Blogs

The Intelligence Perspective

New perspectives and expert insights on AI, data intelligence, and cybersecurity.

Cyber Threat IntelligenceInside the Ecosystem & Operations: LockBit 5.0 Ransomware GroupExplore LockBit 5.0's ransomware ecosystem, victims, and binary analysis.2026.08.18
Cyber Threat IntelligenceThreat Actor Profiling: Moneyistime (a.k.a. @69.pdf)Explore Moneyistime's dark web attacks and BEAST ties.2026.07.29
Cyber Threat IntelligenceQuick Overview of the Chinese Darkweb Market CABYCHow CABYC, a Chinese darkweb market trades and targets Korea.2026.07.22
Cyber Threat IntelligenceBirdCall: ScarCruft Malware Masquerading as Zangi MessengerS2W recently identified and analyzed additional samples of the 'BirdCall' malicious app developed by the North Korea-backed ScarCruft group, also known as APT 37. ESET had previously disclosed that BirdCall targeted China's Yabian region and specific groups.2026.07.14
Cyber Threat IntelligenceMicrosoft Office Excel Remote Code Execution Vulnerability: CVE-2026-40362This is an analysis report on a Heap-based Buffer Overflow vulnerability discovered in the PivotTable record loader of Microsoft Office Excel.2026.07.09
Cyber Threat IntelligenceAnalysis of DPRK-Linked Money Laundering InfrastructureNorth Korea continuously conducts virtual asset compromise and money laundering activities to circumvent restrictions on securing foreign currency due to international financial sanctions. Representative cases include Ronin Bridge (2022), Horizon Bridge (2022), Atomic Wallet (2023), DMM Bitcoin (2024), and Bybit (2025), and the United States government and major blockchain analysis firms assess these as activities of North Korean-backed threat groups such as Lazarus and TraderTraitor.2026.07.01
Cyber Threat IntelligenceInside the Ecosystem & Operations: VECT Ransomware GroupThe VECT ransomware group began its operations by promoting Ransomware-as-a-Service (RaaS) on BreachForums V7. Initially charging for panel access keys, the group expanded its reach by distributing them free of charge to forum members through a BreachForums V7 partnership.2026.06.24
Cyber Threat IntelligenceMegalodon: Software Supply Chain Attack Campaign ReportOn May 21, 2026, Megalodon, a large-scale supply chain attack campaign targeting GitHub, was identified and subjected to detailed analysis.2026.06.17
Cyber Threat IntelligenceAdobe Acrobat Vulnerability Analysis: CVE-2026-34621This report is an analysis of CVE-2026-34621, an Arbitrary Code Execution vulnerability occurring in Adobe Acrobat.2026.06.10