# Threat Intelligence

## The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data

## Iran-Linked Operators Suspected in ATG Breaches

## The cPanel Situation Is…

## Oluomo: Microsoft OAuth AiTM Phishing Using a Naturalization-Form Lure

## Rhadamanthys and the Limits of Private Sector Operations

## Iranian-Affiliated APT Targeting of Rockwell/Allen-Bradley PLCs

## Hackers Are Attempting to Turn ComfyUI Servers Into a Cryptomining Proxy Botnet

## Cutting Through the Noise: A Technique-Based Approach to Hunting Web-Delivered Malware

## Under CTRL: Dissecting a Previously Undocumented Russian .Net Access Framework

## Exposure Brief: Iranian-Linked Wiper Attack on Global Medtech Firm Stryker

## NetSupport Manager: Tracking Dual-Use Remote Administration Infrastructure

## Hunting Cameras in the Dark: Finding Internet Cameras Before Adversaries Do

## ResidentBat: Belarusian KGB Android Spyware at Internet Scale

## Vshell: A Chinese-Language Alternative to Cobalt Strike

## Odyssey Stealer: Inside a macOS Crypto-Stealing Operation

**Where Internet scanning becomes threat intelligence:** Practitioner-led cyber threat research on adversary infrastructure, malware, exploited vulnerabilities, and the trends shaping real-world security decisions.
