WhoisXML API is a cyber intel provider that has been gathering, analyzing, and correlating domain, IP, and DNS data for a more secure and transparent Internet.
What if a fake software installer opened the door to a Silver Fox campaign?
#SilverFox impersonated trusted software vendors to deliver malicious installers, primarily targeting China-based operations and Chinese-speaking users. Thanks to @msftsecurity for the 9 network IoCs, expanding which we uncovered 1,570 new artifacts→ 1,474 email-connected domains, 3 additional IPs, 74 IP-connected domains, and 19 string-connected domains.
Download the full report → https://t.co/ss9HOUHwQ0
#Malware #ThreatIntel #Cybersecurity #DNSintel
What can #AI uncover when it connects the dots across #InternetIntelligence?
See how Jake AI investigates bank impersonation attempts, analyzes suspicious domains and homoglyph variants, and adds context using domain and #threatintelligence.
Try Jake AI for FREE: https://t.co/ObeWqPgc9z
#JakeAI #CyberSecurity #BrandSecurity
WhoisXML API is heading to #BSidesGöteborg 2026!
David Hagberg will be there representing WXA, joining the security community for a day of technical talks, shared ideas, and practitioner-led conversations.
Going too? Request to connect: https://t.co/C18NxnWiPe
#BSidesGothenburg #Cybersecurity #InfoSec
Tokyo, the WXA leadership team is coming back.
On Nov. 19, #cybersecurity leaders from across Japan and APAC will come together for new research, real-world cases, and candid discussion on where threat intelligence goes next in the AI era.
Request an invitation: https://t.co/ZGiR3tABQx
#WXATokyoForum #WXATokyo2026 #ThreatIntelligence #CyberSecurity #APAC #DNS
#Jewelbug’s single control panel powered both #cyberespionage and #cryptofraud across the Middle East and Asia.
Thanks to @symantec and Carbon Black Threat Hunter Team for the 27 network IoCs, building on which we uncovered 5,412 new artifacts → 670 potential victim IPs, 5,331 email-connected domains, 3 additional IPs, 4 IP-connected domains, and 74 string-connected domains.
Download report → https://t.co/ZucvWy7SNF
#ThreatIntel #Cybersecurity #DNSintel #ThreatReport
WhoisXML API is joining #HITCON CISO Summit 2026 as a Silver Sponsor — for a day of sharp conversations around #cybersecurity, #threatintelligence, and what’s shaping defense across the region.
@HacksInTaiwan
👉 Request a meeting: https://t.co/C18NxnWiPe
#HITCON2026 #HITCONCISOSummit #HITCONCISOSUMMIT2026 #CISO
What if one #DNS record could uncover a broader web of connected domains?
Reverse DNS Lookup lets security teams start with an SOA, TXT, or CNAME record and find domain names associated with it.
Get Free Instant Access: https://t.co/ebWuMOlmtH
#ReverseDNS#ThreatIntelligence
The Internet doesn’t govern itself — its naming systems, policies, and security are shaped in rooms like #ICANN87, and WhoisXML API will be in Bali for the conversations that move them forward.
Connect with Ching at @ICANN87: https://t.co/C18NxnWiPe
#ICANN#InternetGovernance #DomainNames #ThreatIntelligence
Trump called it “super intelligence” at the UN. Hours later, the domains started piling up.
Our researchers mapped 1,677 superintelligence-related domains registered in September — including 739 on September 22 alone and 752 more over the next five days.
Download Full Report: https://t.co/T86KfY53Hu
#superintelligence #ArtificialIntelligence #ThreatIntelligence #ThreatResearch #DomainIntelligence #DNSIntelligence #CyberSecurity #OSINT #InfoSec
What if #UNC6293, #UNC7005, and #UNC5976 were using fake domains to track and target high-value individuals?
Thanks to @Google Threat Intelligence Group (#GTIG) for the initial threat report and 33 network #IoCs linked to these three Russian threat groups, expanding which we uncovered 2,689 new artifacts → 317 potential victim IPs, 2,494 email-connected domains, 15 additional IPs, 29 IP-connected domains, and 151 string-connected domains.
Download the full report → https://t.co/KeXMURoOda
#ThreatIntelligence #CyberSecurity #DNSIntel #Infosec #CTI #ThreatResearch
WXA Tokyo Forum is back for 2026!
On November 19, we’re bringing #cybersecurity leaders from across Japan and APAC together in Tokyo for an invitation-only executive luncheon on the next generation of threat intelligence.
New research. Real-world cases. Focused discussion.
Request an invitation now: https://t.co/ZGiR3tABQx
#WXATokyoForum #WXATokyo2026 #ThreatIntelligence
Scammers were building #iPhone18 phishing sites before #Apple even unveiled the phones.
@Forbes@happygeek spoke with our Alexandre François (@detectiveDNS) about #phishing sites built weeks in advance, weekend security gaps, and a major red flag: the standard iPhone 18 isn’t even on sale yet.
Read the full piece here: https://t.co/fqpTTBsAmC
#CyberSecurity #ThreatIntelligence #BrandImpersonation #iPhone18Pro #iPhone18ProMax
🚨 August 2026 Domain Activity Highlights: https://t.co/vC4rPQsZBl
We analyzed 11.6M+ new domains:
• 3.0M+ flagged with malicious intent
• 1.097M+ confirmed malicious
See how #TLD trends and attacker behavior are evolving!
#threatintelligence#cybersecurity#domainintel #infosec
WhoisXML API is joining #RightsConContinues 2026!
Alexandre François, Director of Product Marketing / Research & Media Collaboration, will facilitate a table during the Private Sector Meetup.
We’re looking forward to bringing perspectives from our work in Internet infrastructure intelligence and threat research into the wider digital rights conversation.
@rightscon@accessnow
Sept. 22 | 18:45–19:45 CAT
#RightsCon #RightsCon2026 #DigitalRights #ThreatIntelligence
What if #malvertising delivered #malware that security tools had never seen before?
#SourTrade mimicked TradingView, Solana, and Luno to target retail traders and crypto investors. We expanded 96 know #IoCs and uncovered 1,262 new possibly connected artifacts→ 4 #typosquatting groups, 14 likely malicious domains, 348 email-connected domains, 186 IPs, and 728 string-connected domains.
Download the full SourTrade report → https://t.co/TwLuPvocG7
#ThreatIntel #Cybersecurity
WhoisXML API intelligence is now integrated into @MalforsHQ, a modern investigation platform for threat intelligence, #OSINT, and security research teams.
Analysts can enrich investigations with WHOIS, DNS, IP, subdomain, and geolocation intelligence—directly within their investigation graph.
Learn more: https://t.co/jkQGmmlaby
#ThreatIntelligence #CyberSecurity
We’re heading to Bali for the #ICANN87 Annual General Meeting.
Ching Chiao will represent WhoisXML API, bringing 20+ years across #DNS, Internet infrastructure, #cybersecurity, and governance.
Connect with Ching at @ICANN87: https://t.co/C18NxnWiPe
#ICANN#InternetGovernance #DomainNames #ThreatIntelligence
WhoisXML API just added two new ways to control your account: API IP allowlists and per-member usage monitoring. Restrict API access to a list of trusted IP addresses so a leaked key alone can't get anyone in, and see exactly how much each team member's Child API key is using, all at no extra cost. Learn more in: https://t.co/IhPsyyH6Bu
#APIsecurity #DataProtection
One week to CYBR.SEC.CON. 2026. Ed Gibbs and Michael Kaparos are bringing the data—you bring the questions.
Meet them and talk NetFlow, AI, and threat hunting. Request a time to connect at @CybrSecEvents: https://t.co/C18NxnWiPe
#CYBRSECCON#CYBRSECCommunity#InfoSec#NetFlow #ThreatHunting