<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Threatintel on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/tags/threatintel/</link>
    <description>Recent content in Threatintel on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 24 Feb 2026 06:04:13 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/tags/threatintel/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Hackers target Microsoft Entra accounts in device code vishing attacks</title>
      <link>https://cluster-site.onrender.com/posts/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/</link>
      <pubDate>Thu, 19 Feb 2026 12:30:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/</guid>
      <description>• Hackers target Microsoft Entra accounts via device code vishing, exploiting OAuth 2.0 flow. • Attack uses legitimate OAuth client IDs, bypassing phishing sites and standard login</description>
    </item>
    <item>
      <title>A week in security (February 9 &amp;#8211; February 15)</title>
      <link>https://cluster-site.onrender.com/posts/a-week-in-security-february-9-%238211-february-15/</link>
      <pubDate>Mon, 16 Feb 2026 08:02:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-week-in-security-february-9-%238211-february-15/</guid>
      <description>• Credential‑stealing Chrome extensions discovered; Malwarebytes Labs offers detection and removal guide. • Fake online shops target Winter Olympics 2026 fans, phishing for payment</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• CVE-2024-54529: type confusion in CoreAudio&amp;rsquo;s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje</description>
    </item>
    <item>
      <title>Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088</title>
      <link>https://cluster-site.onrender.com/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088/</link>
      <pubDate>Tue, 27 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088/</guid>
      <description>• CVE-2025-8088: critical path traversal flaw in WinRAR allows arbitrary file writes via ADS. • Exploited by state-backed actors from Russia, China and financially motivated groups</description>
    </item>
    <item>
      <title>Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense</title>
      <link>https://cluster-site.onrender.com/posts/happy-9th-anniversary-cta-a-celebration-of-collaboration-in-cyber-defense/</link>
      <pubDate>Sat, 24 Jan 2026 00:00:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/happy-9th-anniversary-cta-a-celebration-of-collaboration-in-cyber-defense/</guid>
      <description>• CTA founded in 2014, uniting Palo Alto, Fortinet, McAfee, and Symantec for shared threat intelligence. • Shifted industry from proprietary intel to collaborative defense, raising</description>
    </item>
    <item>
      <title>I scan, you scan, we all scan for... knowledge?</title>
      <link>https://cluster-site.onrender.com/posts/i-scan-you-scan-we-all-scan-for...-knowledge/</link>
      <pubDate>Thu, 22 Jan 2026 19:00:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/i-scan-you-scan-we-all-scan-for...-knowledge/</guid>
      <description>• Reconnaissance is often ignored, yet it&amp;rsquo;s essential for protecting networks. • Know your environment: attackers excel at mapping assets, from Windows 7 machines to smart fridges.</description>
    </item>
    <item>
      <title>KONNI Adopts AI to Generate PowerShell Backdoors</title>
      <link>https://cluster-site.onrender.com/posts/konni-adopts-ai-to-generate-powershell-backdoors/</link>
      <pubDate>Thu, 22 Jan 2026 13:54:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/konni-adopts-ai-to-generate-powershell-backdoors/</guid>
      <description>• KONNI leverages AI to auto-generate PowerShell backdoor scripts, streamlining malware development. • AI models produce obfuscated code, enhancing stealth against signature-based</description>
    </item>
    <item>
      <title>Pwn2Own Automotive 2026 - The Full Schedule</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-the-full-schedule/</link>
      <pubDate>Tue, 20 Jan 2026 10:25:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-the-full-schedule/</guid>
      <description>• Pwn2Own Automotive 2026 returns to Tokyo, featuring record 73 entries. • Competition spans real‑world automotive components, testing IVI and Level‑2 EV chargers. • Random draw se</description>
    </item>
    <item>
      <title>Impact of AI on cyber threat from now to 2027</title>
      <link>https://cluster-site.onrender.com/posts/impact-of-ai-on-cyber-threat-from-now-to-2027/</link>
      <pubDate>Fri, 16 May 2025 20:03:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/impact-of-ai-on-cyber-threat-from-now-to-2027/</guid>
      <description>• AI is accelerating threat sophistication, enabling attackers to craft more convincing phishing campaigns. • Machine‑learning models are used to generate polymorphic malware that</description>
    </item>
    <item>
      <title>Russian GRU Targeting Western Logistics Entities and Technology Companies</title>
      <link>https://cluster-site.onrender.com/posts/russian-gru-targeting-western-logistics-entities-and-technology-companies/</link>
      <pubDate>Mon, 12 May 2025 16:49:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/russian-gru-targeting-western-logistics-entities-and-technology-companies/</guid>
      <description>• Russian GRU&amp;rsquo;s 85th GTsSS unit 26165 targets Western logistics and tech firms. • Campaign focuses on coordination, transport, delivery of foreign aid to Ukraine. • Uses known TTPs</description>
    </item>
    <item>
      <title>Fast Flux: A National Security Threat</title>
      <link>https://cluster-site.onrender.com/posts/fast-flux-a-national-security-threat/</link>
      <pubDate>Tue, 01 Apr 2025 19:00:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fast-flux-a-national-security-threat/</guid>
      <description>• Fast flux hides malicious server locations by rapidly changing DNS records. • Enables cybercriminals and nation-state actors to evade detection and maintain C2. • Resilient, high</description>
    </item>
    <item>
      <title>Threat report on application stores</title>
      <link>https://cluster-site.onrender.com/posts/threat-report-on-application-stores/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-report-on-application-stores/</guid>
      <description>• Malware increasingly hides in legitimate app store listings, exploiting user trust for widespread infection. • Supply‑chain attacks target third‑party libraries, enabling attacke</description>
    </item>
    <item>
      <title>The threat from commercial cyber proliferation</title>
      <link>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</guid>
      <description>• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac</description>
    </item>
    <item>
      <title>The near-term impact of AI on the cyber threat</title>
      <link>https://cluster-site.onrender.com/posts/the-near-term-impact-of-ai-on-the-cyber-threat/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-near-term-impact-of-ai-on-the-cyber-threat/</guid>
      <description>• AI accelerates threat detection, enabling faster identification of malicious activity. • Adversarial AI allows attackers to craft evasive malware that bypasses traditional defens</description>
    </item>
    <item>
      <title>The cyber threat to Universities</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-universities/</link>
      <pubDate>Wed, 12 Mar 2025 11:19:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-universities/</guid>
      <description>• Universities face rising ransomware attacks targeting research data and student records. • Phishing campaigns exploit faculty credentials to gain network access. • Supply‑chain v</description>
    </item>
    <item>
      <title>The Cyber Threat to UK Business</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-uk-business/</link>
      <pubDate>Wed, 12 Mar 2025 11:19:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-uk-business/</guid>
      <description>• Ransomware remains the top threat, targeting critical UK business data. • Phishing campaigns exploit remote working, increasing credential theft. • Supply‑chain attacks grow, com</description>
    </item>
    <item>
      <title>The cyber threat to sports organisations</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-sports-organisations/</link>
      <pubDate>Wed, 12 Mar 2025 11:18:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-sports-organisations/</guid>
      <description>• Sports organisations increasingly targeted by ransomware, phishing, and credential‑stealing attacks. • High‑profile events like the Olympics and World Cup attract sophisticated t</description>
    </item>
    <item>
      <title>Summary of the NCSC analysis of May 2020 US sanction</title>
      <link>https://cluster-site.onrender.com/posts/summary-of-the-ncsc-analysis-of-may-2020-us-sanction/</link>
      <pubDate>Wed, 12 Mar 2025 11:17:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/summary-of-the-ncsc-analysis-of-may-2020-us-sanction/</guid>
      <description>• US sanctions in May 2020 targeted Russian cyber actors and infrastructure. • NCSC identified increased threat actor activity following sanction announcements. • Sanctions disrupt</description>
    </item>
    <item>
      <title>Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking</title>
      <link>https://cluster-site.onrender.com/posts/technical-report-responsible-use-of-the-border-gateway-protocol-bgp-for-isp-interworking/</link>
      <pubDate>Wed, 12 Mar 2025 11:12:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/technical-report-responsible-use-of-the-border-gateway-protocol-bgp-for-isp-interworking/</guid>
      <description>• BGP is critical for inter-ISP routing, requiring strict policy enforcement to prevent leaks and hijacks. • Implement prefix filtering and route origin validation to ensure only l</description>
    </item>
    <item>
      <title>Incident trends report (October 2018 - April 2019)</title>
      <link>https://cluster-site.onrender.com/posts/incident-trends-report-october-2018-april-2019/</link>
      <pubDate>Wed, 12 Mar 2025 11:10:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/incident-trends-report-october-2018-april-2019/</guid>
      <description>• Over 1,200 cyber incidents reported across 30 countries, highlighting rising ransomware activity. • Ransomware attacks surged 35%, with CryptoLocker variants targeting healthcare</description>
    </item>
  </channel>
</rss>
