Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: security.com Clear filter
ToolShell Used to Compromise Telecoms Company in Middle East | SECURITY.COM

3w ago · security.com

China-based threat actors exploited the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in the Middle East and multiple government agencies globally shortly after the patch was released in July 2025. The attackers deployed backdoors such as Zingdoor and ShadowPad, used DLL sideloading techniques, and leveraged tools like KrustyLoader and Sliver for post-exploitation. Activities indicate espionage motives, with credential theft and lateral movement observed across compromised networks.

16 IoCs 8 Actors 3 Malware
Ukrainian Organizations Still Heavily Targeted by Russian Attacks | SECURITY.COM

3w ago · security.com

Russian-linked attackers continue to target Ukrainian organizations with a focus on espionage and persistent access. The intrusions involved the use of webshells, living-off-the-land tactics, and minimal malware deployment to harvest credentials and sensitive data. Techniques included memory dumping, registry exfiltration, and disabling security tools, indicating a highly skilled and stealthy threat actor.

27 IoCs 1 Actors 1 Malware