Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep. 79 - BeaverTail and InvisibleFerret: The Malware That Rewrites Itself for Every Target

North Korea has stopped writing bad phishing emails. In Part 2 of our DPRK deep dive, Tova Dvorin and Adrian Culley break down how the Reconnaissance General Bureau and Bureau 121 weaponized AI in 2026: Blue Noroff cloning a CFO's voice to authorize emergency liquidity transfers, real-time face swaps passing DevOps job interviews, and Lazarus using LLMs to polymorph BeaverTail and InvisibleFerret for every single target.

Ungentlemanly behavior: Insights into a ransomware operation

They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.

MECCHA CHAMELEON can't hide from the RCE

TL;DR: We found another delayed RCE in MECCHA CHAMELEON. When playing on an attacker’s map, they can abuse an exposed function to arbitrarily write files to the victim’s system. This can lead to remote code execution on the victim’s system after a restart. We reported the issue to the game’s maintainers, and they fixed the vulnerability in the 4.0.0 update. This update is automatically installed before launching the game.

Block malware before it downloads: Configuring Download Filters in MSP Central

Imagine this: A cracked installer disguised as a productivity tool. An oversized file quietly eating into storage. An EXE attachment that never should have made it past the browser. Without a download policy in place, there's nothing stopping this from happening on any device—for any client at any time.

How BlueVoyant and Partners are Detecting Modern Phishing Campaigns Across the Full Attack Chain Utilizing Microsoft's UEBA Capabilities

Over recent months, our Microsoft Managed Detection and Response (MDR) service, powered by the Threat Fusion Cell, has observed a sharp increase in sophisticated attack campaigns attributed to offshoots of threat brand Vocal Brigantine, who ceased operations in Spring 2026.

Peer Pressure: Inside the Sality Botnet Disruption Operation

On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades. The botnet enabled the operator to distribute malicious payloads to over 15,000 infected machines worldwide.

Pikabot Malware: Delivery Methods, Evasion, and Impact

Originating in early 2023, Pikabot emerged as a significant malware loader. Over the past year, ThreatLabz has diligently monitored its development and operational methods. Notably, there was a surge in Pikabot’s usage in the latter part of 2023, attributed to a BlackBasta ransomware affiliate adopting Pikabot post the FBI-led Qakbot takedown. However, Pikabot’s activity ceased shortly after Christmas 2023, with version 1.1.19 marking its endpoint.

Mini Shai-Hulud hits openapi-react-query-codegen: 10 malicious npm versions

On August 28, 2026, ten malicious versions of @7nohe/openapi-react-query-codegen were published to npm between 20:00 and 20:21 UTC. The package generates React Query hooks from an OpenAPI schema and draws roughly 150,000 weekly downloads. The latest tag pointed at the malicious 3.0.4 for the duration of the window. Eight of the ten releases carry a multi-stage loader that reaches for cloud, registry, and developer credentials. The attacker needed no stolen npm token and no hijacked maintainer account.