Threat Briefings

Stay ahead of the latest cybersecurity threats with decrypted attack and threat insights designed to keep your organization secure and resilient.

Lucie Cardiet
and
A Valid Microsoft Signature Does Not Mean a Driver Is Safe

Four signed drivers. Three had documented CVEs. None on the blocklist. How DragonForce used the kernel signing pipeline to disable security tools.

Read more
Lucie Cardiet
and
From Conti to The Gentlemen: tooling evolved, gaps didn't.

Conti to The Gentlemen: four ransomware leaks, four years. The operators evolved. The gaps stayed exactly where they were. What CISOs should do next.

Read more
Lucie Cardiet
and
Shai-Hulud Part 2: When the Worm Forged Its Own Security Certificate

TeamPCP open-sourced Shai-Hulud today. The OIDC token extraction technique that made the TanStack attack different from every previous campaign is now a public toolkit.

Read more

Videos

Threat Briefings
Threat Briefing: The NPM Exploit that Turned into a Self-Spreading Worm

Discover how the initial NPM exploit evolved into a self-spreading worm, Shai Hulud, and learn key lessons to protect your software supply chain.

Briefings

Insights straight to your inbox

Sign up for bi-weekly threat briefings and security research findings