Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team. Page 5 of 10.

YellowKey and BitLocker Bypass: How Security Teams Should Re-Baseline Stolen-Device Risk
Vulnerabilities2026-06-04

YellowKey and BitLocker Bypass: How Security Teams Should Re-Baseline Stolen-Device Risk

YellowKey made a quiet assumption loud again: encrypted endpoints still need vulnerability intelligence, asset context, and incident workflows. Here is how to respond when a last-resort control becomes a live risk.

9 min readRead
AI-Enabled Device Code Phishing: How OAuth Tokens Became the New Credential Theft Target
Phishing2026-05-10

AI-Enabled Device Code Phishing: How OAuth Tokens Became the New Credential Theft Target

Device code phishing turns a legitimate OAuth flow into a token theft path. Learn how AI-assisted lures, Entra ID abuse, and session token replay change phishing detection in 2026.

10 min readRead
MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface
AI & ML2026-05-09

MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface

Model Context Protocol integrations give agents access to tools, files, and services. That power creates new risks: tool poisoning, prompt injection, overbroad permissions, and untrusted server abuse.

10 min readRead
LLMjacking Explained: How Attackers Abuse Cloud Credentials to Steal AI Compute
Cloud2026-05-08

LLMjacking Explained: How Attackers Abuse Cloud Credentials to Steal AI Compute

LLMjacking combines cloud credential theft with expensive AI workloads. Learn how attackers find exposed keys, abuse model APIs, hide compute costs, and how defenders can detect the pattern.

10 min readRead
Non-Human Identity Security: API Keys, Service Accounts, and Workload Credentials in 2026
Identity2026-05-07

Non-Human Identity Security: API Keys, Service Accounts, and Workload Credentials in 2026

Non-human identities now outnumber users in most environments. Learn how API keys, service accounts, CI tokens, and workload credentials become attack paths and how to govern them.

10 min readRead
OAuth Consent Phishing: Detecting Malicious App Grants Before Data Exfiltration
Phishing2026-05-06

OAuth Consent Phishing: Detecting Malicious App Grants Before Data Exfiltration

OAuth consent phishing tricks users into granting access instead of giving up passwords. Learn how malicious app grants work, which permissions matter, and how to detect abuse early.

10 min readRead
Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond
Malware2026-05-05

Session Token Theft: Why Infostealers Bypass MFA and How Defenders Respond

Infostealers increasingly target browser cookies, session tokens, and refresh tokens. Learn why MFA is not enough, what token theft looks like, and how to detect replay.

10 min readRead
Cloud Control Plane Attacks: Why Identity Is the New Kill Chain
Cloud2026-05-04

Cloud Control Plane Attacks: Why Identity Is the New Kill Chain

Cloud breaches increasingly target the control plane: identities, tokens, policies, APIs, and automation. Learn how attackers move from one credential to full cloud control.

10 min readRead
Security LLM and Agent Workflows: When (and How) to Check Malicious Domains, IPs, and URLs Before Acting
AI & ML2026-05-04

Security LLM and Agent Workflows: When (and How) to Check Malicious Domains, IPs, and URLs Before Acting

AI assistants in SOAR, IDEs, and browser extensions can exfiltrate data or run malicious code if they fetch the wrong link. This guide gives guardrails: schema for tool calls, policy tiers, and where threat intelligence checks belong in the loop.

5 min readRead
Malicious npm Packages: Detecting Open-Source Supply Chain Compromise
Supply Chain2026-05-03

Malicious npm Packages: Detecting Open-Source Supply Chain Compromise

Malicious npm packages use typosquatting, dependency confusion, install scripts, and maintainer compromise to steal secrets and backdoor builds. Learn practical detection and response.

10 min readRead
Malicious Infrastructure Clustering: How Passive DNS, TLS Certificates, and ASNs Reveal Shared Campaigns
Threat Intel2026-05-03

Malicious Infrastructure Clustering: How Passive DNS, TLS Certificates, and ASNs Reveal Shared Campaigns

A single C2 IP is a clue; shared signing patterns and DNS co-occurrence are a map. This guide explains how defenders cluster infrastructure without chasing ghosts—and how to document findings for IR, threat intel, and law enforcement handoffs.

6 min readRead
Compromised Domains in Phishing: When Trusted Sites Become Attack Infrastructure
Phishing2026-05-02

Compromised Domains in Phishing: When Trusted Sites Become Attack Infrastructure

Attackers increasingly host phishing pages, redirects, and malware on compromised legitimate domains. Learn why reputation bypass works and how to detect hidden malicious paths.

10 min readRead
Brand Impersonation and Lookalike Domains: A Practical Monitoring Playbook for Security, Legal, and Fraud Teams
Phishing2026-05-02

Brand Impersonation and Lookalike Domains: A Practical Monitoring Playbook for Security, Legal, and Fraud Teams

Typosquats and homoglyphs are cheap to register and expensive to ignore. Learn how to discover, prioritize, and remove lookalike infrastructure before it harvests credentials or poisons your customers’ trust in search and email.

6 min readRead
DPRK Remote IT Worker Threat: Identity, Insider Risk, and Cloud Access Abuse
Insider Threat2026-05-01

DPRK Remote IT Worker Threat: Identity, Insider Risk, and Cloud Access Abuse

DPRK remote IT worker schemes blend fraud, identity deception, and insider access. Learn how hiring, endpoint, SaaS, and cloud controls can reduce the risk.

10 min readRead
SIEM and SOAR Threat Intelligence Enrichment: Workflows, Field Mapping, and the Metrics That Keep Teams Sane
Threat Intel2026-05-01

SIEM and SOAR Threat Intelligence Enrichment: Workflows, Field Mapping, and the Metrics That Keep Teams Sane

A SOAR playbook without enrichment is a ticket printer. A SIEM with unbounded threat feeds is a bill. Here is a practical way to design enrichment for Splunk, Sentinel, or Elastic-style stacks—what to store, when to run playbooks, and what to report upward.

6 min readRead
Threat Intelligence Risk Scoring: How to Calibrate Reputation, Reduce False Positives, and Defend Your Decisions
Threat Intel2026-04-30

Threat Intelligence Risk Scoring: How to Calibrate Reputation, Reduce False Positives, and Defend Your Decisions

A noisy score is worse than no score. Learn what makes a reputation model trustworthy, how to combine multi-source evidence, and how to communicate uncertainty to your SOC and your executives.

5 min readRead
Proxy, VPN, Tor, and Datacenter IPs: A Decision Matrix for WAF, Fraud, and SIEM Rules (Without Breaking Real Users)
Research2026-04-29

Proxy, VPN, Tor, and Datacenter IPs: A Decision Matrix for WAF, Fraud, and SIEM Rules (Without Breaking Real Users)

Not every "datacenter" IP is malicious, and not every Tor exit is a fraudster. This matrix-style guide helps you combine IP type signals with reputation and product context for safer, explainable security decisions.

5 min readRead
Cloud IP Reputation: What AWS, Azure, and GCP Defenders Should Track in 2026
Cloud2026-04-28

Cloud IP Reputation: What AWS, Azure, and GCP Defenders Should Track in 2026

Cloud IP addresses are shared, recycled, and abused at scale. Learn how to interpret reputation signals, reduce false positives, and align network security with platform-native controls across the three major hyperscalers.

5 min readRead
ASN Reputation for Threat Intelligence: How Autonomous System Intelligence Improves Prioritization and Hunt Programs
Threat Intel2026-04-27

ASN Reputation for Threat Intelligence: How Autonomous System Intelligence Improves Prioritization and Hunt Programs

An IP address is a snapshot; an autonomous system (ASN) is a neighborhood. Learn how to use ASN context safely for triage, fraud, and security operations—without mistaking a giant cloud for a monolithic "bad host".

5 min readRead
Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds
Threat Intel2026-04-26

Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds

Design TIPs and intel pipelines that scale: normalization, confidence scoring, deduplication, API-first delivery, and how to pair platform investments with analyst workflows.

8 min readRead
Building IOC Pipelines: From Raw Indicators to Operational Threat Intelligence in 2026
Threat Intel2026-04-26

Building IOC Pipelines: From Raw Indicators to Operational Threat Intelligence in 2026

A practical engineering guide to building indicator of compromise (IOC) pipelines—ingestion, normalization, deduplication, enrichment, scoring, distribution, and feedback—to turn raw threat feeds into operational defense.

10 min readRead
IOC Enrichment APIs: A Security Operations Guide to Faster Triage, Fewer False Positives, and Measurable ROI
Threat Intel2026-04-26

IOC Enrichment APIs: A Security Operations Guide to Faster Triage, Fewer False Positives, and Measurable ROI

An indicator without context is a ticket without an owner. Learn how IOC enrichment APIs work, which fields SOC teams need at each tier, and how to wire them into case management without building a data swamp.

6 min readRead
Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure
Supply Chain2026-04-25

Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure

Build a modern supply-chain security program: generate SBOMs, map CVEs to components, integrate EPSS and KEV, and coordinate fixes across vendors and open-source maintainers.

8 min readRead
Answer-Engine Optimization for Cybersecurity: How to Get Cited by ChatGPT, Perplexity, and Claude in 2026
Threat Intel2026-04-25

Answer-Engine Optimization for Cybersecurity: How to Get Cited by ChatGPT, Perplexity, and Claude in 2026

Traditional SEO is not enough when users ask large language models for vendor comparisons and step-by-step security guidance. Learn how to structure threat intelligence and security content so AI systems can parse, trust, and cite your brand without hype or ambiguity.

5 min readRead

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.