Interlock ransomware uses hybrid RSA-AES encryption, symlink abuse, and log clearing. See its TTPs and how to detect it in Defender XDR.
Interlock ransomware uses hybrid RSA-AES encryption, symlink abuse, and log clearing. See its TTPs and how to detect it in Defender XDR.
UAC-0050 used phishing, layered archives, and Remote Manipulator System to breach a European bank supporting Ukraine reconstruction.
Learn how correlating Microsoft Teams chats with RMM activity detects social engineering attacks used to gain remote endpoint access.
See how behavioral scoring detects suspicious PowerShell commands, catching obfuscation and encoding that static indicators miss.
Learn how to detect malicious traffic allowed through your firewall despite being flagged, using Fortinet logs and Sentinel KQL.
Learn how attackers abuse Microsoft Teams helpdesk impersonation to gain access, move laterally, and steal sensitive data.
CopyFail, Dirty Frag, and Fragnesia are Linux kernel flaws enabling local root escalation via page cache corruption. Patch now.
Learn how Wizard Cyber detected the Dohdoor backdoor by identifying DNS-over-HTTPS C2 traffic and KQL threat hunting.
Learn how attackers abuse Claude AI through fake installers, ads, and ClickFix lures to steal credentials and deploy malware.
Learn how to detect boot-level persistence in Windows by identifying BCD abuse, bcdedit misuse, and early startup manipulation.
Threat actors exploit SEO poisoning to distribute fake VPN installers, steal credentials, and gain silent access to enterprises.
Learn how ClickFix and HijackLoader deliver DeerStealer via user execution, MSI abuse, and DLL sideloading on Windows.