2026-08-22
- threat intel
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Threat actors increasingly target CI/CD pipelines and developer tools rather than application code directly, exposing gaps in supply chain security. Organizations need comprehensive visibility across the entire software development lifecycle (SDLC) and enforce stringent security controls to defend against these attacks.
Why it matters: Development teams and security leaders must audit CI/CD infrastructure and developer tooling for misconfigurations and access weaknesses, as compromises here can inject malicious code at scale before applications reach production.
- government policy
Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers have called for an investigation into the effects of staffing reductions at the Cybersecurity and Infrastructure Security Agency (CISA). The inquiry aims to determine what operational impacts the cuts have had and whether lost expertise has been adequately replaced.
Why it matters: Security practitioners rely on CISA for threat intelligence, advisories, and incident response guidance; staffing erosion may degrade the government's ability to support private sector defenders and critical infrastructure operators.
- threat intel
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researchers identified 14 trojanized npm packages disguised as calendar and streak utilities that deploy RedC2 4.0, an AI-powered Linux backdoor. The malicious packages execute a bundled binary as a background process upon module load, establishing unauthorized system access.
Why it matters: Developers using these packages from npm repositories face direct compromise of their build environments and production systems; audit your dependencies immediately for these trojanized packages and implement strict software supply chain controls.
- threat intel
Scattered Spider Targets Tech Companies for Help-Desk Exploitation
Scattered Spider, a financially motivated cybercriminal gang, exploits social engineering and phishing to target technology vendors, managed service providers (MSPs), and IT contractors as gateways to breach multiple client networks. Analysis of over 600 domains associated with the group found that 81% impersonate tech vendors using typosquatted domains and phishing frameworks like Evilginx to harvest credentials from high-value users such as system administrators and executives. The group has shifted tactics from hyphenated domains to subdomain-based keywords to evade detection, while collaborating with ransomware operators like ALPHV and DragonForce to deploy encryption and double extortion campaigns at scale.
Why it matters: MSPs, IT contractors, and organizations in technology, finance, and retail sectors need to immediately harden help-desk verification protocols, implement mandatory MFA for privileged access, and monitor domain registrations for typosquatting patterns, as Scattered Spider's focus on supply chain compromise enables rapid lateral movement across client networks.
- threat intel
Threat Spotlight: Capitol x Kremlin: Will US Politics Reshape Russian Cyber Threats?
US policy shifts under the Trump administration, including tariff changes, CISA restructuring, and diplomatic efforts with Russia, are reshaping the ransomware and nation-state threat landscape. Ransomware targeting of US entities has declined following peace talks, but new groups like DragonForce are expanding activity and adopting cartel models to consolidate power in the criminal ecosystem. Budget cuts to CISA, supply-chain vulnerabilities from tariff-driven vendor transitions, and potential insider threats represent emerging risks for organizations globally.
Why it matters: US-based organizations face increased insider threat risk and supply-chain attacks as security budgets shrink and vendors undergo rapid transitions; European and Canadian organizations should prepare for potential ransomware shifts; all organizations need to monitor DragonForce and similar groups adopting cartel models that enable more sophisticated, coordinated attacks.
- threat intel
Introducing: Finance & Insurance Sector Threat Landscape
ReliaQuest released a threat landscape report on attacks targeting the finance and insurance sector, identifying command shell execution and account discovery as the top techniques used by threat actors. The report benchmarks incident response performance, showing that organizations using automated response achieve 4-minute mean time to contain versus 4 hours with manual processes, and flags cryptojacking, hacktivism, and state-sponsored APT activity as emerging threats against the sector.
Why it matters: Finance and insurance practitioners should review this sector-specific threat analysis to understand attack patterns, validate their incident response automation, and assess exposure to cryptojacking and APT persistence tactics targeting their industry.
- threat intelCVE-2023-28771CVE-2023-42793
Russia-Linked Threats to Operational Technology
A ReliaQuest report examines Russia-linked advanced persistent threat (APT) groups targeting operational technology (OT) environments, analyzing key cyber attacks from the past 12 months including coordinated energy sector attacks in Denmark, compromise of Ukraine's Kyivstar telecommunications provider, and exploitation of JetBrains TeamCity vulnerabilities. The analysis documents Russia-developed OT-specific malware such as COSMICENERGY and Industroyer variants, outlines tactics and techniques observed in a manufacturing sector incident, and forecasts continued targeting of Ukrainian and allied critical infrastructure alongside long-term espionage operations. The report provides detection rules and mitigation recommendations including network segmentation, multifactor authentication, account creation restrictions, and service execution controls.
Why it matters: Organizations operating OT in critical infrastructure, manufacturing, energy, and telecommunications must assess exposure to Russia-linked APT groups and ransomware groups that may act on state direction; implement the technical mitigations detailed to limit lateral movement, privilege escalation, and persistence.
- threat intel
Health Care Social Engineering Campaign
In early April 2024, ReliaQuest identified a coordinated campaign targeting health care organizations' Revenue Cycle Management departments. Attackers used social engineering to manipulate help desk staff into resetting MFA credentials after bypassing location-based access controls with stolen credentials, then accessed banking systems likely to alter routing information. The campaign involved extensive reconnaissance, multi-stage authentication attacks, and infrastructure pivoting across multiple hosting providers.
Why it matters: Health care organizations and their finance teams face immediate risk from targeted social engineering attacks against help desk staff; practitioners should implement stricter MFA reset verification procedures, device-based conditional access, and escalation controls for finance-related identity requests to prevent banking fraud.