Infoblox Threat Intel reports that nearly 20% of daily gTLD registrations are dropcatch domains—previously registered domains that expired and were re-registered. Threat actors exploit the inherited reputation and lingering connections of these domains to facilitate malware distribution, phishing, and infrastructure hijacking. Threat actors Shady Squirrel and Sable Squirrel are actively using this technique.
Threat Intelligence
18 posts
Drop Something? Don’t Worry, Someone Caught it July 2026 CVE Landscape Insikt Group identified 85 high-impact vulnerabilities in July 2026, a 44% increase from the prior month, with 57 enabling RCE and 60 having public PoC exploits. Threat actors including the Dysphoria botnet, Cloud Atlas, Armored Likho, UAT-7810, and TA488 actively exploited vulnerabilities across IoT devices, email platforms, enterprise applications, and security appliances. Common weakness classes included OS command injection (CWE-78), unrestricted file upload (CWE-434), code injection (CWE-94), and deserialization flaws (CWE-502). Fourteen vulnerabilities were at least five years old, demonstrating continued exploitation of legacy flaws in unpatched environments.
Dealing with AI-Generated Extortion The article describes an emerging extortion trend where threat actors use generative AI to fabricate leaked data and fake victim lists on ransomware leak sites, eliminating the need for actual intrusions. Groups like 0APT and ALP-001 have deployed this tactic, creating real pressure on defenders who must now validate whether extortion claims reflect genuine compromises or fabricated datasets. The recommended defense combines data governance (understanding where and how organizational data is stored) with threat intelligence (assessing the reliability and reputation of threat actors making claims).
Updated Cyber Threat Actor Naming System Google Threat Intelligence Group (GTIG) announced a new unified cryptonym-based naming taxonomy for threat actor tracking, merging the previously separate Mandiant and TAG naming systems. The schema assigns each actor a memorable two-word cryptonym, where the second word denotes category (e.g., origin/motivation such as nation-state attribution or cybercriminal activity), improving cross-platform consistency and reducing reliance on sequential identifiers like APT numbers.
June 2026 CVE Landscape Insikt Group identified 60 high-impact vulnerabilities in June 2026 (a 49% increase from May), with 23 listed in CISA's KEV catalog and 53 having public PoC exploits. The dominant theme was exploitation of externally reachable enterprise applications and appliances by multiple threat actors: StrikeShark chained 13 CVEs to deploy SharkLoader and Cobalt Strike, Lazarus exploited CVE-2025-55182 (React2Shell, CVSS 10.0) to deploy COPPERHEDGE and EtherRAT, APT36 targeted India via Microsoft Office/Windows CVEs, and Qilin ransomware was linked to Check Point gateway exploitation. 25 of the 60 vulnerabilities enabled RCE across 18 vendors, with CWE-22 (Path Traversal) being the most common flaw class.
June 2026 Dark Web Issue Trend Report The June 2026 Dark Web Issue Trend Report documents significant governance instability across major dark web forums. BreachForums faced operator conflicts, retirement announcements, and a clone forum impersonation scheme where operators unlivid and Nullified sold a fake forum claiming to be the original, including forged PGP keys impersonating ShinyHunters. Multiple forums including DarkForums, XSS, and DaMaGeLiB experienced domain suspensions or administrative disruptions, while new forums reusing names of defunct platforms emerged, demonstrating ecosystem resilience.
22nd June – Threat Intelligence Report This threat intelligence report highlights recent data breaches involving third-party vendors, emerging AI threat vectors such as prompt injection and WebSocket abuse, and active exploitation of critical vulnerabilities in Fortinet, Cisco, and Splunk products. Additionally, seasonal phishing campaigns targeting travelers and Amazon Prime members are surging alongside a cross-platform Rust-based crypto clipboard hijacker.
Q1 2026 Cyber Risk Report: Insights from 2.1 Million Malware and Phishing Investigations ANY.RUN's Q1 2026 Cyber Risk Report highlights a significant acceleration in attacker operational tempo, with the median time-to-persistence dropping to 21 seconds and LOTL execution occurring in 16 seconds. The data also shows a marked increase in loader-based attacks, credential theft, and the weaponization of trusted tools via JavaScript LOLBAS techniques, emphasizing the critical need for rapid, behavior-based detection capabilities.
The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It. The emergence of AI-assisted vulnerability discovery tools has significantly compressed the timeline between vulnerability disclosure and active exploitation. To manage the resulting flood of disclosures, security programs must transition from manual triage to intelligence-led prioritization that automatically correlates vulnerabilities with real-world adversary activity at machine speed.
NIST Stopped Scoring Most CVEs. The Signal You Actually Need Was Never in NVD. NIST has significantly reduced its enrichment of CVEs in the National Vulnerability Database (NVD), limiting full analysis to a small subset of critical vulnerabilities. This policy change exposes organizations relying solely on NVD CVSS scores to significant blind spots, necessitating a shift toward threat intelligence-driven prioritization based on real-world weaponization and active exploitation.
Tune In: The Future of AI-Powered Vulnerability Discovery The article discusses the impending 'vuln-pocalypse' driven by AI-accelerated vulnerability discovery and fuzzing. Threat actors, including FANCY BEAR and FAMOUS CHOLLIMA, are increasingly leveraging AI to enhance phishing campaigns and exploit zero-days faster, necessitating a shift toward threat-informed patch prioritization and robust post-exploitation behavioral detection.
From Overwhelmed to Autonomous: Rethinking Threat Intelligence in 2026 The article advocates for a paradigm shift in cybersecurity from manual, reactive threat intelligence to autonomous, machine-speed defense. It emphasizes the need for unified visibility across cyber operations, digital risk, third-party risk, and payment fraud to effectively counter modern, automated threats.
Today, trust is the superpower that makes innovation possible This thought leadership article emphasizes the critical role of digital trust and proactive threat intelligence in fostering economic growth. It highlights the partnership between Recorded Future and Mastercard and underscores the need for enhanced public-private collaboration to address rising cyber threats, particularly noting the surge of ransomware incidents in Latin America.
AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation? The integration of AI into vulnerability research is scaling up existing challenges for defenders by increasing the volume of vulnerability reports and shrinking the time-to-exploit from days to hours. While AI currently augments skilled operators rather than enabling mass low-skill exploitation, organizations must adopt automated, exposure-based prioritization and accelerated patching to manage the growing noise and mitigate high-impact threats.
4 Essential Integration Workflows for Operationalizing Threat Intelligence The article outlines strategies for operationalizing threat intelligence by integrating it into existing security stacks. It highlights four essential workflows—IOC enrichment, vulnerability prioritization, autonomous threat operations, and watch list automation—to elevate cybersecurity maturity from reactive to autonomous.
A New Way to Buy Recorded Future: Solutions and Packages Built for the 2026 Threat Landscape Recorded Future has announced a restructuring of its threat intelligence platform into four core solutions and three tiered packages (Core, Professional, Elite) designed to address the evolving 2026 threat landscape. The new model emphasizes unlimited user access and integrations to operationalize intelligence across cyber operations, digital risk, third-party risk, and payment fraud domains.
Third-Party Risk Is an Intelligence Operation. It's Time We Treated It Like One. The article advocates for an intelligence-driven approach to third-party risk management, arguing that static security ratings are insufficient against modern supply chain threats. It highlights the necessity of integrating external hygiene data with real-time threat intelligence to proactively detect vendor compromises such as ransomware extortion and credential leaks.
Case Study: When Forum Disruption Reshapes the Ransomware Market The disruption of a major cybercrime forum has led to a fragmented ransomware market, prompting groups like Nova RaaS to artificially inflate their perceived status. Despite aggressive recruitment and branding efforts, structural indicators reveal Nova's operational scale remains far below established market leaders.