Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team. Page 4 of 10.

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector
Supply Chain2026-08-05

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector

CI/CD pipeline compromises keep recurring across GitHub Actions ecosystems. Learn the detection signals, hardening steps, and enrichment workflow security teams need.

6 min readRead
Infostealer Log Marketplaces: How Stolen Corporate Credentials End Up for Sale
Malware2026-08-04

Infostealer Log Marketplaces: How Stolen Corporate Credentials End Up for Sale

Stealer-log marketplaces are booming in 2026, trading stolen corporate cookies, passwords, and SaaS sessions that fuel ransomware access and bypass MFA.

6 min readRead
Subdomain Enumeration for Security Teams: Attack Surface Discovery and DNS Reconnaissance
DNS2026-08-02

Subdomain Enumeration for Security Teams: Attack Surface Discovery and DNS Reconnaissance

Subdomain enumeration surfaces forgotten dev servers, dangling DNS, and shadow IT before attackers do. Passive and active recon techniques compared.

6 min readRead
Malicious Browser Extensions Are Stealing Session Cookies: Detection Guide
Malware2026-07-30

Malicious Browser Extensions Are Stealing Session Cookies: Detection Guide

Rebranded browser extensions are harvesting session cookies and OAuth tokens after silent updates. Here is how to detect and respond before EDR ever sees it.

6 min readRead
urlscan.io vs isMalicious: URL Scanning
Threat Intel2026-07-28

urlscan.io vs isMalicious: URL Scanning

urlscan.io captures what a page does; isMalicious tells you if it is malicious. Verdicts, redirect chains, and blocklists compared.

5 min readRead
isMalicious vs GreyNoise: IP Noise Scoring and Threat Intelligence API Compared
Threat Intel2026-07-27

isMalicious vs GreyNoise: IP Noise Scoring and Threat Intelligence API Compared

GreyNoise tags internet background noise; isMalicious adds verdicts, WHOIS, DNS history, and ransomware context. A SOC-focused comparison for triage teams.

6 min readRead
SSO Vishing And SaaS Data Theft: Domain Monitoring Before The Helpdesk Call
Phishing2026-07-13

SSO Vishing And SaaS Data Theft: Domain Monitoring Before The Helpdesk Call

ShinyHunters-style SSO vishing shows how fake login domains, MFA enrollment abuse, and SaaS access can become data theft. Domain monitoring gives defenders early warning.

3 min readRead
Mobile Smishing Defense: URL Scanners And Domain Reputation For July 2026
Phishing2026-07-12

Mobile Smishing Defense: URL Scanners And Domain Reputation For July 2026

Mobile phishing keeps gaining operational relevance. Security teams need URL scanning, domain reputation checks, DNS pivots, and employee reporting workflows built for SMS and chat.

4 min readRead
China Edge Device Campaigns: Passive DNS And Certificates For Early Warning
Threat Intel2026-07-11

China Edge Device Campaigns: Passive DNS And Certificates For Early Warning

Dutch intelligence warnings about Chinese cyber capability reinforce a practical defense priority: monitor edge devices, VPNs, routers, DNS history, and certificate reuse.

3 min readRead
When Vulnerability Exploitation Overtakes Credentials: CVE Prioritization In 2026
Vulnerabilities2026-07-10

When Vulnerability Exploitation Overtakes Credentials: CVE Prioritization In 2026

Verizon DBIR reporting highlights vulnerability exploitation as a top breach path. CVE Watch, KEV, EPSS, and exposure context help teams patch what attackers actually use.

3 min readRead
Shadow AI Data Leak Defense: Monitor Domains, URLs, And Unsanctioned AI Apps
AI & ML2026-07-09

Shadow AI Data Leak Defense: Monitor Domains, URLs, And Unsanctioned AI Apps

Shadow AI has become a governance and data leakage issue. Security teams need discovery, DNS visibility, sanctioned app controls, and domain monitoring around AI tool usage.

3 min readRead
Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows
AI & ML2026-07-08

Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows

Anthropic mapped AI-enabled cyber activity to MITRE ATT&CK and found gaps around autonomous orchestration. SOC teams need AI summaries tied to evidence, not unsupported verdicts.

4 min readRead
SOC Alert Fatigue In July 2026: Confidence Scoring Beats More Noise
SOC2026-07-07

SOC Alert Fatigue In July 2026: Confidence Scoring Beats More Noise

Vectra AI research shows alert overload remains a resilience problem. SOC teams need source quality, confidence scoring, enrichment, and SIEM workflows that suppress noise without hiding risk.

4 min readRead
Ransomware Revenue Is Rising: Initial Access Brokers Make Threat Intelligence Urgent
Ransomware2026-07-06

Ransomware Revenue Is Rising: Initial Access Brokers Make Threat Intelligence Urgent

Q1 2026 ransomware revenue reporting points to a mature access market. Defenders need ransomware intelligence, domain monitoring, blocklists, and API enrichment before encryption begins.

4 min readRead
AMOS macOS Infostealer: ClickFix Shows Why Hash Reputation Must Cover Developer Macs
Malware2026-07-05

AMOS macOS Infostealer: ClickFix Shows Why Hash Reputation Must Cover Developer Macs

AMOS and related macOS infostealers are turning social engineering into credential theft. File hash reputation, URL scanning, and domain intelligence help teams respond before stolen tokens spread.

3 min readRead
BlueHammer Defender Exploitation: July 2026 Patch SLA For Windows Fleets
Vulnerabilities2026-07-04

BlueHammer Defender Exploitation: July 2026 Patch SLA For Windows Fleets

BlueHammer coverage shows why endpoint patching, CISA KEV context, CVE Watch, and IOC enrichment have to work together when local privilege escalation becomes ransomware tradecraft.

3 min readRead
Arch AUR Rootkit And Infostealer Campaign: Supply Chain Defense Starts With Hash Intelligence
Supply Chain2026-06-15

Arch AUR Rootkit And Infostealer Campaign: Supply Chain Defense Starts With Hash Intelligence

The June 2026 Arch User Repository compromise shows why supply chain security needs package review, file hash reputation, developer credential protection, and fast IOC enrichment.

6 min readRead
Microsoft June 2026 Patch Tuesday: Turning 206 Vulnerabilities Into A SOC Priority Queue
Vulnerabilities2026-06-15

Microsoft June 2026 Patch Tuesday: Turning 206 Vulnerabilities Into A SOC Priority Queue

Microsoft patched 206 vulnerabilities in June 2026, including publicly disclosed zero-days. Security teams need CVE Watch, KEV context, exploit evidence, and enrichment to avoid patch fatigue.

6 min readRead
CISA KEV Adds Cisco, Chrome, And Arista Flaws: How To Prioritize Active Exploitation
Vulnerabilities2026-06-15

CISA KEV Adds Cisco, Chrome, And Arista Flaws: How To Prioritize Active Exploitation

CISA added Cisco SD-WAN, Google Chromium V8, and Arista EOS vulnerabilities to KEV in June 2026. Here is how SOC and vulnerability teams should turn that signal into action.

6 min readRead
Oracle PeopleSoft Zero-Day: CVE-2026-35273 Shows Why CVE Watch Needs IOC Enrichment
Vulnerabilities2026-06-15

Oracle PeopleSoft Zero-Day: CVE-2026-35273 Shows Why CVE Watch Needs IOC Enrichment

The PeopleSoft CVE-2026-35273 exploitation reports show how vulnerability response, ransomware intelligence, IP enrichment, and incident response must work together.

6 min readRead
Outsider Enterprise Takedown: AI Phishing Infrastructure Is Now A Domain Reputation Problem
Phishing2026-06-15

Outsider Enterprise Takedown: AI Phishing Infrastructure Is Now A Domain Reputation Problem

The FBI, Google, and Black Lotus Labs disruption of Outsider Enterprise shows why AI phishing defense needs URL scanning, domain reputation checks, blocklists, and fast API enrichment.

7 min readRead
Shadow AI Governance: How Security Teams Can Detect Risk Without Blocking Innovation
AI & ML2026-06-04

Shadow AI Governance: How Security Teams Can Detect Risk Without Blocking Innovation

Shadow AI is the new shadow IT: fast adoption, weak visibility, and serious data leakage risk. Security teams need discovery, domain intelligence, policy, training, and monitoring.

8 min readRead
AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action
AI & ML2026-06-04

AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action

AI-enabled threats are being mapped into ATT&CK language, but mapping is only useful when it drives enrichment, detection, triage, and response workflows.

8 min readRead
Cyber Extortion Now Includes Physical Threats: What Incident Response Teams Must Change
Ransomware2026-06-04

Cyber Extortion Now Includes Physical Threats: What Incident Response Teams Must Change

Cyber incidents are no longer always contained to systems and data. As extortion crews add physical threats, responders need ransomware intelligence, safety escalation, IOC enrichment, and executive-ready evidence.

8 min readRead

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.