Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators
September 30, 2026 | Sean Shirley
Stay Informed
Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.
Citrix NetScaler Zero-Day Exploited Globally
September 29, 2026 | Karl Sigler
On Sept 27, Citrix released patches for two critical vulnerabilities being ...
File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”)
September 24, 2026 | Jamie Mamroe and Matt Arbaugh & Joel Bowers
A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, ...
Enumerating Users and MFA via Microsoft's Password Reset Portal
September 23, 2026 | Matthew Coady
Microsoft's Self-Service Password Reset (SSPR) portal is a legitimate feature ...
One Patch Behind: Nightmare-Eclipse's ShieldCrash and the Defender Bypass That Won't Stay Fixed
September 16, 2026 | Serhii Melnyk and Timmy Lister
(Edit - Sept 17, 2026): The originally released PoC had issues that broke ...
Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs
September 09, 2026 | Serhii Melnyk and Timmy Lister
In our previous blog, we explored a series of disclosures from the leak persona ...
Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader
August 28, 2026 | Serhii Melnyk
This is a collaborative follow-up to our original post, developed jointly with ...
Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat
August 25, 2026 | Nikita Kazymirskyi
A cyber incident affecting a small UK electricity generator in July 2026 ...
Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking
August 19, 2026 | Serhii Melnyk and Timmy Lister
Following GreenPlasma, YellowKey and MiniPlasma, RoguePlanet and GreatXML, and ...
Release the RAVEN: Destruction and Discipline
August 18, 2026 | Karl Biron
In Part 4, we stole every document from every index, planted a rogue superuser ...
Release the RAVEN: Data Heist and Persistence
August 14, 2026 | Karl Biron
We have access through port 9200. We have code execution through port 5601. ...
Release the RAVEN: Kibana Under Siege
August 13, 2026 | Karl Biron
In Parts 1 and 2, every command targeted port 9200. Every exploit, every ...
The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains
August 12, 2026 | Karla Agregado
To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based ...
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
August 10, 2026 | Rodel Mendrez
This post is the result of an investigation into a case we worked on, in which ...
Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
August 07, 2026 | King Orande and Cris Tomboc
The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...
Release the RAVEN: Exploiting the Cracks
August 06, 2026 | Karl Biron
In Part 1, we went from a single open port to a complete map of the target. ...
Release the RAVEN: First Contact
August 05, 2026 | Karl Biron
You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...
Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems
August 04, 2026 | Nikita Kazymirskyi
In light of the water-sector activity described below, we've increased ...
Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes
July 29, 2026 | Karl Biron
You have almost certainly interacted with Elasticsearch today. The search bar ...
LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation
July 27, 2026 | Serhii Melnyk and Timmy Lister
Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and ...
LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses
July 23, 2026
Explore the latest tactics, techniques, and procedures (TTPs) our incident ...
Exploitarium: Inside the Archive Behind the Mass 0-Day Drop
July 21, 2026 | Serhii Melnyk
Coordinated vulnerability disclosures operate on a straightforward premise: the ...
LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC
July 20, 2026 | Pauline Bolaños
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...
Still Circling: Blind Eagle's Toolkit Keeps Evolving
July 17, 2026 | Serhii Melnyk
In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 | Rodel Mendrez
You're browsing a legitimate small business website. Before the page loads, a ...
Mitigating New Vulnerabilities with owLSM
July 13, 2026
Following the successful launch of owLSM, our first open-source project with ...
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
July 09, 2026 | Nathaniel Morales
The LevelBlue Managed Threat Research team investigated a security alert in a ...
Open Sourcing Our Most Advanced Linux Security Engine: owLSM
July 09, 2026
We at LevelBlue company have decided to do something for the community, with ...