Skip to content
  • Wed. Apr 1st, 2026
TIR
  • Home
  • Blog
  • Intelligence Reliability
  • Learning CTI Skills
  • Privacy Policy / TOS
  • Subscribe
Top Tags
  • Incident_Response
  • Threat_Hunting
  • Vulnerability Management
  • Malware_Detection
  • Cybercrime_Organizations
  • Ransomware
  • Nation_State_Actors

Latest Post

OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes Microsoft incident responders publish a playbook for detecting prompt abuse in enterprise AI tools
Articles

OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target

12 March 2026 Threat Analyst
Articles

Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials

12 March 2026 Threat Analyst
Industry_News

Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry

12 March 2026 Threat Analyst
Articles

Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes

12 March 2026 Threat Analyst
Industry_News

Microsoft incident responders publish a playbook for detecting prompt abuse in enterprise AI tools

12 March 2026 Threat Analyst
  • Latest
  • Popular
  • Trending
Articles
OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target
Articles
Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials
Industry_News
Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry
Articles
Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes
Articles
OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target
Articles
Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials
Industry_News
Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry
Articles
Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes
Articles
OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target
Articles
Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials
Industry_News
Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry
Articles
Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes

EDITOR'S CHOICE

Articles

OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target

12 March 2026 Threat Analyst
Articles

Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials

12 March 2026 Threat Analyst
Industry_News

Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry

12 March 2026 Threat Analyst
Articles

Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes

12 March 2026 Threat Analyst
Industry_News

Microsoft incident responders publish a playbook for detecting prompt abuse in enterprise AI tools

12 March 2026 Threat Analyst
Articles

BadPaw and MeowMeow: steganographic .NET malware hits Ukrainian targets

12 March 2026 Threat Analyst
Articles

UAT-9244 hits South American telcos with TernDoor, PeerTime and BruteEntry

6 March 2026 Threat Analyst
Articles

BadAudio and APT24: “good enough” OPSEC powering a multi-vector espionage chain

2 March 2026 Threat Analyst
Articles

Iran crisis cyber risk rises as defacements and disruptive activity reported

2 March 2026 Threat Analyst
Articles

OpenClaw “ClawJacked” chain: malicious websites can hijack local AI agents via localhost WebSockets

2 March 2026 Threat Analyst
Incident_Reports

Qilin Ransomware Attack on Lee Enterprises: Operational Disruption at a Major US Newspaper Publisher

28 February 2025 Threat Analyst

1. Executive Summary In February 2025, Lee Enterprises disclosed a material cybersecurity incident that disrupted distribution, billing, collections, and vendor payments across its newspaper portfolio. In a regulatory filing, the…

Vulnerabilities_Exploits

Microsoft February 2025 Patch Tuesday: 55 CVEs Fixed, 4 Zero-Days (2 Exploited In-The-Wild)

14 February 2025 Threat Analyst

1. Executive Summary On 11 February 2025, Microsoft released Patch Tuesday security updates addressing 55 CVEs, including three Critical remote code execution (RCE) vulnerabilities and four zero-days. Two of the…

Vulnerabilities_Exploits

Finastra Secure File Transfer Platform

20 January 2025 Threat Analyst

1. Executive Summary On 19 November 2024, reporting indicated that financial software provider Finastra was investigating an alleged data breach involving its secure file transfer capability used for transmitting sensitive…

Articles

Nation-State Cyberattacks Escalate: Indian Government Systems and Romanian Elections Under Coordinated Digital Siege

9 January 2025 Threat Analyst

Introduction December 2024 marked a sharp escalation in nation-state cyber activity targeting democratic institutions and government infrastructure. Two developments stand out: a sustained rise in cyberattacks against Indian government entities…

Vulnerabilities_Exploits

Microsoft December Patch Tuesday: 71 Vulnerabilities Patched, Including Actively Exploited CLFS Zero-Day (CVE-2024-49138)

27 December 2024 Threat Analyst

Microsoft has released its December Patch Tuesday security updates, addressing 71 vulnerabilities across its product ecosystem. The release includes 16 Critical-rated flaws and one actively exploited zero-day vulnerability: CVE-2024-49138, affecting…

Incident_Reports

SRP Federal Credit Union Data Breach: Nitrogen Ransomware Claims Compromise of 240,742 Member Records

20 December 2024 Threat Analyst

The Nitrogen ransomware group has claimed responsibility for a significant data breach affecting SRP Federal Credit Union, resulting in the exposure of sensitive personal and financial information belonging to 240,742…

Incident_Reports

Change Healthcare Ransomware Attack (UnitedHealth / Optum): ALPHV/BlackCat Disruption and Mass PHI Exposure

20 December 2024 Threat Analyst

Note on timing: Public reporting and official disclosures indicate the intrusion began in February 2024, while October 2024 is significant because Change Healthcare informed HHS OCR that ~100 million individual…

Vulnerabilities_Exploits

CVE-2024-38094: Microsoft SharePoint Deserialisation RCE — Active Exploitation, Detection Tips, and Mitigation

30 November 2024 Threat Analyst

1. Executive Summary CVE-2024-38094 is a Microsoft SharePoint Server remote code execution (RCE) vulnerability rooted in unsafe deserialisation (CWE-502) and scored 7.2 (High) under CVSS v3.1 by Microsoft. (NVD) It…

Articles

Internet Archive Under Fire: 31 Million-Account Breach and Zendesk Token Exposure Amid Sustained DDoS Disruption

20 November 2024 Threat Analyst

1. Executive Summary In October 2024, the Internet Archive (IA) faced a compound cyber incident combining service-disrupting DDoS activity with a major compromise of user authentication data (31 million records)…

Vulnerabilities_Exploits

GeoVision EOL Devices Under Active Exploitation: CVE-2024-11120 Pre-Auth OS Command Injection Enables Remote Command Execution (CVSS 9.8)

20 November 2024 Threat Analyst

1. Executive Summary CVE-2024-11120 is a critical OS command injection vulnerability affecting certain end-of-life (EOL) GeoVision video server/DVR and licence-plate-recognition device lines, enabling unauthenticated remote attackers to execute arbitrary system…

Posts pagination

1 … 8 9 10 … 29
Search
Recent Posts
  • OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target
  • Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials
  • Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry
  • Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes
  • Microsoft incident responders publish a playbook for detecting prompt abuse in enterprise AI tools
Archives
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • November 2023
  • October 2023
  • August 2023
  • July 2023
  • June 2023
  • January 2023
  • July 2022
  • July 2021
  • July 2020
  • June 2020
  • May 2020
Contact Info
Tweet us @ThreatIntRep

You missed

Articles

OpenClaw lures fuel ClickFix infostealer infections as agentic AI ecosystems become a new credential target

12 March 2026 Threat Analyst
Articles

Storm-2561 pushes fake VPN installers via SEO poisoning to steal enterprise credentials

12 March 2026 Threat Analyst
Industry_News

Hudson Rock ties Polyfill.io supply-chain compromise to DPRK operator via Lumma Stealer telemetry

12 March 2026 Threat Analyst
Articles

Stryker ‘Handala’ incident: global Microsoft environment disruption and reported remote device wipes

12 March 2026 Threat Analyst
TIR

TIR

© Copyright 2026 ThreatIntelReport.com

  • Home
  • Blog
  • Intelligence Reliability
  • Learning CTI Skills
  • Privacy Policy / TOS
  • Subscribe