Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators

September 30, 2026 | Sean Shirley

Hunter

Stay Informed

Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.

Citrix NetScaler Zero-Day Exploited Globally

September 29, 2026 | Karl Sigler

On Sept 27, Citrix released patches for two critical vulnerabilities being ...

File Acquisition May Be Recorded as “FileAccessed” in Microsoft 365 (“M365”)

September 24, 2026 | Jamie Mamroe and Matt Arbaugh & Joel Bowers

A recent trend has emerged where threat actor groups (e.g., ShinyHunters, PEAR, ...

Enumerating Users and MFA via Microsoft's Password Reset Portal

September 23, 2026 | Matthew Coady

Microsoft's Self-Service Password Reset (SSPR) portal is a legitimate feature ...

One Patch Behind: Nightmare-Eclipse's ShieldCrash and the Defender Bypass That Won't Stay Fixed

September 16, 2026 | Serhii Melnyk and Timmy Lister

(Edit - Sept 17, 2026): The originally released PoC had issues that broke ...

Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs

September 09, 2026 | Serhii Melnyk and Timmy Lister

In our previous blog, we explored a series of disclosures from the leak persona ...

Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

August 28, 2026 | Serhii Melnyk

This is a collaborative follow-up to our original post, developed jointly with ...

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

August 25, 2026 | Nikita Kazymirskyi

A cyber incident affecting a small UK electricity generator in July 2026 ...

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking

August 19, 2026 | Serhii Melnyk and Timmy Lister

Following GreenPlasma, YellowKey and MiniPlasma, RoguePlanet and GreatXML, and ...

Release the RAVEN: Destruction and Discipline

August 18, 2026 | Karl Biron

In Part 4, we stole every document from every index, planted a rogue superuser ...

Release the RAVEN: Data Heist and Persistence

August 14, 2026 | Karl Biron

We have access through port 9200. We have code execution through port 5601. ...

Release the RAVEN: Kibana Under Siege

August 13, 2026 | Karl Biron

In Parts 1 and 2, every command targeted port 9200. Every exploit, every ...

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

August 12, 2026 | Karla Agregado

To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based ...

CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain

August 10, 2026 | Rodel Mendrez

This post is the result of an investigation into a case we worked on, in which ...

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

August 07, 2026 | King Orande and Cris Tomboc

The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...

Release the RAVEN: Exploiting the Cracks

August 06, 2026 | Karl Biron

In Part 1, we went from a single open port to a complete map of the target. ...

Release the RAVEN: First Contact

August 05, 2026 | Karl Biron

You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...

Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems

August 04, 2026 | Nikita Kazymirskyi

In light of the water-sector activity described below, we've increased ...

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

July 29, 2026 | Karl Biron

You have almost certainly interacted with Elasticsearch today. The search bar ...

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

July 27, 2026 | Serhii Melnyk and Timmy Lister

Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and ...

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

July 23, 2026

Explore the latest tactics, techniques, and procedures (TTPs) our incident ...

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop

July 21, 2026 | Serhii Melnyk

Coordinated vulnerability disclosures operate on a straightforward premise: the ...

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

July 20, 2026 | Pauline Bolaños

Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...

Still Circling: Blind Eagle's Toolkit Keeps Evolving

July 17, 2026 | Serhii Melnyk

In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

July 16, 2026 | Rodel Mendrez

You're browsing a legitimate small business website. Before the page loads, a ...

Mitigating New Vulnerabilities with owLSM

July 13, 2026

Following the successful launch of owLSM, our first open-source project with ...

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

July 09, 2026 | Nathaniel Morales

The LevelBlue Managed Threat Research team investigated a security alert in a ...

Open Sourcing Our Most Advanced Linux Security Engine: owLSM

July 09, 2026

We at LevelBlue company have decided to do something for the community, with ...