I will hold an online session of the Paralus LLC Applied #CyberThreatIntelligence course from 27-31 July, 1400-1600 US Eastern/2000-2200 Central European time. Focused, to the point training, two hours per day for five days.

Register your interest at the following form: https://forms.gle/M1LgQTomJGekRaq76

Paralus LLC: Applied Threat Intelligence

Hello and thank you for your interest in a workshop focusing on Applied Threat Intelligence! Scheduling: 27-31 July 2026 (Five Days) 1400-1600 US Eastern/2000-2200 Central European (Two Hours/Day) Cost: $650 USD Workshop Description: When used properly, cyber threat intelligence allows an organization to leverage another’s breach or incident to their own benefit. Yet while many cyber threat intelligence courses and guides exist, these are primarily designed for developing long-range, in-depth intelligence products for strategic or similar overview with an overemphasis on theory and little experience in practice. Applied threat intelligence instead supports a different audience: day to day security work and network defense. While cyber threat intelligence must always meet standards for accuracy, relevancy, and timeliness, SOC watch-standers and IR personnel need enriched, good-enough information now over “the best” information later in order to execute their jobs. This course fills a critical role that other training does not address: how to successfully embed cyber threat intelligence operations into the daily rhythm of security to support everyday tasks, and extraordinary incidents. Toward that end, while this course will touch on theoretical concepts such as kill chain methodology, Diamond Model clustering, and other ideas, the real focus will be on what efforts make operational threat intelligence possible and sustainable: Establishing roles, responsibilities, and service agreements in advance. Determining priorities, intelligence requirements, and customer threat landscape. Molding threat intelligence information to security tools to make enriched information useful and actionable. How to analyze internal and external data sources to extract actionable threat intelligence for operational defenders. An extensive walk-through of IOC analysis, pivoting, and information enrichment to demonstrate how to better equip defenders to respond to emerging threats. Discussions on reporting, feedback, and closing the intelligence loop to definitively show how threat intelligence operations link to SOC, IR, and security policy entities. Building and maintaining lines of communication between intelligence and operations personnel to drive ideal outcomes in security event analysis and closure. A complete overview and syllabus can be found at this link. This form is to gauge interest and rough attendance for the proposed event. If a sufficient number of attendees sign up for this proposed workshop, those interested will receive an invoice for the cost of training via PayPal. Payment is required in full prior to the event to ensure cost coverage and commitment to attending. If an insufficient number of persons submit payment for the course, the event will be cancelled no later than three weeks in advance of the proposed event date. Attendees will receive a certificate of completion following the course to record for training and CPE purposes on request.

Google Docs

What happens when cyber threat intelligence professionals from around the world come together? Conversations turn into collaboration and collaboration strengthens the global security community ✊🌍

#FIRSTCTI26 brought together analysts, researchers, and security leaders for three days of discussion, knowledge sharing, and forward-looking conversations on the evolving threat landscape. From emerging trends and intelligence sharing to relationship building across organizations and borders, the event highlighted why community-driven CTI work matters more than ever.

If you couldn’t attend, or want to relive the experience, read the official event recap and catch some of the highlights and #FOMO from FIRSTCTI26: https://www.first.org/blog/20260518-FIRSTCTI26-Event-Recap

#FIRSTCTI #ThreatIntelligence #CyberSecurity #CyberThreatIntelligence #FIRSTdotOrg

FIRSTCTI26 Recap: Threat Intel & Pretzels Sold Out!

Ten years ago, a group of cybersecurity professionals gathered in Munich with a simple but ambitious idea: create a trusted space where threat intelligence experts from different sectors could actually talk to each other, collaborate openly, and tackle emerging challenges together.

FIRST — Forum of Incident Response and Security Teams

World Cup Scams Target Security Leaders with AI-Driven Threats

As the 2026 World Cup approaches, security leaders are on high alert for AI-driven scams that could compromise corporate devices and accounts, especially when employees use them for personal activities like hunting for tickets or booking travel. Even personal emails can become a threat vector, making effective…

https://osintsights.com/world-cup-scams-target-security-leaders-with-ai-driven-threats?utm_source=mastodon&utm_medium=social

#WorldCupScams #AidrivenThreats #EventdrivenScams #CyberThreatIntelligence #Radware

World Cup Scams Target Security Leaders with AI-Driven Threats

Protect against World Cup scams and AI-driven threats by learning effective cybersecurity strategies now and stay safe from event-driven attacks with expert insights.

OSINTSights

The latest episode of Signals & Stories by the Vertex Project is here!

In this episode, the Vertex analysts discuss:

• How cyber reporting evolved beyond malware analysis

• Why attribution is more complicated than most people realize

• The tension between intelligence sharing and publicity

• How geopolitics now shapes cyber operations

• Why diverse perspectives improve intelligence analysis • The traits that separate strong analysts from the rest

Listen on:
Apple Podcasts: https://podcasts.apple.com/us/podcast/signals-stories/id1893656837?i=1000768498350

Spotify: https://open.spotify.com/episode/0smNRBAKqdB1zbn6hIlw91?si=2QYGk5nkSNWB2Yik_-xyIQ

YouTube: https://youtu.be/AqqjYu6618g?si=8_TGWWS56WKK4yFC

Show Notes: https://vertex.link/10-year-anniversary/episode02

#CTI #CyberThreatIntelligence

Episode 2: “It Depends”: Attribution, Analysis, and the Evolution of Cyber Reporting

Podcast Episode · Signals & Stories · May 19 · 42m

Apple Podcasts

New IOCs observed from breached threat actor logs:

mavpaprokla[.]lat
smackit[.]lat

Recommend:
• Block/sinkhole at DNS and proxy layers
• Hunt across DNS, HTTP/S, EDR, and firewall telemetry
• Check for historical resolutions and outbound connections
• Review related infrastructure, certificates, and passive DNS pivots

If seen in your environment, treat as potentially malicious pending further enrichment.

#ThreatIntel #IOC #IOCs #CyberThreatIntelligence #DFIR #BlueTeam #SOC #ThreatHunting #Malware #Infosec #CyberSecurity #OSINT #DetectionEngineering #IncidentResponse #CTI #NetworkSecurity #DNS #ThreatResearch #CyberDefense #SIEM #EDR #MalwareAnalysis

Hackers Exploit Human Behavior to Bypass Security Tools

As cyber threats evolve at an alarming rate, hackers are exploiting human behavior to outsmart security tools, forcing organizations to rethink their defensive strategies. With identity abuse and data extortion on the rise, businesses must stay ahead of the game to protect themselves.

https://osintsights.com/hackers-exploit-human-behavior-to-bypass-security-tools?utm_source=mastodon&utm_medium=social

#CyberThreatIntelligence #ThreatLandscape #IdentityAbuse #DataExfiltration #ExtortionModels

Hackers Exploit Human Behavior to Bypass Security Tools

Learn how hackers exploit human behavior to bypass security tools and adapt your defensive strategies to stay ahead of emerging threats effectively now.

OSINTSights

Confirming, I observed Kali365 activity as early as February this year. Arctic Wolf’s writeup is great on this phish kit.

Check your auth logs for successful logins from 216.203.20.X and 199.91.220.X. The last octet will vary across at least 2 neighbors. If you find compromised accounts, run your playbooks, turn on conditional access, inspect outlook rules, and monitor for outbound DNS requests to .xyz domains.

Check for email history with phishing themes related to construction and HR docs containing an outlook safelinks embedded URL or a PDF in some cases, dropping a trojanized version of ScreenConnect in the latter.

https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/

#cyberthreatintelligence
#cybersecurity
#infosec
#threatintel

Token Bingo: Don't Let Your Code be the Winner - Arctic Wolf

Arctic Wolf recently observed a large scale device code phishing campaign leveraging the Kali365 phishing‑as‑a‑service platform to obtain initial access and conduct follow-on activity.

Arctic Wolf

New Intelligence Brief: UNC6692 “Snow” Malware Suite — deep network compromise via helpdesk impersonation. Analysis covers initial access, credential harvesting, lateral movement, and operational impact.

Full report: https://thecybermind.co/wab2

#CyberThreatIntelligence #CyberSecurity

https://thecybermind.co/2026/04/26/unc6692-snow-malware-suite-deep-network/?utm_source=mastodon&utm_medium=jetpack_social

Snow Malware Suite – Deep Network Compromise UNC6692

Snow Malware Suite UNC6692 consist of SnowBelt, Glase and Basin, Altogether they Present Deep Network Compromise via Helpdesk Impersonation and Domain Takeover.

The Cyber Mind

New Intelligence Brief: UNC6692 “Snow” Malware Suite — deep network compromise via helpdesk impersonation. Analysis covers initial access, credential harvesting, lateral movement, and operational impact.

Full report: https://thecybermind.co/wab2

#CyberThreatIntelligence #CyberSecurity

https://thecybermind.co/2026/04/26/unc6692-snow-malware-suite-deep-network/?utm_source=mastodon&utm_medium=jetpack_social

🎖️ El Curso de Maltego Graph CE está permanente disponible en el aula virtual para acceso inmediato. 📲 WhatsApp: https://wa.me/51949304030 🌐 https://www.reydes.com/e/Curso_Maltego #cyberthreatintelligence #threatintel #cybersecurity #investigation #cyberinvestigation #bugbounty #osint