Cybersecurity

Sponsored
by

Cybersecurity / Industry Updates

A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign

A DNS investigation into a Microsoft 365 device code phishing campaign uncovered coordinated, disposable infrastructure, including 290 indicators of compromise, 87 malicious IP addresses and hundreds of connected domains, suggesting the operation remains active.

5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive

A DNS deep dive into five major cyber attacks of 2026 uncovers infrastructure linked to Cisco, Ivanti, Stryker and ShinyHunters incidents, revealing hundreds of connected domains and IP addresses that could sharpen threat detection efforts.

Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe

A sprawling phishing campaign targeting hotels in Japan and Europe used deceptive photo ZIP files and legitimate web services to establish persistent access, while researchers uncovered thousands of potentially connected infrastructure artifacts and victim IP addresses.

Global Domain Activity Trends Seen in Q2 2026

WhoisXML API's Q2 2026 analysis reveals rising domain registrations, shifting TLD rankings, growing DNS infrastructure concentration, and evolving malicious domain activity, based on billions of DNS records and millions of newly registered and confirmed malicious domains.

APT37 Strikes Again, This Time with NarwhalRAT

North Korea's APT37 has launched a new NarwhalRAT campaign using spearphishing emails and malicious LNK files to deploy data-stealing malware. Researchers also uncovered infrastructure links and fresh indicators that expand the group's known operational footprint.

A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

An analysis of LenAI's ErrTraffic ClickFix infrastructure uncovered new DNS links, exposing malicious domains, IPs, typosquatting clusters, and email connections that broaden threat visibility and support stronger detection and incident response through expanded network intelligence.

Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive

DNS analysis of a malware distribution ecosystem uncovered thousands of linked artifacts, exposing typosquatting, malicious infrastructure and victim connections that broaden detection opportunities beyond Check Point Research's original indicators through expanded DNS intelligence correlation efforts.

DNS Investigation: Threat Actor TA4922 Goes Global

TA4922 is expanding beyond nearby targets, deploying a fast-changing malware arsenal across Europe and Africa. A DNS investigation uncovered thousands of connected domains, dozens of malicious assets and signs of compromised victim infrastructure worldwide today.

Under the DNS Hood of an Ongoing Legacy MSHTA Tool Attack

A DNS analysis of infrastructure behind ongoing MSHTA abuse uncovered malicious registrations, typosquatting clusters, victim activity, and hundreds of linked indicators, revealing how legacy Windows tooling continues enabling modern malware campaigns through interconnected DNS intelligence.

What Running .CA and .NL Taught Us About Building Better Registry Infrastructure

Running .CA and .NL has taught Hello Registry that true back-end excellence depends on resilience, adaptability and operational experience, helping registries navigate evolving technical, policy and security demands with confidence and long-term stability.