Skip to main content
Blog

Threat Intelligence Blog

Research, insights, and updates from the isMalicious team.

Malicious PyPI Packages: Detect Supply-Chain Attacks
Supply Chain2026-08-24

Malicious PyPI Packages: Detect Supply-Chain Attacks

Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.

3 min readRead
GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector
Supply Chain2026-08-05

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector

CI/CD pipeline compromises keep recurring across GitHub Actions ecosystems. Learn the detection signals, hardening steps, and enrichment workflow security teams need.

6 min readRead
Arch AUR Rootkit And Infostealer Campaign: Supply Chain Defense Starts With Hash Intelligence
Supply Chain2026-06-15

Arch AUR Rootkit And Infostealer Campaign: Supply Chain Defense Starts With Hash Intelligence

The June 2026 Arch User Repository compromise shows why supply chain security needs package review, file hash reputation, developer credential protection, and fast IOC enrichment.

6 min readRead
Malicious npm Packages: Detecting Open-Source Supply Chain Compromise
Supply Chain2026-05-03

Malicious npm Packages: Detecting Open-Source Supply Chain Compromise

Malicious npm packages use typosquatting, dependency confusion, install scripts, and maintainer compromise to steal secrets and backdoor builds. Learn practical detection and response.

10 min readRead
Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure
Supply Chain2026-04-25

Supply Chain CVE Response: SBOMs, Dependency Risk, and Coordinated Vulnerability Disclosure

Build a modern supply-chain security program: generate SBOMs, map CVEs to components, integrate EPSS and KEV, and coordinate fixes across vendors and open-source maintainers.

9 min readRead
SBOM and Supply Chain Security: What Security Teams Actually Need
Supply Chain2026-03-28

SBOM and Supply Chain Security: What Security Teams Actually Need

Software bills of materials are not paperwork for compliance alone. Learn how SBOMs reduce third-party risk and speed response when a dependency blows up.

2 min readRead
Supply Chain Attack Detection: Lessons from SolarWinds to MOVEit
Supply Chain2026-01-03

Supply Chain Attack Detection: Lessons from SolarWinds to MOVEit

Supply chain attacks have become the weapon of choice for sophisticated threat actors. Learn how to detect compromised vendors, monitor third-party risk, and protect your organization before your suppliers become your vulnerability.

11 min readRead

Expert Threat Intelligence Analysis

Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.

Practical Security Guidance

Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.

Stay Ahead of Emerging Threats

The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.

Subscribe to Our Newsletter

Weekly threat intelligence insights delivered to your inbox.