Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Havoc Malware: Techniques, Targets, and Threat Overview

Security analysts have noticed a trend among threat actors shifting towards adopting a novel open-source command and control (C2) framework called Havoc as an alternative to paid solutions like Cobalt Strike and Brute Ratel. Developed in the C language and introduced in 2022, Havoc’s Main branch received updates in 2023.

How Do I Check My iPhone for Malware: A Complete Guide

If your iPhone suddenly feels wrong, slower, hotter, or louder in the background, don't waste time hunting for a magic antivirus button. How do I check my iPhone for malware is the wrong question if you expect a desktop-style scan, because iOS doesn't work that way. The right question is, what did the attacker leave behind, and what changed in the device's behavior or configuration? That's the triage mindset security teams use on endpoints, and it fits iPhone incidents too.

The 14-Hour Recovery: Rethinking Healthcare Cyber Resilience

Ransomware recovery for healthcare IT depends on isolated recovery environments (IRE) and the ability to find clean data for patient safety. Jeremy Cathey shares insights on building cyber resilience by moving away from traditional disaster recovery toward a model that handles systemic cyberattacks. He details the three essential zones of an IRE: the clean room for forensics, the staging zone for validation, and the standby production environment where clinicians resume work.

Ransomware protection: how endpoint security and backup work together

Quick definition Ransomware protection combines two things that work at different points of an attack: endpoint protection software that detects and blocks ransomware before it encrypts data, and backup and disaster recovery solutions that let an organization restore its systems if an attack still gets through.

Atlanta's $17M Ransomware Attack: What Could Have Stopped It

In March 2018, the SamSam ransomware attack on the city of Atlanta became one of the most expensive ransomware incidents ever to hit a US local government. It remains a useful case study in what happens when an organization has no way to detect, stop or recover from ransomware in real time.

SparkKitty Malware: An Emerging Threat to Mobile Users

SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a previous stealer known as SparkCat.

Why Flipping Cyber Defense Backwards Works

Standard incident response is failing to keep pace with long-term threat campaigns. Adam Karcher from the FBI explains why the most effective security teams run their operations as an inverted offensive strategy, leveraging continuous adversary emulation to stop intrusions before they begin. Watch the full video on our channel.