Threat Intelligence

Threat Intelligence / Most Commented

Moving Target: Spammer Using Over 1000 Home Computers as DNS

Some individual appears to have hijacked more than a 1,000 home computers starting in late June or early July and has been installing a new Trojan Horse program on them. The Trojan allows this person to run a number of small websites on the hijacked home computers. These websites consists of only a few web pages and apparently produce income by directing sign-ups to for-pay porn websites through affiliate programs. Spam emails messages get visitors to come to the small websites.

To make it more difficult for these websites to be shut down, a single home computer is used for only 10 minutes to host a site. After 10 minutes, the IP address of the website is changed to a different home computer... more

98% Of Internet’s Main Root Server Queries Are Unnecccary: Should You Be Concerned?

A recent study by researchers at the Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Super Computer Center (SDSC) revealed that a staggering 98% of the global Internet queries to one of the main root servers, at the heart of the Internet, were unnecessary. This analysis was conducted on data collected October 4, 2002 from the 'F' root server located in Palo Alto, California.

The findings of the study were originally presented to the North American Network Operators' Group (NANOG) on October 2002 and later discussed with Richard A. Clarke, chairman of the President's Critical Infrastructure Protection Board and Special Advisor to the U.S. President for Cyber Space Security. more

Why Container Security Is Still Fighting Yesterday’s Battle

Rule-based container security can miss attacks that evade predefined patterns, prompting an argument for behavioral detection that models activity across Kubernetes workloads and control planes while retaining rules for known threats. more

UK, US and Dutch Agencies Expose Iranian Spyware Targeting Dissidents and Journalists

UK, US and Dutch agencies have exposed Iranian state-linked spyware that uses personalized social engineering to compromise Windows devices and surveil dissidents, activists and journalists, capturing communications, files, audio and other sensitive data. more

Cyberattackers Are Using AI Across More of the Kill Chain, Anthropic Reports

Anthropic says attackers are increasingly using AI agents to orchestrate cyber operations, automating reconnaissance, exploitation, data theft and malware adaptation while lowering the expertise and resources previously required for sophisticated attacks. more

From Forgotten to Exploited: How AI Changes the Dangling DNS Threat

Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits. more

Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union’s Domain

Russia is imposing state identity verification on .su, the Soviet Union's surviving domain, as researchers uncover criminal infrastructure across the namespace and ICANN pursues a retirement process that could eventually remove it from the global root. more

More Than 100 Organizations Call for Global Surge in AI-Assisted Cyber Defense

More than 100 organizations are calling for wider use of AI in cyber defense, urging governments, technology providers and AI developers to expand funding, tools, model access and practical support for under-resourced critical infrastructure operators. more

UK Warns of Rising Cyberattacks on Exposed Industrial Systems

Britain's cyber agency warns that attackers are increasingly targeting internet-exposed industrial systems, routers and other edge devices, with some intrusions causing real-world disruption and highlighting the growing risks of poorly secured operational technology worldwide. more

Trump Enlists Private Firms for Offensive Cyber Operations

The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards. more

Phantom Squatting: When LLMs’ Hallucination Becomes an Attacker’s Best Friend

As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone. more

Microsoft Launches AI Cybersecurity Model to Boost MDASH Performance and Cut Costs

Microsoft has unveiled a specialist cybersecurity AI model powering MDASH, claiming higher benchmark performance and lower costs while launching Project Perception, an agentic security platform designed to help defenders counter increasingly automated cyber threats. more

Who Registers the Domain That Steals Your Data? The Registrar Accountability Gap in India’s DNS Abuse Crisis

India's DNS abuse crisis exposes a registrar accountability gap: malicious domains remain online while vulnerable users bear the cost. Concentrated abuse patterns suggest stronger oversight and faster mitigation could significantly reduce predictable harms nationwide today. more

FBI Warns of Russian Cyber Campaign Targeting Vulnerable Routers

The FBI and international partners warn that Russia's FSB Center 16 is exploiting vulnerable routers worldwide, highlighting persistent weaknesses in network security and urging organizations to adopt stronger protections to safeguard critical infrastructure against intrusion. more

UK Unveils AI Cyber Shield to Counter Machine-Speed Digital Threats

Britain is developing Cyber Shield, an AI-powered national cyber defense program designed to detect threats, automate responses and protect critical infrastructure as increasingly sophisticated attacks challenge conventional security and strain existing defensive capabilities. more