>2026-09-08T07:59:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[From Forgotten to Exploited: How AI Changes the Dangling DNS Threat]]></title>
      <link>https://circleid.com/posts/from&#45;forgotten&#45;to&#45;exploited&#45;how&#45;ai&#45;changes&#45;the&#45;dangling&#45;dns&#45;threat</link>
      <guid isPermaLink="true">https://circleid.com/posts/from&#45;forgotten&#45;to&#45;exploited&#45;how&#45;ai&#45;changes&#45;the&#45;dangling&#45;dns&#45;threat</guid>

      <description><![CDATA[Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits.]]></description>
      <dc:date>2026-09-01T08:46:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union&#8217;s Domain]]></title>
      <link>https://circleid.com/posts/thirty&#45;five&#45;years&#45;later&#45;moscow&#45;comes&#45;looking&#45;for&#45;the&#45;soviet&#45;unions&#45;domain</link>
      <guid isPermaLink="true">https://circleid.com/posts/thirty&#45;five&#45;years&#45;later&#45;moscow&#45;comes&#45;looking&#45;for&#45;the&#45;soviet&#45;unions&#45;domain</guid>

      <description><![CDATA[Russia is imposing state identity verification on .su, the Soviet Union's surviving domain, as researchers uncover criminal infrastructure across the namespace and ICANN pursues a retirement process that could eventually remove it from the global root.]]></description>
      <dc:date>2026-09-01T08:35:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[More Than 100 Organizations Call for Global Surge in AI-Assisted Cyber Defense]]></title>
      <link>https://circleid.com/posts/more&#45;than&#45;100&#45;organizations&#45;call&#45;for&#45;global&#45;surge&#45;in&#45;ai&#45;assisted&#45;cyber&#45;defense</link>
      <guid isPermaLink="true">https://circleid.com/posts/more&#45;than&#45;100&#45;organizations&#45;call&#45;for&#45;global&#45;surge&#45;in&#45;ai&#45;assisted&#45;cyber&#45;defense</guid>

      <description><![CDATA[More than 100 organizations are calling for wider use of AI in cyber defense, urging governments, technology providers and AI developers to expand funding, tools, model access and practical support for under-resourced critical infrastructure operators.]]></description>
      <dc:date>2026-08-29T11:49:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;infrastructure&#45;analysis&#45;of&#45;a&#45;microsoft&#45;365&#45;device&#45;code&#45;phishing&#45;campaign</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;infrastructure&#45;analysis&#45;of&#45;a&#45;microsoft&#45;365&#45;device&#45;code&#45;phishing&#45;campaign</guid>

      <description><![CDATA[A DNS investigation into a Microsoft 365 device code phishing campaign uncovered coordinated, disposable infrastructure, including 290 indicators of compromise, 87 malicious IP addresses and hundreds of connected domains, suggesting the operation remains active.]]></description>
      <dc:date>2026-08-28T11:59:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[UK Warns of Rising Cyberattacks on Exposed Industrial Systems]]></title>
      <link>https://circleid.com/posts/uk&#45;warns&#45;of&#45;rising&#45;cyberattacks&#45;on&#45;exposed&#45;industrial&#45;systems</link>
      <guid isPermaLink="true">https://circleid.com/posts/uk&#45;warns&#45;of&#45;rising&#45;cyberattacks&#45;on&#45;exposed&#45;industrial&#45;systems</guid>

      <description><![CDATA[Britain's cyber agency warns that attackers are increasingly targeting internet-exposed industrial systems, routers and other edge devices, with some intrusions causing real-world disruption and highlighting the growing risks of poorly secured operational technology worldwide.]]></description>
      <dc:date>2026-08-28T09:02:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/5&#45;of&#45;the&#45;biggest&#45;cyber&#45;attacks&#45;in&#45;2026&#45;so&#45;far&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/5&#45;of&#45;the&#45;biggest&#45;cyber&#45;attacks&#45;in&#45;2026&#45;so&#45;far&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[A DNS deep dive into five major cyber attacks of 2026 uncovers infrastructure linked to Cisco, Ivanti, Stryker and ShinyHunters incidents, revealing hundreds of connected domains and IP addresses that could sharpen threat detection efforts.]]></description>
      <dc:date>2026-08-24T11:43:00-07:00</dc:date>
    </item>
  

  </channel>
  

</rss>