Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Malware Risks and Mitigation: Strengthen Your Cybersecurity Posture

Malware attacks are a major cybersecurity concern for individuals and businesses. These attacks can lead to data theft and financial losses. A report from AV-Test suggests that more than 450,000 new malware and PUA samples are detected each day, bringing the total to 1.56 billion known samples. Malware can take many forms, such as viruses, ransomware, spyware, and trojans. These can threaten data integrity, privacy, and business continuity.

Ransomware Attacks Drive a Surge in Cyber Insurance Claims

Cyber insurance claims surged by 40% over the past eighteen months, while ransomware payments have dropped by 44%, according to a new report from Cowbell Cyber. The three most common incident types were data breaches, cybercrime (including phishing and business email compromise), and extortion attacks (including ransomware).

Surviving a LockBit Ransomware Attack: The ROI of Visibility

In August 2023, while thousands of students at William Jewell College were hauling mini-fridges and textbooks into dorms, the invisible, digital heart of the campus was flatlining. There was no internet. No email. Even the HVAC system, tied to a compromised network, had shut down in the sweltering Missouri heat. The culprit? LockBit, a prolific ransomware syndicate that just hit Boeing days prior.

Reimagining Disaster Recovery: Building the Isolated Recovery Environment

Healthcare cyber resilience depends on ransomware recovery and patient care continuity. Christian Lindmark of Stanford Health Care joins Josh Howell to discuss an innovative approach to building an isolated recovery environment. Instead of requesting significant new capital from the board, Christian proposes a hybrid model that utilizes existing disaster recovery hardware for cyber response. They explore the shift from physical disaster planning to addressing the persistent reality of cyber attacks that compromise environment trust.

How Replicating Marauder Rewired the Supply Chain Playbook

In March 2026, researchers began linking a series of software supply-chain compromises to Replicating Marauder, the BlueVoyant Threat Fusion Cell (TFC) primary identifier for the actor publicly tracked elsewhere as TeamPCP. What made the campaign stand out was that trusted software was poisoned and one compromise repeatedly appeared to enable the next by exposing credentials, release paths, or Continuous Integration and Continuous Delivery or Deployment (CI/CD) trust relationships.

BlackToad: Network Manipulation in an AutoIt Payload

Recently, JUMPSEC’s DART (Detection and Response Team) detected a phishing email targeting a client environment. The email, written in Thai and containing a MediaFire download link, was identified as suspicious by an incident responder and we kicked off an investigation. Since then, we have established infrastructure to track the threat actor, analysed the novel payload in detail, and identified several IoCs below.

Analyzing real malware with Claude Code and LimaCharlie

Most malware analysis workflows follow the same pattern: run a set of tools, manually review the output, build detection rules from memory, and repeat. It's reliable, but slow, and for MDR and MSSP teams handling volume, delays have a cost. In this workshop, LimaCharlie Senior Solutions Engineer Chris Botelho demonstrates a faster path: using Claude Code with LimaCharlie's reverse engineering environment to triage, analyze, and build detections against a real malware sample pulled from Malware Bazaar.