Threat Research

In-depth threat intelligence and security research from Palo Alto Unit 42, Cisco Talos, Mandiant, Check Point, CrowdStrike, and other leading intelligence labs.

▤ Subscribe to RSS · Search Threat Research → · Full Intel Platform →
CRITICAL Full article

Thus Spoke…The Gentlemen

Key Points Introduction The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. Its operators advertise t

CRITICAL Full article

11th May – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, t

CRITICAL Full article

The State of Ransomware – Q1 2026

Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collect

LOW

C/C++ checklist challenges, solved

We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples: a deceptively simple Linux pin

LOW Full article

4th May – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 4th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Medtronic, a gl

LOW

Extending Ruzzy with LibAFL

LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims im

CRITICAL Full article

VECT: Ransomware by design, Wiper by accident

Key Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cyber

MEDIUM Full article

27th April – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vercel, a fr

LOW

Trailmark turns code into graphs

We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metad

CRITICAL Full article

20th April – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com,

CRITICAL Full article

13th April – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Los Ange

HIGH

Mutation testing for the agentic era

Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures

Get Deeper Threat Research Intelligence

The CyberHawk platform goes far beyond news. Scan indicators, track active campaigns, monitor infostealer feeds, and access a complete analyst toolkit — all free to join.

IOC Scanner — 3.6M+ indicators
Live IOC Feed — filterable threat data
Infostealer Intelligence — live cred logs
Live Threat Map — real-time attacks
MISP Threat Feeds — CIRCL, Feodo, more
GitHub Arsenal — security tools library
Security Blog — deep-dive research
Video Courses — training and education
SOPs — SecOps procedures
Analyst Library — references and toolkits