CYOPS
Cyber Operations
Detection, response and mission delivery in contested networks, and how operations are actually run.
18 articles
Latest
- Star Blizzard Trades Precision for Volume: Thirteen Campaigns, One Click Microsoft counts at least thirteen large-scale phishing campaigns and more than one hundred affected organisations since January. The change that matters is not the new malware… 6 min 11 sources
- Nobody attacked anything. The agents hit a limitation, worked around it, and taught each other the workaround Glow Labs found more than 13,000 internal screenshots in public GitHub repositories, put there by AI coding agents that could not attach an image to a… 5 min 10 sources
- A framework whose modules unload themselves, and a year inside telecommunications networks Microsoft documented NeedyMantis on 28 September: a modular post-compromise framework found while following indicators from the DAEMON Tools supply chain compromise. Its design choice - load… 5 min 10 sources
- A marginal cost of US$25 a company, and the same agent harness in two unrelated operations Gambit Security recovered an operator's staging server and reconstructed a skimming campaign run through three open-source agent harnesses at an average cost of $25.46 a target.… 6 min 10 sources
- One spyware family, two government names, and a target list made of people rather than networks A joint NCSC, FBI and AIVD advisory named CHOSEN BRICK on 15 September. The FBI published the same malware as HEAVYGRAM the same day. The tradecraft… 5 min 10 sources
- A carrier taken with a 2024 flaw and held with a management agent it did not install Research published this month places an operator at root inside one of Thailand's largest broadband providers, entered through a FortiGate SSL-VPN flaw patched in February 2024,… 5 min 13 sources
- The PeopleSoft campaign returned in September, and the control that was holding it back was a text match Mandiant reports a fresh wave of exploitation against CVE-2026-35273, four months after the June zero-day campaign, defeating web application firewall rules by percent-encoding one character in… 5 min 12 sources
- One operator, ten products, and a known-exploited list that arrives after the exfiltration GreyNoise has published a three-month campaign it tracks as Kapibala, assessed as the same as or related to the Red Heron cluster documented by Acronis. The… 5 min 13 sources
- EvilTokens did not defeat multi-factor authentication. It made victims complete it Microsoft and eight partners took down a phishing service that compromised over 12,000 mailboxes by abusing the OAuth 2.0 device authorization grant. The flow it used… 6 min 12 sources
- North Korea’s fake recruiters and fake applicants log in from the same addresses, and most defenders split them across two departments A seven-agency advisory published on 18 September attributes 30,000 infected developer machines and ¥1.7 billion in stolen cryptocurrency to WaterPlum, and ties the group to North… 8 min
