<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">

Third segment: threat-intelligence
  
  <channel>

  <title><![CDATA[CircleID]]></title>
  <link>https://circleid.com/topics/threat-intelligence</link>
  <description>CircleID - Threat Intelligence</description>
  <dc:language>en</dc:language>
  <dc:rights>Copyright 2026, unless where otherwise noted.</dc:rights>
  <dc:date>2026-09-01T16:03:00+00:00</dc:date>

  
    <item>
      <title><![CDATA[DNS Spotlight: 2026&#8217;s 5 Most Notorious Ransomware]]></title>
      <link>https://circleid.com/posts/dns&#45;spotlight&#45;2026s&#45;5&#45;most&#45;notorious&#45;ransomware</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;spotlight&#45;2026s&#45;5&#45;most&#45;notorious&#45;ransomware</guid>

      <description><![CDATA[DNS analysis of 84 network indicators tied to LockBit, Cl0p, Akira, Medusa, and Qilin uncovered thousands of connected domains and IP addresses, including additional artifacts already identified as malicious.]]></description>
      <dc:date>2026-09-08T07:59:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[From Forgotten to Exploited: How AI Changes the Dangling DNS Threat]]></title>
      <link>https://circleid.com/posts/from&#45;forgotten&#45;to&#45;exploited&#45;how&#45;ai&#45;changes&#45;the&#45;dangling&#45;dns&#45;threat</link>
      <guid isPermaLink="true">https://circleid.com/posts/from&#45;forgotten&#45;to&#45;exploited&#45;how&#45;ai&#45;changes&#45;the&#45;dangling&#45;dns&#45;threat</guid>

      <description><![CDATA[Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits.]]></description>
      <dc:date>2026-09-01T08:46:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union&#8217;s Domain]]></title>
      <link>https://circleid.com/posts/thirty&#45;five&#45;years&#45;later&#45;moscow&#45;comes&#45;looking&#45;for&#45;the&#45;soviet&#45;unions&#45;domain</link>
      <guid isPermaLink="true">https://circleid.com/posts/thirty&#45;five&#45;years&#45;later&#45;moscow&#45;comes&#45;looking&#45;for&#45;the&#45;soviet&#45;unions&#45;domain</guid>

      <description><![CDATA[Russia is imposing state identity verification on .su, the Soviet Union's surviving domain, as researchers uncover criminal infrastructure across the namespace and ICANN pursues a retirement process that could eventually remove it from the global root.]]></description>
      <dc:date>2026-09-01T08:35:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[More Than 100 Organizations Call for Global Surge in AI-Assisted Cyber Defense]]></title>
      <link>https://circleid.com/posts/more&#45;than&#45;100&#45;organizations&#45;call&#45;for&#45;global&#45;surge&#45;in&#45;ai&#45;assisted&#45;cyber&#45;defense</link>
      <guid isPermaLink="true">https://circleid.com/posts/more&#45;than&#45;100&#45;organizations&#45;call&#45;for&#45;global&#45;surge&#45;in&#45;ai&#45;assisted&#45;cyber&#45;defense</guid>

      <description><![CDATA[More than 100 organizations are calling for wider use of AI in cyber defense, urging governments, technology providers and AI developers to expand funding, tools, model access and practical support for under-resourced critical infrastructure operators.]]></description>
      <dc:date>2026-08-29T11:49:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;infrastructure&#45;analysis&#45;of&#45;a&#45;microsoft&#45;365&#45;device&#45;code&#45;phishing&#45;campaign</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;infrastructure&#45;analysis&#45;of&#45;a&#45;microsoft&#45;365&#45;device&#45;code&#45;phishing&#45;campaign</guid>

      <description><![CDATA[A DNS investigation into a Microsoft 365 device code phishing campaign uncovered coordinated, disposable infrastructure, including 290 indicators of compromise, 87 malicious IP addresses and hundreds of connected domains, suggesting the operation remains active.]]></description>
      <dc:date>2026-08-28T11:59:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[UK Warns of Rising Cyberattacks on Exposed Industrial Systems]]></title>
      <link>https://circleid.com/posts/uk&#45;warns&#45;of&#45;rising&#45;cyberattacks&#45;on&#45;exposed&#45;industrial&#45;systems</link>
      <guid isPermaLink="true">https://circleid.com/posts/uk&#45;warns&#45;of&#45;rising&#45;cyberattacks&#45;on&#45;exposed&#45;industrial&#45;systems</guid>

      <description><![CDATA[Britain's cyber agency warns that attackers are increasingly targeting internet-exposed industrial systems, routers and other edge devices, with some intrusions causing real-world disruption and highlighting the growing risks of poorly secured operational technology worldwide.]]></description>
      <dc:date>2026-08-28T09:02:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/5&#45;of&#45;the&#45;biggest&#45;cyber&#45;attacks&#45;in&#45;2026&#45;so&#45;far&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/5&#45;of&#45;the&#45;biggest&#45;cyber&#45;attacks&#45;in&#45;2026&#45;so&#45;far&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[A DNS deep dive into five major cyber attacks of 2026 uncovers infrastructure linked to Cisco, Ivanti, Stryker and ShinyHunters incidents, revealing hundreds of connected domains and IP addresses that could sharpen threat detection efforts.]]></description>
      <dc:date>2026-08-24T11:43:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe]]></title>
      <link>https://circleid.com/posts/massive&#45;photo&#45;zip&#45;campaign&#45;targets&#45;booking&#45;dot&#45;com&#45;partner&#45;and&#45;other&#45;hotels</link>
      <guid isPermaLink="true">https://circleid.com/posts/massive&#45;photo&#45;zip&#45;campaign&#45;targets&#45;booking&#45;dot&#45;com&#45;partner&#45;and&#45;other&#45;hotels</guid>

      <description><![CDATA[A sprawling phishing campaign targeting hotels in Japan and Europe used deceptive photo ZIP files and legitimate web services to establish persistent access, while researchers uncovered thousands of potentially connected infrastructure artifacts and victim IP addresses.]]></description>
      <dc:date>2026-08-18T11:18:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Trump Enlists Private Firms for Offensive Cyber Operations]]></title>
      <link>https://circleid.com/posts/trump&#45;enlists&#45;private&#45;firms&#45;for&#45;offensive&#45;cyber&#45;operations</link>
      <guid isPermaLink="true">https://circleid.com/posts/trump&#45;enlists&#45;private&#45;firms&#45;for&#45;offensive&#45;cyber&#45;operations</guid>

      <description><![CDATA[The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards.]]></description>
      <dc:date>2026-08-13T08:33:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Global Domain Activity Trends Seen in Q2 2026]]></title>
      <link>https://circleid.com/posts/global&#45;domain&#45;activity&#45;trends&#45;seen&#45;in&#45;q2&#45;2026</link>
      <guid isPermaLink="true">https://circleid.com/posts/global&#45;domain&#45;activity&#45;trends&#45;seen&#45;in&#45;q2&#45;2026</guid>

      <description><![CDATA[WhoisXML API's Q2 2026 analysis reveals rising domain registrations, shifting TLD rankings, growing DNS infrastructure concentration, and evolving malicious domain activity, based on billions of DNS records and millions of newly registered and confirmed malicious domains.]]></description>
      <dc:date>2026-08-13T07:43:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[APT37 Strikes Again, This Time with NarwhalRAT]]></title>
      <link>https://circleid.com/posts/apt37&#45;strikes&#45;again&#45;this&#45;time&#45;with&#45;narwhalrat</link>
      <guid isPermaLink="true">https://circleid.com/posts/apt37&#45;strikes&#45;again&#45;this&#45;time&#45;with&#45;narwhalrat</guid>

      <description><![CDATA[North Korea's APT37 has launched a new NarwhalRAT campaign using spearphishing emails and malicious LNK files to deploy data-stealing malware. Researchers also uncovered infrastructure links and fresh indicators that expand the group's known operational footprint.]]></description>
      <dc:date>2026-08-07T08:38:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Phantom Squatting: When LLMs&#8217; Hallucination Becomes an Attacker&#8217;s Best Friend]]></title>
      <link>https://circleid.com/posts/phantom&#45;squatting&#45;when&#45;llms&#45;hallucination&#45;becomes&#45;an&#45;attackers&#45;best&#45;friend</link>
      <guid isPermaLink="true">https://circleid.com/posts/phantom&#45;squatting&#45;when&#45;llms&#45;hallucination&#45;becomes&#45;an&#45;attackers&#45;best&#45;friend</guid>

      <description><![CDATA[As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone.]]></description>
      <dc:date>2026-08-04T08:55:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Investigation of LenAI&#8217;s ErrTraffic ClickFix Distribution Network]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;lenais&#45;errtraffic&#45;clickfix&#45;distribution&#45;network</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;lenais&#45;errtraffic&#45;clickfix&#45;distribution&#45;network</guid>

      <description><![CDATA[An analysis of LenAI's ErrTraffic ClickFix infrastructure uncovered new DNS links, exposing malicious domains, IPs, typosquatting clusters, and email connections that broaden threat visibility and support stronger detection and incident response through expanded network intelligence.]]></description>
      <dc:date>2026-07-31T08:39:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Microsoft Launches AI Cybersecurity Model to Boost MDASH Performance and Cut Costs]]></title>
      <link>https://circleid.com/posts/microsoft&#45;launches&#45;ai&#45;cybersecurity&#45;model&#45;to&#45;boost&#45;mdash&#45;performance&#45;and&#45;cut&#45;costs</link>
      <guid isPermaLink="true">https://circleid.com/posts/microsoft&#45;launches&#45;ai&#45;cybersecurity&#45;model&#45;to&#45;boost&#45;mdash&#45;performance&#45;and&#45;cut&#45;costs</guid>

      <description><![CDATA[Microsoft has unveiled a specialist cybersecurity AI model powering MDASH, claiming higher benchmark performance and lower costs while launching Project Perception, an agentic security platform designed to help defenders counter increasingly automated cyber threats.]]></description>
      <dc:date>2026-07-28T09:21:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[DNS analysis of a malware distribution ecosystem uncovered thousands of linked artifacts, exposing typosquatting, malicious infrastructure and victim connections that broaden detection opportunities beyond Check Point Research's original indicators through expanded DNS intelligence correlation efforts.]]></description>
      <dc:date>2026-07-27T12:51:00-07:00</dc:date>
    </item>
  

  </channel>
  

</rss>