New.

Watchtower: Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) https://labs.watchtowr.com/marking-your-own-homework-check-point-remote-access-vpn-ikev1-authentication-bypass-cve-2026-50751/ #infosec #VPN #CheckPoint #threatresearch

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad people in. While we’ve seemingly had a breather from traditional

watchTowr Labs
APT28, an evolution of tradecraft

Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and publicly attributed to the GRU’s Unit 26165, is one of the most prolific and persistent state-sponsored actors we monitor. Its operations span in two […]

Sekoia.io Blog

New.

"The RAT abuses the Google Sheets API as its command-and-control (C2) channelauthenticating via an embedded GCP service account private key and using individual spreadsheet tabs per victim for bidirectional communication."

Securonix: Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation https://www.securonix.com/blog/sheetcreep-evolved-google-sheets-rat/ #espionage #infosec #threatresearch #Google

SHEET#CREEP Espionage Return

Securonix Threat Research: Securonix analyzes SHEET#CREEP, a stealthy RAT that uses Google Sheets as a command-and-control channel, enabling persistent access, espionage, and cloud-based evasion.

Securonix
RoguePlanet: Anatomy of the Nightmare Eclipse Microsoft Defender Zero-Day

Learn how autonomous penetration testing platforms use AI agents to scope, execute, validate, and revalidate real attack paths.

From SQLi to RCE - Exploiting LangGraph’s Checkpointer - Check Point Research

By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state. But what happens when that persistence layer isn’t locked down? Key Points Background LangGraph is an open-source framework for building stateful, multi-agent AI systems with built-in persistence. It’s an extension of LangChain, with over […]

Check Point Research
Zscaler ThreatLabz 2026 Phishing and Initial Access Report

ThreatLabz 2026 report highlights: AI-driven phishing, encrypted delivery, real-time session compromise, and reconnaissance at scale—plus guidance to reduce initial acces

New.

Huntress: The Fake Download That Steals Everything: How Deceptive Installers Are Targeting macOS Users https://www.huntress.com/blog/deceptive-installers-macos-infostealers @huntress #infosec #threatresearch #macOS #Apple #malware

Deceptive Installers: How Fake Apps Target macOS | Huntress

Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.

Huntress
SilabRAT, What’s Your Power?

SilabRAT is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.

Group-IB
Blackpoint, from yesterday: Seeing Through the Tunnel: Leveraging SIEM Detections to Expose Malicious SSL VPN Authentications https://blackpointcyber.com/blog/malicious-ssl-vpn-authentication-detection/ #infosec #threatresearch #VPN
Seeing Through the Tunnel: Leveraging SIEM  Detections to Expose Malicious SSL VPN Authentications 

Threat actors are increasingly using compromised SSL VPN credentials to access corporate networks. Learn how SIEM detections identify malicious VPN authentications before lateral movement and ransomware attacks begin.

Blackpoint Cyber

New.

KrebsonSecurity: Who Runs the Ransomware Group ‘The Gentlemen?’ https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/ @briankrebs

Speaking of which, the latest caper by these crooks included raiding Central Arkansas Pediatrics on June 8 and a few other targets. Very gentlemanly. https://ransomware.live/id/Q2VudHJhbCBBcmthbnNhcyBQZWRpYXRyaWNzQHRoZWdlbnRsZW1lbg #infosec #ransomware #threatresearch

Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security