Intelligence desk
Threat Intelligence
A permanent file of Security.io’s selected briefings tagged to this executive theme. It reflects the publication’s curated coverage, not a census of all global activity.
Fake coding tests turn developer hiring into an espionage pathEndpoint Security
QTFY disruption exposes the weakness of source-IP trustNetwork Security
Federal agencies warn of active AI-assisted targeting of Siemens S7 PLCsOperational Technology
Expanded Mabna charges sharpen the research-espionage threat modelThreat Intelligence
Jewelbug turns one shared webmail template into a national-scale footholdThreat Intelligence
Lazarus campaign used a Windows zero-day to suppress endpoint visibilityThreat Intelligence
Gunra warning turns perimeter patching into a credential-and-recovery incident investigationRansomware
LightSpy’s new footprint puts routers inside the spyware incident boundaryThreat Intelligence
OWAReaper persistence survives credential rotation and endpoint rebuildingThreat Intelligence
Recovered intrusion logs show an AI agent executing unattended post-exploitation tasksAI and Emerging Threats
Iran-linked actors are overriding PLC shutdown and alarm logicOperational Technology and Resilience
Laundry Bear’s Zimbra campaign turns a viewed email into mailbox persistenceThreat Intelligence and Identity
Fraud disruption reveals the infrastructure behind the scamLaw enforcement
The state of the router is now a critical-infrastructure questionGeopolitics & infrastructure