The Banshee Queen 👑

@cyberoverdrive.bsky.social

#threatintel @Recorded Future | Formerly @PwC GTI | Malware & infrastructure analysis with a side of cyberpunk. 🌃🌌 She/her, support 🏳️‍🌈🏳️‍⚧️✨

North Korea-linked hackers has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the known scope of DPRK’s efforts to access trusted code environments www.nextgov.com/cybersecurit...

Amazon uncovers broad North Korean hacking campaign against open-source software

New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.

nextgov.com

So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

proofpoint.com

Yeah the idea that you have to be very careful and measured when talking about bigots lest you be labeled as “hysterical” etc has been a great boon in the push to renew white supremacy.

NEW: After a purported crackdown on scam compounds last year, researchers now say at least 25 new scamming sites have opened or expanded in Myanmar. Satellite images show trees being razed and land cleared, with large compounds appearing months later

Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere

Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.

wired.com

1/ We just published new research on TAG-195 (“Golden Chickens” / “Venom Spider”), documenting a major evolution of one of cybercrime’s longest-running Malware-as-a-Service ecosystems. We identified 4 previously undocumented malware families, revealing a shift toward modular, operator-driven tooling

TAG-195 Upgrades MaaS Ecosystem with Modular Tools

Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem

recordedfuture.com

Come read TWO @threatinsight.proofpoint.com blogs on Russia state-aligned threat actors doing some funky exploitation over email 🔥 with accompanying NSA/FBI reporting 👾

Saher@saffronsec.bsky.social · 2w ago

Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...

The billionaires have a vision of the future, and in it, many of us are dead. Not because they all want to kill us (some of them want to kill some of us), but because we are simply surplus and expendable in their eyes.

Volexity has published details on a recent incident response investigation involving exploitation of multiple #0day vulnerabilities in SonicWall SMA 1000 series appliances. This full technical breakdown includes vulnerability workflow, malware analysis & IOCs. #dfir #memoryforensics #threatintel

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised multiple of the customer's SonicWall Secure Mobil...

volexity.com

"Pegasus training material describes situations where it may not be possible to attack a target directly [...] NSO Group suggests expanding to 'close-circle infection,' targeting [...] colleagues, friends or family members of the primary target in order to gather information about them indirectly."

Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab

We are presenting here our most complete analysis to date of the Pegasus spyware. This blog post builds on previous technical reports and forensic investigations by Amnesty International’s Security La...

securitylab.amnesty.org

German firm files for insolvency, blames cybercrims who shut down production for 6 weeks. ZEGO's filing adds another name to the short but growing list of companies that say a digital break-in was commercially fatal to their business. From The Register: www.theregister.com/cyber-crime/...

German firm files for insolvency, blames cybercrims who shut down production for 6 weeks

ZEGO-TVZ says the financial fallout from a March cyberattack left shutting its doors as the only option

theregister.com