<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">

Third segment: threat-intelligence
  
  <channel>

  <title><![CDATA[CircleID]]></title>
  <link>https://circleid.com/topics/threat-intelligence</link>
  <description>CircleID - Threat Intelligence</description>
  <dc:language>en</dc:language>
  <dc:rights>Copyright 2026, unless where otherwise noted.</dc:rights>
  <dc:date>2026-08-18T22:23:00+00:00</dc:date>

  
    <item>
      <title><![CDATA[Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe]]></title>
      <link>https://circleid.com/posts/massive&#45;photo&#45;zip&#45;campaign&#45;targets&#45;booking&#45;dot&#45;com&#45;partner&#45;and&#45;other&#45;hotels</link>
      <guid isPermaLink="true">https://circleid.com/posts/massive&#45;photo&#45;zip&#45;campaign&#45;targets&#45;booking&#45;dot&#45;com&#45;partner&#45;and&#45;other&#45;hotels</guid>

      <description><![CDATA[A sprawling phishing campaign targeting hotels in Japan and Europe used deceptive photo ZIP files and legitimate web services to establish persistent access, while researchers uncovered thousands of potentially connected infrastructure artifacts and victim IP addresses.]]></description>
      <dc:date>2026-08-18T11:18:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Trump Enlists Private Firms for Offensive Cyber Operations]]></title>
      <link>https://circleid.com/posts/trump&#45;enlists&#45;private&#45;firms&#45;for&#45;offensive&#45;cyber&#45;operations</link>
      <guid isPermaLink="true">https://circleid.com/posts/trump&#45;enlists&#45;private&#45;firms&#45;for&#45;offensive&#45;cyber&#45;operations</guid>

      <description><![CDATA[The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards.]]></description>
      <dc:date>2026-08-13T08:33:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Global Domain Activity Trends Seen in Q2 2026]]></title>
      <link>https://circleid.com/posts/global&#45;domain&#45;activity&#45;trends&#45;seen&#45;in&#45;q2&#45;2026</link>
      <guid isPermaLink="true">https://circleid.com/posts/global&#45;domain&#45;activity&#45;trends&#45;seen&#45;in&#45;q2&#45;2026</guid>

      <description><![CDATA[WhoisXML API's Q2 2026 analysis reveals rising domain registrations, shifting TLD rankings, growing DNS infrastructure concentration, and evolving malicious domain activity, based on billions of DNS records and millions of newly registered and confirmed malicious domains.]]></description>
      <dc:date>2026-08-13T07:43:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[APT37 Strikes Again, This Time with NarwhalRAT]]></title>
      <link>https://circleid.com/posts/apt37&#45;strikes&#45;again&#45;this&#45;time&#45;with&#45;narwhalrat</link>
      <guid isPermaLink="true">https://circleid.com/posts/apt37&#45;strikes&#45;again&#45;this&#45;time&#45;with&#45;narwhalrat</guid>

      <description><![CDATA[North Korea's APT37 has launched a new NarwhalRAT campaign using spearphishing emails and malicious LNK files to deploy data-stealing malware. Researchers also uncovered infrastructure links and fresh indicators that expand the group's known operational footprint.]]></description>
      <dc:date>2026-08-07T08:38:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Phantom Squatting: When LLMs&#8217; Hallucination Becomes an Attacker&#8217;s Best Friend]]></title>
      <link>https://circleid.com/posts/phantom&#45;squatting&#45;when&#45;llms&#45;hallucination&#45;becomes&#45;an&#45;attackers&#45;best&#45;friend</link>
      <guid isPermaLink="true">https://circleid.com/posts/phantom&#45;squatting&#45;when&#45;llms&#45;hallucination&#45;becomes&#45;an&#45;attackers&#45;best&#45;friend</guid>

      <description><![CDATA[As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone.]]></description>
      <dc:date>2026-08-04T08:55:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Investigation of LenAI&#8217;s ErrTraffic ClickFix Distribution Network]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;lenais&#45;errtraffic&#45;clickfix&#45;distribution&#45;network</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;lenais&#45;errtraffic&#45;clickfix&#45;distribution&#45;network</guid>

      <description><![CDATA[An analysis of LenAI's ErrTraffic ClickFix infrastructure uncovered new DNS links, exposing malicious domains, IPs, typosquatting clusters, and email connections that broaden threat visibility and support stronger detection and incident response through expanded network intelligence.]]></description>
      <dc:date>2026-07-31T08:39:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Microsoft Launches AI Cybersecurity Model to Boost MDASH Performance and Cut Costs]]></title>
      <link>https://circleid.com/posts/microsoft&#45;launches&#45;ai&#45;cybersecurity&#45;model&#45;to&#45;boost&#45;mdash&#45;performance&#45;and&#45;cut&#45;costs</link>
      <guid isPermaLink="true">https://circleid.com/posts/microsoft&#45;launches&#45;ai&#45;cybersecurity&#45;model&#45;to&#45;boost&#45;mdash&#45;performance&#45;and&#45;cut&#45;costs</guid>

      <description><![CDATA[Microsoft has unveiled a specialist cybersecurity AI model powering MDASH, claiming higher benchmark performance and lower costs while launching Project Perception, an agentic security platform designed to help defenders counter increasingly automated cyber threats.]]></description>
      <dc:date>2026-07-28T09:21:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[DNS analysis of a malware distribution ecosystem uncovered thousands of linked artifacts, exposing typosquatting, malicious infrastructure and victim connections that broaden detection opportunities beyond Check Point Research's original indicators through expanded DNS intelligence correlation efforts.]]></description>
      <dc:date>2026-07-27T12:51:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Who Registers the Domain That Steals Your Data? The Registrar Accountability Gap in India&#8217;s DNS Abuse Crisis]]></title>
      <link>https://circleid.com/posts/who&#45;registers&#45;the&#45;domain&#45;that&#45;steals&#45;your&#45;data&#45;the&#45;registrar&#45;accountability&#45;gap&#45;in&#45;indias&#45;dns&#45;abuse&#45;crisis</link>
      <guid isPermaLink="true">https://circleid.com/posts/who&#45;registers&#45;the&#45;domain&#45;that&#45;steals&#45;your&#45;data&#45;the&#45;registrar&#45;accountability&#45;gap&#45;in&#45;indias&#45;dns&#45;abuse&#45;crisis</guid>

      <description><![CDATA[India's DNS abuse crisis exposes a registrar accountability gap: malicious domains remain online while vulnerable users bear the cost. Concentrated abuse patterns suggest stronger oversight and faster mitigation could significantly reduce predictable harms nationwide today.]]></description>
      <dc:date>2026-07-24T07:53:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Investigation: Threat Actor TA4922 Goes Global]]></title>
      <link>https://circleid.com/posts/dns&#45;investigation&#45;threat&#45;actor&#45;ta4922&#45;goes&#45;global</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;investigation&#45;threat&#45;actor&#45;ta4922&#45;goes&#45;global</guid>

      <description><![CDATA[TA4922 is expanding beyond nearby targets, deploying a fast-changing malware arsenal across Europe and Africa. A DNS investigation uncovered thousands of connected domains, dozens of malicious assets and signs of compromised victim infrastructure worldwide today.]]></description>
      <dc:date>2026-07-17T08:56:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[FBI Warns of Russian Cyber Campaign Targeting Vulnerable Routers]]></title>
      <link>https://circleid.com/posts/fbi&#45;warns&#45;of&#45;russian&#45;cyber&#45;campaign&#45;targeting&#45;vulnerable&#45;routers</link>
      <guid isPermaLink="true">https://circleid.com/posts/fbi&#45;warns&#45;of&#45;russian&#45;cyber&#45;campaign&#45;targeting&#45;vulnerable&#45;routers</guid>

      <description><![CDATA[The FBI and international partners warn that Russia's FSB Center 16 is exploiting vulnerable routers worldwide, highlighting persistent weaknesses in network security and urging organizations to adopt stronger protections to safeguard critical infrastructure against intrusion.]]></description>
      <dc:date>2026-07-14T12:12:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Under the DNS Hood of an Ongoing Legacy MSHTA Tool Attack]]></title>
      <link>https://circleid.com/posts/under&#45;the&#45;dns&#45;hood&#45;of&#45;an&#45;ongoing&#45;legacy&#45;mshta&#45;tool&#45;attack</link>
      <guid isPermaLink="true">https://circleid.com/posts/under&#45;the&#45;dns&#45;hood&#45;of&#45;an&#45;ongoing&#45;legacy&#45;mshta&#45;tool&#45;attack</guid>

      <description><![CDATA[A DNS analysis of infrastructure behind ongoing MSHTA abuse uncovered malicious registrations, typosquatting clusters, victim activity, and hundreds of linked indicators, revealing how legacy Windows tooling continues enabling modern malware campaigns through interconnected DNS intelligence.]]></description>
      <dc:date>2026-07-10T09:16:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[UK Unveils AI Cyber Shield to Counter Machine-Speed Digital Threats]]></title>
      <link>https://circleid.com/posts/uk&#45;unveils&#45;ai&#45;cyber&#45;shield&#45;to&#45;counter&#45;machine&#45;speed&#45;digital&#45;threats</link>
      <guid isPermaLink="true">https://circleid.com/posts/uk&#45;unveils&#45;ai&#45;cyber&#45;shield&#45;to&#45;counter&#45;machine&#45;speed&#45;digital&#45;threats</guid>

      <description><![CDATA[Britain is developing Cyber Shield, an AI-powered national cyber defense program designed to detect threats, automate responses and protect critical infrastructure as increasingly sophisticated attacks challenge conventional security and strain existing defensive capabilities.]]></description>
      <dc:date>2026-07-08T08:27:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[macOS ClickFix Campaign Delivers AMOS and Other Infostealers: A DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/macos&#45;clickfix&#45;campaign&#45;delivers&#45;amos&#45;and&#45;other&#45;infostealers&#45;a&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/macos&#45;clickfix&#45;campaign&#45;delivers&#45;amos&#45;and&#45;other&#45;infostealers&#45;a&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[A DNS deep dive into Microsoft's macOS ClickFix campaign uncovered victim infrastructure, typosquatting clusters, malicious registrations, and hundreds of linked indicators, exposing a broader infostealer ecosystem beyond the original 140 network IoCs identified by Microsoft.]]></description>
      <dc:date>2026-07-06T08:58:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[What the Interisle Report Reveals, and What It Doesn&#8217;t, About DNS Abuse]]></title>
      <link>https://circleid.com/posts/what&#45;the&#45;interisle&#45;report&#45;reveals&#45;and&#45;what&#45;it&#45;does&#45;not&#45;about&#45;dns&#45;abuse</link>
      <guid isPermaLink="true">https://circleid.com/posts/what&#45;the&#45;interisle&#45;report&#45;reveals&#45;and&#45;what&#45;it&#45;does&#45;not&#45;about&#45;dns&#45;abuse</guid>

      <description><![CDATA[Interisle's report illuminates malicious registration trends, but its broad blocklist methodology measures different questions than DNS Abuse, complicating conclusions about registry and registrar accountability by conflating reputation signals with actionable domain enforcement decisions for policymakers.]]></description>
      <dc:date>2026-06-30T08:34:00-07:00</dc:date>
    </item>
  

  </channel>
  

</rss>