Release the RAVEN: Kibana Under Siege
August 13, 2026 | Karl Biron
Stay Informed
Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.
The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains
August 12, 2026 | Karla Agregado
To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based ...
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain
August 10, 2026 | Rodel Mendrez
This post is the result of an investigation into a case we worked on, in which ...
Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
August 07, 2026 | King Orande and Cris Tomboc
The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...
Release the RAVEN: Exploiting the Cracks
August 06, 2026 | Karl Biron
In Part 1, we went from a single open port to a complete map of the target. ...
Release the RAVEN: First Contact
August 05, 2026 | Karl Biron
You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...
Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems
August 04, 2026 | Nikita Kazymirskyi
In light of the water-sector activity described below, we've increased ...
Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes
July 29, 2026 | Karl Biron
You have almost certainly interacted with Elasticsearch today. The search bar ...
LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation
July 27, 2026 | Serhii Melnyk and Timmy Lister
Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and ...
LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses
July 23, 2026
Explore the latest tactics, techniques, and procedures (TTPs) our incident ...
Exploitarium: Inside the Archive Behind the Mass 0-Day Drop
July 21, 2026 | Serhii Melnyk
Coordinated vulnerability disclosures operate on a straightforward premise: the ...
LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC
July 20, 2026 | Pauline Bolaños
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...
Still Circling: Blind Eagle's Toolkit Keeps Evolving
July 17, 2026 | Serhii Melnyk
In June 2025, LevelBlue SpiderLabs published Tracing Blind Eagle to Proton66, ...
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 | Rodel Mendrez
You're browsing a legitimate small business website. Before the page loads, a ...
Mitigating New Vulnerabilities with owLSM
July 13, 2026
Following the successful launch of owLSM, our first open-source project with ...
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
July 09, 2026 | Nathaniel Morales
The LevelBlue Managed Threat Research team investigated a security alert in a ...
Open Sourcing Our Most Advanced Linux Security Engine: owLSM
July 09, 2026
We at LevelBlue company have decided to do something for the community, with ...
From Phishing to Persistence: A CrySome RAT Infection Chain Analysis
July 06, 2026 | Sean Shirley and Kyle Sopt
During a recent security alert, the LevelBlue MDR SOC successfully triaged and ...
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
July 02, 2026 | Fernando Martinez Sidera
Over the past two weeks, LevelBlue SpiderLabs has been tracking an active ...
An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails
June 30, 2026 | Hajime Takai
Key points LevelBlue has identified two distinct attack vectors associated with ...
Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux
June 25, 2026 | Chen Aviani and Nikita Kazymirskyi
Remote access trojans (RATs) are legacy threats that continue to evolve ...
LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign
June 24, 2026 | Dawid Nesterowicz
In Norse mythology, Loki, the god of mischief, has powerful and deceptive ...
Operation FlutterBridge: The FlutterShell macOS Backdoor
June 18, 2026 | Maor Gabay
Identified through macOS endpoint monitoring, the CL-CRI-1089 cluster, ...
RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse
June 17, 2026 | Serhii Melnyk
Following our previous research, LevelBlue SpiderLabs continued monitoring a ...
Reversing NVIDIA’s CVE-2026-24190: How a Kernel Flaw Put Enterprise AI Clusters and Workstations at Risk
June 15, 2026 | Alon Bancic
Executive Summary: Bypassing Boundaries in Enterprise AI Infrastructure The ...
The Device Code Phishing Tsunami: What We’re Seeing in the Wild
June 09, 2026 | John Kevin Adriano
With contributions from Cris Tomboc.
macOS ClickFix Social Engineering Campaigns
June 04, 2026 | Maor Gabay
Overview The "ClickFix" threat landscape has undergone a significant ...
ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery
June 04, 2026 | King Orande and Cris Tomboc
The LevelBlue OpsIntel CTI team examined the latest version of the ClickFix ...