Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 79 - BeaverTail and InvisibleFerret: The Malware That Rewrites Itself for Every Target

North Korea has stopped writing bad phishing emails. In Part 2 of our DPRK deep dive, Tova Dvorin and Adrian Culley break down how the Reconnaissance General Bureau and Bureau 121 weaponized AI in 2026: Blue Noroff cloning a CFO's voice to authorize emergency liquidity transfers, real-time face swaps passing DevOps job interviews, and Lazarus using LLMs to polymorph BeaverTail and InvisibleFerret for every single target.

Ungentlemanly behavior: Insights into a ransomware operation

They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.

MECCHA CHAMELEON can't hide from the RCE

TL;DR: We found another delayed RCE in MECCHA CHAMELEON. When playing on an attacker’s map, they can abuse an exposed function to arbitrarily write files to the victim’s system. This can lead to remote code execution on the victim’s system after a restart. We reported the issue to the game’s maintainers, and they fixed the vulnerability in the 4.0.0 update. This update is automatically installed before launching the game.

Block malware before it downloads: Configuring Download Filters in MSP Central

Imagine this: A cracked installer disguised as a productivity tool. An oversized file quietly eating into storage. An EXE attachment that never should have made it past the browser. Without a download policy in place, there's nothing stopping this from happening on any device—for any client at any time.

How BlueVoyant and Partners are Detecting Modern Phishing Campaigns Across the Full Attack Chain Utilizing Microsoft's UEBA Capabilities

Over recent months, our Microsoft Managed Detection and Response (MDR) service, powered by the Threat Fusion Cell, has observed a sharp increase in sophisticated attack campaigns attributed to offshoots of threat brand Vocal Brigantine, who ceased operations in Spring 2026.

Peer Pressure: Inside the Sality Botnet Disruption Operation

On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades. The botnet enabled the operator to distribute malicious payloads to over 15,000 infected machines worldwide.