Herkese selam, Path Traversal zafiyeti hakkında bir medium yazısı yazdım. Aşağıya linki bırakıyorum, umarım güzel olmuştur. Geri dönüşlerinizi bekliyorum.
https://t.co/jRvJpRt8sr
🦉 NEW CTI CHALLENGE: Glass House
A loader called Chimera is dropping infostealers across client networks. Who runs it? The sample was built to mislead, and one indicator is a false flag planted to frame the wrong person.
🔵 Recover the real indicators from build metadata, decode the config
🔵 Cluster and follow the funds by hand to the cash-out
🔵 Separate real leaks from deception, then call attribution with a defensible confidence level
Difficulty: Hard. Role: CTI.
Can you tell the real trail from the trap? 👉 https://t.co/Hy6UqLtZgY
Cyber Threat Intelligence for Beginners 💙
#CTI #ThreatIntel #Attribution
🦉 New on the blog.
In 2025 one of the most prolific ransomware groups on earth went from 700+ named victims to zero in a matter of months. The market barely noticed.
RansomHub went dark on 31 March 2025 and its affiliates simply moved. Akira, Qilin, Safepay and DragonForce grew to absorb them within weeks. New banner, same hands on the keyboard.
That is what RaaS actually is. A franchise, not a malware family. The operators write it, the affiliates deploy it, and the affiliates now set the terms.
Meanwhile leak site victims rose 44% in 2025 while payments stayed flat near $850M, and a growing share of these groups don't encrypt anything at all.
Full breakdown 👉 https://t.co/z9OOavXqAW 💙
#CTIAcademy #ThreatIntel #Ransomware
In 2025 a threat group went from one phone call to the IT help desk to full domain administrator access in roughly forty minutes. No malware. No exploit. No vulnerability. Mandiant documented it in M-Trends 2026, and the caller used four psychological levers in about ninety seconds.
Nothing in the security stack was defeated, because nothing in the security stack was engaged.
Key points:
Verizon's 2026 Data Breach Investigations Report found the human element in 62 percent of breaches, and Palo Alto Networks recorded social engineering as its leading initial access vector at 36 percent of incident response cases.
Helpfulness is the structural problem. Service desks and finance teams are hired to help, so an attacker with a plausible problem is not fighting instinct, they are riding it.
AI lowered the cost of delivery, not the psychology. Mandiant's assessment is that most 2025 breaches still came from weak identity verification and inconsistent MFA, not from AI.
What holds is friction that cannot be talked around: out of band verification with no urgency exception, hardened help desk resets, and phishing resistant authentication such as FIDO2 and passkeys.
An audio deepfake of the LastPass CEO failed for two reasons unrelated to the voice: it arrived through the wrong channel, and it manufactured urgency. Both tells survive even when the voice is perfect.
https://t.co/s5RH1IQ0AR
#ThreatIntelligence #SocialEngineering #CyberSecurity #CTI #InfoSec
DOUBLECUP: ClickFix is now sold as infrastructure, and the payload arrives as a cached image
Published research documents a Russian language loader-as-a-service operation tracked as DOUBLECUP, active since early June 2026 and found through an open directory on the operation's own license panel.
The lure is familiar. The delivery is not. Nothing arrives that a user would recognise as a file. The code sits inside an ordinary PNG the browser caches like any other page asset, and it is pulled back out of that cache on the host.
Technical findings:
Lure pages impersonate CRM login and verification flows for NetSuite, Odoo, HubSpot and Salesforce, and the ClickFix step is framed as routine verification.
The first stage causes a steganographic PNG to be cached, and the second stage is extracted from that image on the host. No attachment, no visible download, no second domain to block.
The second stage derives its decryption key from the victim's public IP address. That is environmental keying (T1480.001), and an offline sandbox detonation yields nothing.
The service is licensed. Operators bring their own lure pages and receive a panel with a payload builder that configures the domain, the steganography method and the execution chain.
CountLoader 4.5p is delivered in Windows and macOS variants. It patches PE metadata on copied system binaries to defeat name based rules, and enumerates 48 hardcoded cryptocurrency wallet extension IDs across 45 browsers.
DeviceManager, a previously undocumented modular Python RAT, resolves its C2 address from an Ethereum smart contract using EtherHiding, then communicates over DNS tunnelling under a spoofed https://t.co/CYHiWqA1iz apex. A smart contract cannot be seized the way a domain can.
Persistence runs on 25 and 10 minute scheduled task cycles under names imitating Google and Microsoft update services, each process alive for seconds.
For context, ESET recorded a 108 percent increase in fake CAPTCHA detections between H2 2025 and H1 2026, and Microsoft Defender Experts attributed 47 percent of the initial access cases it handled in 2025 to ClickFix. DOUBLECUP is what that technique looks like once a commercial supply chain forms behind it.
Recommendations:
Treat the browser cache as an execution source, and alert on command line utilities reading files inside browser cache directories.
Hunt scheduled tasks with 10 and 25 minute recurrence, and compare a running process's PE OriginalFilename against its file name on disk.
Alert on blockchain RPC calls from hosts with no blockchain workload, and on high volume DNS TXT queries with long encoded labels.
The user side control has not changed. No legitimate site, CAPTCHA or login page will ever ask anyone to paste a command into the Run dialog or a terminal.
Sources and the full technical analysis are in the comments.
#ThreatIntelligence #ClickFix #CyberSecurity #MalwareAnalysis #CTI #CTIAcademy
Most people treat SOC vs CTI as a fork in the road. It isn't.
The SOC consumes threat intelligence. CTI produces it. Two seats on the same team, and the SOC is the most common on-ramp to the other one.
The real split is timescale. A SOC lives in minutes and hours: SIEM, EDR, SOAR, a queue that never empties, fifty tickets on a busy shift. Threat intelligence lives in days and months: TIP, OSINT, MISP, ATT&CK, and a single threat actor you might research for weeks.
Mindset decides it, not the job title. If you make good calls under pressure and learn by doing, the SOC hands you a firehose of hands-on experience faster than anything else in security. If you'd rather sit with an ambiguous problem for weeks and write up what you found, that's CTI, and finding real-time alert pressure draining is a signal, not a weakness.
Then the part recruiter pages skip. ISC2's 2025 workforce study found 48 percent of security professionals exhausted trying to keep up with threats, and a widely cited Tines survey put SOC burnout at 71 percent in 2022 and 63 percent in 2023. The answer isn't avoiding the SOC. It's treating Tier 1 as a launchpad and planning your move within twelve to twenty-four months.
Meanwhile automation is eating the mechanical floor of both jobs. Tier 1 triage workload is down roughly a fifth, CTI collection runs at a scale no human team matches, and the judgment sitting on top of both is worth more than it was.
Full breakdown: the tiers, the SOC to CTI path, the burnout data, and how AI is reshaping the entry level.
Link in the reply.
#ThreatIntelligence #CyberSecurity #CTI
New Mission Live: Hidden API Discovery
A regional data platform consultancy runs a quiet, professional looking marketing site. A landing page, a services list, a team section, a client login. Nothing on the surface looks wrong.
But somewhere between the homepage and the code that renders it, the company left a thread hanging. Pull it, and the whole internal directory comes with it: staff accounts, an administrator with the safety switch turned off, service credentials, and the client book sitting behind them.
Here is what makes this mission different: you are not breaking anything. Not one login. Not one exploit. Your job is to map what this organisation has already handed to the open internet, starting from a single domain name and ending with a written picture of everything an outsider could reach without ever authenticating.
That is the uncomfortable part of external attack surface work. The most damaging findings are rarely the ones someone had to force open. They are the ones that were never closed.
One domain in. A full exposure map out.
How much can you see before you ever log in? The mission link is in the comments below.
#ThreatIntelligence #CTI #CyberSecurity #OSINT #AttackSurface #APISecurity #ReconOps #CTIAcademy
New Mission Live: Operation Iron Veil
A regional banking outlet was quietly redirecting its readers through a hidden iframe. Nobody clicked anything. The compromise happened in silence.
In our newest mission, you step in as the analyst who has to unravel the entire chain: from that silent iframe load, through a gated delivery kit and a Windows dropper, into a second-stage payload, and all the way to the operators' own C2 panel. From there you pivot through DNS records and an underground forum to put a name to the actor behind the campaign.
This is also a first for CTI Academy: Operation Iron Veil is our first mission that puts you behind a VPN before you touch the infrastructure, bringing your workflow one step closer to how real investigations actually run.
Full kill chain. Real pivots. Real attribution.
Think you can trace it back to the source?
The mission link is in the comments below.
#ThreatIntelligence #CTI #CyberSecurity #DFIR #MalwareAnalysis #ThreatHunting #CTIAcademy
The fastest way to get quietly cut out of an information sharing community is not leaking something. It is mislabeling it.
Mark a report TLP:RED when it should have been TLP:GREEN and the intelligence becomes useless to everyone who needed it. Mark it TLP:GREEN when the source meant TLP:AMBER and a trust relationship built over years is gone.
TLP is also one of the most consistently misexplained topics in threat intelligence. CTI Academy's latest article is a current and accurate reference for TLP 2.0.
Key points:
- There are four labels, not five: TLP:RED, TLP:AMBER, TLP:GREEN and TLP:CLEAR. TLP:AMBER+STRICT is a restriction a source applies to AMBER, not a separate label. Analysts say five in conversation, but policy and tooling should follow the formal four.
- TLP:WHITE was retired in August 2022 and replaced by TLP:CLEAR. Seeing TLP:WHITE in a current document is a reliable signal that the document or its author's training is stale. TLP:BLUE was never part of the standard at any version.
- The difference between GREEN and AMBER is structure, not sensitivity. GREEN travels along informal trust relationships. AMBER travels along formal ones, and under TLP 2.0 includes the recipient's clients by default, so that service providers and national teams can warn those who need to protect themselves.
- TLP is not a classification scheme and is not legally binding. CISA states this plainly. It operates on community trust and reciprocity, which is why violating it costs access rather than legal exposure.
- The machine-readable gap is the part most guides omit. STIX 2.1's predefined marking definitions still reflect the older label set, so TLP:CLEAR and TLP:AMBER+STRICT fall outside the core specification and require an OASIS extension. MISP users have had bundles carrying TLP:CLEAR rejected outright, and an OpenCTI connector issue opened in February 2026 documents STIX 2.1 export validation failing on TLP:AMBER+STRICT.
- Over-marking is the most common failure and the most damaging. Defaulting everything to AMBER or RED feels prudent, but it defeats a protocol designed to increase sharing. Intelligence that nobody is permitted to act on protects nobody.
Marking is a dissemination decision, not administrative housekeeping, and it is one of the first things a receiving organization notices about a product.
The full breakdown, including the formatting rules and the seven mistakes analysts actually make, is available below.
https://t.co/TYAgBv2x1L
#ThreatIntelligence #CTI #CyberSecurity #InfoSec #IncidentResponse
Qilin Ransomware Operators Are Using CVE-2026-0257 as an Initial Access Vector
Arctic Wolf Labs has documented multiple June 2026 intrusions in which the PAN-OS GlobalProtect authentication bypass CVE-2026-0257 (CVSS 7.8) served as the entry point and ended in domain-wide Qilin ransomware deployment. Palo Alto Networks published the advisory on May 13, 2026, and CISA added the flaw to the KEV catalog on May 29 with a three day remediation deadline for federal agencies.
The relevant point is not the CVE number. It is that an optional convenience feature was left holding a trust boundary.
Technical findings
- Exploitation requires three conditions: an exposed GlobalProtect portal or gateway, authentication override cookies enabled, and reuse of the cookie certificate elsewhere, for example on the portal HTTPS service.
- The appliance decrypts the override cookie without verifying any signature, so an attacker who reads the public key from the TLS certificate chain can forge a cookie and authenticate as admin (CWE-565).
- Sessions were established from hosts self-identifying as kali, with several addresses appearing both as exploitation sources and as later session origins.
- Credential access followed inside the same intrusions: LSASS was dumped via rundll32.exe and comsvcs.dll with output written to a .odt file, and the domain database was extracted with ntdsutil.exe using the IFM method.
- The payload was staged as C:\PerfLogs\win.exe, executed through PsExec over administrative shares and gated behind a runtime password, which complicates sandbox analysis and triage.
- Event logs were cleared with a PowerShell routine that enumerates every channel containing records, not only Security and System.
Assessment
Tradecraft ranged from encryption only operations to full double extortion with exfiltration to MEGA over Rclone, consistent with several affiliates sharing a single access vector. Arctic Wolf assesses with moderate confidence that the activity is ongoing. Qilin posted 338 victims in Q1 2026 according to Check Point Research, leading leak site volume for a third consecutive quarter.
Recommended actions
- Patch affected PAN-OS and Prisma Access versions, then terminate active GlobalProtect sessions, since patching alone does not invalidate an established session.
- If exploitation is suspected, treat the domain as compromised and rotate credentials, including KRBTGT twice.
- Hunt GlobalProtect logs from May 17, 2026 onward for cookie based authentication from hosting provider address space.
- Block execution from C:\PerfLogs\ and alert on Windows Event ID 1102.
Sources
- Arctic Wolf Labs: https://t.co/0DGSxTg59A
- Palo Alto Networks: https://t.co/cSTEX1Z5dJ
- The Hacker News: https://t.co/OajO172MfB
#ThreatIntelligence #Ransomware #CyberSecurity #VulnerabilityManagement #CTI
¡CAMPEONES DEL MUNDO! Enhorabuena, España. 🇪🇸
The final whistle went last night. The fraud infrastructure built around this World Cup did not go with it.
Ticket scams, cloned pages, resale channels and phishing kits do not retire when the trophy is handed over. They pivot. Refunds, memorabilia, "last-minute inventory", the next event.
🔍 Today's mission on CTI Academy is Operation TURNSTILE.
Our dark web monitoring flagged a cluster of posts on NullBase targeting World Cup 2026 fans, World Cup 2026 infrastructure and World Cup ticket buyers. You step in as the threat intelligence team.
Work the forum. Identify every distinct actor. Then follow each thread wherever it leads: off-platform channels, external code repositories, fake sites. By the end you deliver the full picture. Who they are, what they are selling, how it connects, and what the ATT&CK mapping looks like.
⚠️ The forum is a simulation. The tradecraft you'll be profiling is not.
⏰ And the clock is already running: solve the mission within the next 13 hours and you take home bonus XP on top of your solve.
Solve Today: https://t.co/4idiztLsfD
#ThreatIntelligence #CTI #CyberSecurity #OSINT #WorldCup2026
Three months. That's how long an intruder lived inside NovaCure Therapeutics' research network before anyone noticed.
The entry point was a single spear-phishing email. From there: quiet lateral movement through the research segment, straight toward proprietary COVID-19 vaccine development data. When the SOC finally caught the unauthorized access, containment was only half the problem.
🔍 The other half: who is behind it?
That case is Operation Dark Horizon, today's mission on CTI Academy. You step in as the threat intelligence team. Work the evidence, map the TTPs against real APT tradecraft, and build an attribution call you can defend in front of leadership.
⚠️ The company is fictional. The tradecraft you'll be profiling is not.
⏰ And the clock is already running: solve the mission within the next 15 hours and you take home bonus XP on top of your solve.
Solve Today: https://t.co/4idiztLsfD
There is no exploit in a ClickFix attack. No malicious attachment, no drive-by download, no vulnerability. The victim runs the malware themselves, copying a command off a web page and pasting it into their own machine, convinced they're fixing a problem.
Microsoft attributed 47% of all initial access intrusions it tracked in 2025 to this one technique.
The trick is an inversion. Traditional social engineering has to convince you to do something unusual and risky: open this attachment, enable these macros, wire this money. ClickFix asks you to do something that feels routine, even protective. Prove you're human. Update your browser. Fix the page that failed to load.
Underneath the lure it's a clipboard hijack. JavaScript on the page silently writes the attacker's command to your clipboard while showing friendly instructions: press Win+R, paste, Enter. You think you're pasting a verification step.
And it doesn't defeat your security stack, it walks around it. Email filters see no attachment. EDR sees a user voluntarily opening PowerShell, which happens all day long. The network sees a normal web request. From the machine's point of view, the authorized user did all of it deliberately.
The lure changes constantly. The chain never does: arrival, lure page, clipboard poisoning, user execution, payload, persistence. Chase individual lures and you're always a step behind. Understand the chain and you catch the whole family.
It's not a novelty anymore either. ESET measured a 500%+ surge in H1 2025. It's gone cross-platform, including macOS via the native Terminal. Turnkey kits reportedly sell for ~$800 with advertised conversion rates near 60%, and one 2026 campaign was tied to 149,000+ confirmed infections.
The uncomfortable part: awareness isn't enough on its own. revel8's 2026 simulation research found that even where the mechanism is widely known, contextual lures still pulled interaction rates above 10%, and above 23% for high-trust themes like Microsoft Teams.
What actually works: disable the Run dialog via GPO where it isn't needed, enforce PowerShell Constrained Language Mode and app control, and hunt the behavior (a browser, Explorer, or terminal spawning PowerShell with encoded args) instead of the payload of the week.
And one rule, taught until it's reflex: no legitimate website, CAPTCHA, or software update will ever ask you to copy a command and paste it into the Run dialog, a terminal, or the Explorer address bar.
Full breakdown, three real campaigns dissected, FileFix, detections, IOCs:
https://t.co/v5NwKOiuHI
#ThreatIntelligence #ClickFix #CTI
Telegram is not the dark web. No Tor, no onion routing, no hidden service. It's a mainstream app you already have open on your phone. That is exactly why so much of cybercrime moved there.
The friction that used to define the underground, the Tor browser, the reputation you had to grind, the escrow you had to trust, got replaced by instant channel creation, subscription malware, and bots that will sell you stolen data in the time it takes to send a message. Practitioners call it "dark web lite."
The ecosystem runs in four layers. Communication at the base. Above it the marketplace: stealer logs, leaked databases, carding, corporate access. Then automation, which is what actually separates Telegram from a static forum. At the top, amplification: extortion crews broadcasting victims with countdown timers.
Automation is the part people underestimate. A buyer doesn't scroll listings, they query a bot. Send a domain, get a stolen-record count back in seconds. No skill required.
And OTP bots are the defining threat of 2026. The attacker already has your password from a breach or a stealer log. The bot calls you, impersonates your bank, and socially engineers you into reading back the one-time code. Sold as subscription SaaS with pricing tiers, customer support, refund policies, and update logs announcing new bank targets. Intel 471 documented fees from tens to hundreds of dollars a month, with one tool advertising ~80% success when the victim answers. The FBI logged 5,100+ account takeover complaints in 2025, losses over $262M.
One rule worth repeating: your bank will never call and ask you to read back a code you just received. SMS OTP is not a strong second factor anymore.
"But Telegram cracked down." It did. After Durov's arrest, millions of channels were removed through 2025, and the two biggest Chinese-language guarantee markets, Huione and Xinbi, were shut down after Elliptic traced $35B+ in transactions between them.
It didn't empty the shelves. Backup channels are pre-created with audiences preloaded and reconstitute within hours under the same brand. Request-to-join gating blocks automated moderation. Anonymous numbers bought through Fragment make the IP-and-phone disclosure policy useless. Enforcement changed behavior, not allegiance.
Why this is a job and not just a horror story: credentials and access are advertised days or weeks before they're weaponized. Query the log bots for your own domains and you can find your exposure before someone buys it.
Full breakdown, with real redacted captures from active channels:
https://t.co/5SNapxSrqa
#ThreatIntelligence #CTI #Telegram
https://t.co/mMayXrWEkO üzerinden Vulnerabilities, Ransomware, Data Breaches, Supply Chain Attack, Malware ve Phishing kategorilerinde ücretsiz feed alabilirsiniz. Siber güvenlik gündemini özet ve ilişkili tehdit verileriyle birlikte takip edebiliyorsunuz. Özellikle CTI tarafında takip edilecek kaynak olarak kullanılabilir
🔴 CRITICAL | Twill Typhoon, a China-linked threat actor, has been conducting cyberattacks against organizations in Japan and the Asia-Pacific region since late September 2025
#apt#TwillTyphoon#cybersecurity
https://t.co/SuGqZ1zl4v
🔴 CRITICAL | Threat actors have been observed exploiting CVE-2026-44338, a critical authentication bypass vulnerability in the PraisonAI open-source multi-agent orchestration framework, within four hours of i…
#vulnerability#CVE202644338#cybersecurity
https://t.co/lOBAdGi6gL
🔴 CRITICAL | The Nitrogen ransomware group has claimed responsibility for a cyberattack on Foxconn's North American facilities, which the company confirmed affected some operations
#ransomware#Nitrogen#cybersecurity
https://t.co/GSQeywN9I4
🟠 HIGH | CERT Polska coordinated the disclosure of two critical vulnerabilities, CVE-2025-68420 and CVE-2025-68421, affecting Comarch ERP Optima software
#vulnerability#CVE202568420#CVE202568421#cybersecurity
https://t.co/CozOuiOcvd
Today in Cyber is live.
Cybersecurity news is everywhere. Hundreds of stories every day.
We gather them, summarize them, and rate them by how much they actually matter.
One place. Clear language. Free.
https://t.co/yOPna42jBG