What do the Wu-Tang Clan and Barney have in common? ๐๐ฆ
Theyโre both featured on this yearโs Threat sounds playlist!
Every year, the Red Canary team collaborates to pair the top 10 threats and techniques from our Threat Detection Report with a specific track. Thanks to community suggestions, this yearโs list is our most diverse yetโfrom hip-hop legends to childhood classics.
Whether you're hunting threats or just clearing your queue, weโve got your soundtrack covered.
๐ง Listen to the full playlist and download the report here: https://t.co/TOBGl6OYZj
The 2026 Threat Detection Report is packed with brand-new sections on the AI trends weโre seeing in the wild. ๐ค๐ก
From AI-powered threats to AI infrastructure risks, these are the priorities every security leader needs to prioritize.
Our experts break down everything youโll find in this year's report right here ๐ https://t.co/OiZf7Rm6EC
If youโre waiting for a breach to learn how adversaries move, youโre already behind. ๐
Weโve crunched the numbers, analyzed the latest techniques, and built the ultimate guide to keeping your environment safe.
The 2026 Red Canary Threat Detection Report is dropping soon! https://t.co/2DqSEmS1rO
In June of 2025, @NBCNews published its investigation into Rwanda's secret war in the DRC. At the time of publication, Rwanda was at the table for US-backed peace negotiations for a conflict they had never admitted to taking part in.
Now, we're starting to see that admission๐งต
What a year 2025 has been! From relentless threat detection to excitedly joining the Zscaler family, it has been a busy year for the Red Canary team.
We're looking back at the most beloved and informative content we brought you, the cybersecurity community, throughout 2025 in this "best of" list.
Explore our top picks here โก๏ธ https://t.co/pvN21tC92Q
The "Sticky Bandits" of cybercrime are out there waiting for an opportunity to wreak havoc. Your cloud security strategy needs a bit of Kevin McCallister's legendary proactive defense!
โก๏ธ Click here before your cloud gets hit with a paint can: https://t.co/xx3Ia8uCRx
The @CISAgov is strongly encouraging organizations to patch a critical-severity Windows Server Update Services (WSUS) vulnerability (CVE-2025-59287) after adding it to its catalog of Known Exploited Vulnerabilities (KEV Catalogue). On servers with WSUS Server Role enabled and ports open to 8530/8531, adversaries can leverage specially crafted requests to exploit a deserialization of untrusted data vulnerability that allows for remote code execution. This can lead to PowerShell and Windows Command Shell executing base64 encoded commands designed to enumerate users and network information on affected endpoints.
While Microsoft has issued guidance for mitigating this vulnerability, including releasing an out-of-band security update for impacted Windows Server versions, some organizations may not be able to patch immediately.
Red Canary has detected post exploitation activity related to this vulnerability through the following detection analytics:
๐๐๐ฎ๐ฌ๐ ๐จ๐ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐จ๐ฆ๐ฆ๐๐ง๐ ๐ฌ๐ก๐๐ฅ๐ฅ ๐๐จ๐ซ ๐๐ฑ๐๐๐ฎ๐ญ๐ข๐จ๐ง
Security teams could detect this activity by looking for ๐๐ข๐.๐๐ญ๐ being spawned from the Windows Server IIS worker process (๐ฌ3๐ฌ๐ฅ.๐๐ญ๐) or the WSUS service binary (๐ฌ๐จ๐ช๐จ๐จ๐๐ง๐ซ๐๐๐.๐๐ญ๐), with a /๐ command that starts another ๐๐ข๐.๐๐ญ๐ /๐ instance. https://t.co/4QxhnhfgmS
๐๐๐ฎ๐ฌ๐ ๐จ๐ ๐๐จ๐ฐ๐๐ซ๐๐ก๐๐ฅ๐ฅ ๐ญ๐จ ๐จ๐๐๐ฎ๐ฌ๐๐๐ญ๐ ๐๐จ๐ฆ๐ฆ๐๐ง๐๐ฌ
Another detection opportunity involves looking for the use of the shortened encodedCommand flag in ๐๐ค๐ฌ๐๐ง๐๐๏ฟฝ๏ฟฝ๐ก๐ก. Adversaries often try to obfuscate the use of malicious code on an endpoint, wrapping them up for PowerShell to execute. https://t.co/DQYc56Q0kC
Based on all the Easter eggs, we were expecting Taylor's new album to be called "The Life of a SOC analyst." But we're excited for this new era nonetheless! โค๏ธโ๐ฅ
๐ฉโ๐ป Revisit @Susannigans's blog on why Swifties should work in cybersecurity: https://t.co/LsYuxWqMWq
๐ฃ A new color bird threat has hatched!
Mocha Manakin employs paste and run with PowerShell to drop a custom NodeJS backdoor that could lead to ransomware.
โ Read our breaking research for detection opportunities and more technical details on this Red Canary-named threat.
https://t.co/bAxFbBb0FV
Rwanda has never admitted to taking part in the conflict in the DRC that since 2021 has killed thousands and displaced millions. @NBCNews Digital Docs investigation discredits Rwanda's narrative of this conflict and lays bare their hidden invasion.
๐งต with links to watch & read
NBC News analyzed leaked reports, satellite images and interviews to reveal the extent of Rwanda's carefully concealed and high-tech war in the Congo, as the U.S. tries to strike a deal for peace and access to the region's minerals. https://t.co/jdzC4cacbV
#NewsEmmys Nominees for Research โ News:
- Apes (@natgeo)
- Breakdown in Maine @PBS)
- The Cap Arcona | @60Minutes (@CBS)
- Documenting Police Use of Force (@PBS)
- The Hidden Autopilot Data ... (@WSJ)
- K File Investigation in NC Governor's Race (@CNN)
- Starving Gaza (@AJENews)
๐ธ Did you know our annual report has a soundtrack? Read our liner notes to find out which threats and techniques we paired with songs by Taylor Swift, Beyoncรฉ, Phish, and more. https://t.co/Zbl4vDNpht
๐ฅ Full behind the scenes video here: https://t.co/9chFFo1LTn
This is the fifth Threat Detection Report I've worked on, and I'm so proud of the way it has evolved into an evergreen resource that people refer to as they run into cyber threats throughout the year. Don't try to take it in all once! https://t.co/GKjk1SKqlG
The Threat Detection Report is both a timely read and an evergreen resource that practitioners refer to throughout the year. ๐ฒ
Here's what's new in the 2025 edition: https://t.co/nI3FkbBwM6