Report an Incident Become a Partner Careers Contact
Book a Demo
Threat Intelligence, Wizard Cyber

CYBERSHIELD Threat Intelligence Team

Wizard Cyber's first line of defence in proactive threat intelligence. The team is dedicated to the identification, monitoring and analysis of emerging cyber threats, including activity across the dark web, underground forums and threat actor infrastructure. Leveraging advanced threat intelligence platforms, OSINT tooling and adversary tracking methodologies, the team provides actionable intelligence to anticipate attacks before they occur. With expertise in threat actor profiling, TTP mapping aligned to the MITRE ATT&CK framework, and IOC enrichment, it equips clients with the insight needed to fortify defences, mitigate risk and stay ahead of an evolving threat landscape. The team works across Wizard Cyber's security operations centres, each manned around the clock in its own right rather than handing over to the next region. Wizard Cyber has run Microsoft Sentinel since 2019 and is a Microsoft Solutions Partner.

LinkedIn

Written by CYBERSHIELD Threat Intelligence Team

7 articles

Threat Research

Brevo Supply Chain Attack: One API Key, 100,000 Websites

A hardcoded Cloudflare API key let attackers rewrite Brevo's scripts at the edge, pushing ClickFix and a hidden WordPress backdoor to around 100,000 sites.

8 min read
Threat Research

Plugin4Shell: A Zero-Click RCE In Four AI Coding Agents

Four AI coding agents checked out a pinned commit without verifying it landed. A branch named like the hash delivers malicious code, and the pin still looks intact.

7 min read
Threat Research

CVE-2025-55241 – Azure Entra Elevation Of Privilege Via Actor Token Vulnerability

A flaw in Entra ID meant any user account could be escalated to Global Administrator. Patched before disclosure — and still the most instructive Entra bug of the year.

6 min read
Threat Research

Dumping System Secrets While EDR Is Running

Blocking the obvious tool is not the same as preventing the technique. Why SAM, SYSTEM and SECURITY remain reachable with EDR running, and what actually detects it.

8 min read
Threat Research

Weaponizing Screen Savers: A Deep Dive Into SCR File Exploitation

A .scr file is nominally a screen saver and actually a Windows executable. Why that distinction is an attack vector, why detection struggles with it, and how to shut it down.

8 min read
Threat Research

COM Hijacking: Enhancing Red Team Persistence Strategies

A fileless persistence technique that needs no admin rights and leaves almost no forensic trace. How COM hijacking works, why it is hard to see, and the registry telemetry that catches it.

8 min read
Threat Research

Escaping a Docker Container: An Attacker's Perspective

A container is not a security boundary by default. How an over-privileged container becomes a host compromise, which capabilities actually matter, and how to detect and prevent it.

9 min read
Where to start

Talk to the people
who do the work.

A demo against your own estate rather than a canned one, run by an analyst rather than a salesperson.