https://github.com/marktsec
specterops.io/blog/2025/12...
specterops.io/blog/2025/12...
Windows PowerShell 5.1 now displays a security confirmation prompt when using the Invoke-WebRequest command to fetch web pages without special parameters.
support.microsoft.com/en-us/topic/...
Windows PowerShell 5.1 now displays a security confirmation prompt when using the Invoke-WebRequest command to fetch web pages without special parameters.
support.microsoft.com/en-us/topic/...
www.gdatasoftware.com/blog/2025/11...
www.gdatasoftware.com/blog/2025/11...
flare.io/learn/resour...
flare.io/learn/resour...
mazinahmed.net/blog/publish...
mazinahmed.net/blog/publish...
Nova operators announced locker rewritten in ADA/SPARK and targeting Windows, Linux, and ESXi.
The group boasts Rust-like techniques, enhanced evasion, and even a so-called “safe mode.”
#ThreatIntel #Ransomware #MalwareAnalysis
Nova operators announced locker rewritten in ADA/SPARK and targeting Windows, Linux, and ESXi.
The group boasts Rust-like techniques, enhanced evasion, and even a so-called “safe mode.”
#ThreatIntel #Ransomware #MalwareAnalysis
www.greynoise.io/blog/cve-202...
www.greynoise.io/blog/cve-202...
xbz0n.sh/blog/living-...
xbz0n.sh/blog/living-...
• Steam token collection restored, now pulled directly from local files (no process injection), enabling multi-account token harvesting.
• New data targets: Perplexity “Comet” browser & IndexedDB for all MetaMask versions.
#infosec #threatintel
• Steam token collection restored, now pulled directly from local files (no process injection), enabling multi-account token harvesting.
• New data targets: Perplexity “Comet” browser & IndexedDB for all MetaMask versions.
#infosec #threatintel
www.intrinsec.com/hide-the-thr...
www.intrinsec.com/hide-the-thr...
www.zscaler.com/blogs/securi...
www.zscaler.com/blogs/securi...
redcanary.com/blog/threat-...
redcanary.com/blog/threat-...
krebsonsecurity.com/2025/11/meet...
krebsonsecurity.com/2025/11/meet...
www.validin.com/blog/inside_...
www.validin.com/blog/inside_...
www.picussecurity.com/resource/blo...
www.picussecurity.com/resource/blo...
gist.github.com/alexgreenlan...
gist.github.com/alexgreenlan...
labs.watchtowr.com/when-the-imp...
labs.watchtowr.com/when-the-imp...
www.greynoise.io/blog/palo-al...
www.greynoise.io/blog/palo-al...
• Updated Edge module to extract the new v20 key
• Expanded crypto-wallet targeting (incl. LTC/Dash Core, Trezor Suite, MEW Desktop, AtomicDEX & more)
• Improved C2 marker parsing + performance fixes
#ThreatIntel #InfoSec
• Updated Edge module to extract the new v20 key
• Expanded crypto-wallet targeting (incl. LTC/Dash Core, Trezor Suite, MEW Desktop, AtomicDEX & more)
• Improved C2 marker parsing + performance fixes
#ThreatIntel #InfoSec
ipurple.team/2025/11/18/l...
ipurple.team/2025/11/18/l...
www.cybereason.com/blog/the-gen...
www.cybereason.com/blog/the-gen...
Denis Obrezko is allegedly part of the notorious group Void Blizzard
edition.cnn.com/2025/11/15/a...
Denis Obrezko is allegedly part of the notorious group Void Blizzard
edition.cnn.com/2025/11/15/a...
blog.nviso.eu/2025/11/13/c...
blog.nviso.eu/2025/11/13/c...