Tag: tactics
-
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant
Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls >>pucker factor<<: how close each tactic puts an organisation to major damage once it lands. Built on telemetry from more than 5 million endpoints…
-
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Microsoft says the cyberespionage campaign has hit U.S. and U.K. targets, relying on sheer volume and requiring only a single victim interaction. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-star-blizzard-redflick-phishing-campaigns/
-
Stopping IT Worker Scams Requires Revamped HR Process
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/stopping-it-worker-scams-revamped-hr-process
-
SASE Converges Network & Security Into One Cloud Solution
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/sase-converges-network-security-one-cloud
-
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. First seen on cyberscoop.com Jump to article: cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/
-
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.”Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,” Checkmarx said. “ First seen on…
-
US cyber agency endorses ‘decoy’ tactics
Official US guidance suggests organisations consider using cyber decoys to strengthen their detection and response capabilities. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650815/US-cyber-agency-endorses-decoy-tactics
-
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
Researchers at Huntress have detailed two ransomware incidents involving Settra, a relatively new strain first observed in June, and revealed a consistent set of post-compromise tactics defenders can use to spot the threat before encryption takes hold. In a blog post published this week, Huntress researchers Harlan Carvey and Lindsey O’Donnell-Welch said the company had…
-
Could blame culture be cybersecurity’s next Achilles heel?
By Myles Bray, CEO of CyberSentriq. When it comes to cybersecurity, discussions often centre on technical capabilities, tooling and attacker tactics, but often overlooks the employees and security teams the strategy is intended to protect. The reality is that most critical business functions from staff payroll to procurement and more have now moved online across…
-
Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI. First seen on therecord.media Jump to article: therecord.media/invoice-scam-emails-new-features-microsoft-researchers
-
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
-
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
-
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
-
Red Flags That Expose Fake North Korean IT Workers
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage. First seen on darkreading.com Jump to article: www.darkreading.com/insider-threats/red-flags-expose-fake-north-korean-it-workers
-
The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact
In this post we examine how modern hacktivism has evolved into a tool of global hybrid warfare, analyzing crowdsourced attack tactics, media-driven propaganda, and real-world impacts across Ukraine, the Middle East, European Union, and NATO nations. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-evolution-of-hacktivism-in-hybrid-warfare-modern-tactics-and-real-world-impact/
-
Rethinking Threat Intelligence: New Tactics for the Age of AI
Joe Hladik, head of Rubrik Zero Labs, sat down with the CEO and founder of the Techstrong Group, Alan Shimel, at Black Hat 2026 to talk about how Zero Labs is taking novel approaches to threat intelligence. One emerging source of threat intelligence, Hladik said, has historically been overlooked in threat detection: backup data. “When..…
-
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Tags: access, authentication, conference, cyber, defense, espionage, google, group, intelligence, phishing, russia, tactics, threat, toolGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers,…
-
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/critical-infrastructure-medusa/
-
‘Living Off the Plant’ OT Attacks Pose Physical Safety Risk
Beware Abuse of Native OT Functionality, Says Orange Cyberdefense’s Ric Derbyshire. Attackers can employ living off the plant tactics to stealthily access and move laterally inside industrial networks, abusing native functionality to conduct cyberespionage or disruption campaigns. Orange Cyberdefense’s Ric Derbyshire details essential defenses against this threat. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/living-off-plant-ot-attacks-pose-physical-safety-risk-a-32591
-
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. First seen on cyberscoop.com Jump to article: cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/
-
Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud

