Sign in

Cyber Threat Alliance

@cyberalliance.bsky.social
1.7K followers 731 following 583 posts

CTA is a group of cybersecurity practitioners who work together to improve the overall security of the global digital ecosystem. We are stronger together. www.cyberthreatalliance.org

PostsRepliesMedia
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
Ever wonder about the day in a life of a Cyber Research Communicator. Thanks to CTA member LevelBlue, you can know: www.levelblue.com/blogs/levelb... #cybersecurity #CyberResearch
levelblue.com
Day in the Life of a Cyber Research Communicator: From Threats to Takeaways
Cybersecurity research, threat intel, and novel findings produce no information shortage. What's difficult is sorting through the noise to determine what's worth following.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member Maltiverse by LUMU on the invisible cyber fraud network hijacking everyday payments lumu.io/blog/shadowp... #cybersecurity #CyberResearch
lumu.io
Unmasking ShadowParasite: The Invisible Cyber Fraud Network Hijacking Everyday Payments
An investigation by Lumu CTI exposes a Colombian payment fraud network using fake payment portals to hijack everyday utility bills and harvest banking credentials.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member CyberCX on how AI could change the economics of #cyberattacks cybercx.com.au/blog/ai-coul... #cybersecurity
cybercx.com.au
AI could change the economics of cyber attacks. Can defences keep up?
This blog was originally published as part of CyberCX’s C-Suite Cyber Newsletter series on 30 September 2026.     What...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @brandefense.bsky.social discuss how an exposed GitLab email toekn becomes push access to main... brandefense.io/blog/gitlab-... #cybersecurity #CyberResearch
brandefense.io
GitLab Incoming Email Token: Push Access From a README
A GitLab incoming email token in your public README never expires and can be used to push code to main. See how exposed docs become external attack surface.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @telefonica-en.bsky.social on protecting AI in retail... telefonicatech.com/en/blog/prot... #cybersecurity #protectingAI
telefonicatech.com
How to protect AI in retail: risks and best practices
Cybersecurity risks associated with AI in retail and the automotive sector, including data leakage, fraud, LLMJacking and adversarial attacks, together with best practices for protection.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @sophossecurity.bsky.social on a ClickFix variant known as TerminalFix... www.sophos.com/en-us/blog/t... #cybersecurity #CyberResearch
sophos.com
TerminalFix and Lorem Ipsum Loader enable covert tunneling
The activity is linked to a broader campaign that previously used a different delivery mechanism
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @rapid7.com tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. www.rapid7.com/blog/post/tr... #cybersecurity #CyberResearch
rapid7.com
SMTP is the key: BPFDoor and AVERAT hitting the network edge
Rapid7 Intelligence tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Re...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @nozominetworks.bsky.social observed multiple attempts to exploit CVE-2021-35394 affecting internet-exposed devices. Most of the activity resembled opportunistic scanning, but a subset led to a different finding... www.nozominetworks.com/blog/a-stunn... #cybersecurity #malware
nozominetworks.com
A STUNning Disguise: Cling Malware Masquerades as Google
Cling is an IoT botnet that abuses STUN-like traffic to register infected hosts, receive commands, and blend into normal network activity.
010
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member Gen Digital on the hiddent chain of residential proxies: www.gendigital.com/blog/insight... #cybersecurity #residentialproxies
gendigital.com
Your IP, Their Traffic
Inside the hidden supply chain of residential proxies
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @talosintelligence.com has eight Cisco Talos researchers share practical ways defenders can frustrate adversaries at different stages of an operation. blog.talosintelligence.com/the-fine-art... #cybersecurity #cyberdefense
blog.talosintelligence.com
The Fine Art of Frustrating the Adversary
What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependenc...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA member @reversinglabs.com on an interesting new benchmark of eight leading AI systems showing that an intelligence model still needs a good context-rich harness. #cybersecurity www.reversinglabs.com/blog/smart-l...
reversinglabs.com
Why the smartest LLMs are not-so-smart pen testers | RL Blog
A new benchmark of eight leading AI systems shows that an intelligent model still needs a good context-rich harness.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14h
CTA Member Trinity Cyber on what Cozy Bear can teach us about #cyberdefense "The problem is, malicious actors can be well-funded – even sponsored by nation-states – and able to use AI to stay ahead of traditional defenses." www.trinitycyber.com/blog/dont-ma... #cybersecurity
trinitycyber.com
Don't Make it Easy: What Cozy Bear Can Teach Us About Cyber Defense
Learn how Cozy Bear exploits common security gaps and how the Trinity Cyber platform stops phishing, exploits and RDP threats before they reach your network.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 15h
CTA member VMRay brings a story of a hunt: how a pile of 276 Formbook samples run through a machine learning pipeline led us to a global Business Email Compromise campaign. www.vmray.com/hunting-a-gl... #cybersecurity #threatresearch
vmray.com
From One RedLine IP to a Maritime Phishing Cluster: A Threat Intelligence Pivot Chain
A single RedLine C2 from UniqueSignal pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 01/10/2026
"Healthcare systems are increasingly prime targets for cybercriminals. The networks are complex & have many connected devices, & healthcare systems traditionally have not invested as much in #cybersecurity. Plus, the information, including personal medical information, has value tinyurl.com/45aephh6
tinyurl.com
Luminis Health says MyChart systems back online after cyberattack
Luminis Health said MyChart, its online patient portal, is back online as it responds to a cyberattack. The company has still not said specifically what systems were targeted or who is investigating.
020
Cyber Threat Alliance @cyberalliance.bsky.social · 30/09/2026
CTA member @sophossecurity.bsky.social @chiesennegs.bsky.social "It is time to drop the caricatures, stop indulging in logical fallacies, and get back to the work of empirical verification. We need good-faith engagement, because we cannot afford to get this wrong" www.linkedin.com/pulse/ai-deb...
linkedin.com
The AI Debate and the Risk of Logical Fallacies
A troubling dynamic has settled into the debate over artificial intelligence, and it is actively degrading our ability to evaluate real cyber risk. Rather than engaging in sober, adversarial analysis,...
010
Cyber Threat Alliance @cyberalliance.bsky.social · 30/09/2026
Starting Soon! Sept 29 @ 7 pm PT: Addressing the New APAC Battleground: Geopolitics, Cybercrime, and Data in Motion tinyurl.com/ycy6xtjp Hear how APAC cybersecurity leaders can boost regional resilience through scalable intel sharing & real-time cross-border collaboration amid rising cyber threats
010
Cyber Threat Alliance @cyberalliance.bsky.social · 29/09/2026
Interesting blog by @cyberalliance.bsky.social member @mcafee.com on the scam landscape by US state. www.mcafee.com/blogs/other-... #scam #cybersecurity
mcafee.com
011
Cyber Threat Alliance @cyberalliance.bsky.social · 28/09/2026
Tuesday, Sept 29th 7 pm ET Addressing the New APAC Battleground: Geopolitics, Cybercrime, and Data in Motion tinyurl.com/ycy6xtjp Hear how APAC #cybersecurity leaders can boost regional resilience through scalable intelligence sharing & real-time cross-border collaboration amid rising cyber threats
000
Cyber Threat Alliance @cyberalliance.bsky.social · 25/09/2026
CTA member @mcafee.com on an FBI warning of law enforcement impersanatino scams: www.mcafee.com/blogs/securi... #cybersecurity #scams
mcafee.com
000
Cyber Threat Alliance @cyberalliance.bsky.social · 22/09/2026
As attackers scale their operations with AI, Trinity Cyber's collaboration with the @cyberalliance.bsky.social helps ensure every threat discovery gives the next defender a better place to start. www.cyberthreatalliance.org/as-the-front... #cybersecurity #threatintelligence #strongertogether #cyber
cyberthreatalliance.org
As the Frontier Scales, Shared Intelligence Matters More - Cyber Threat Alliance
By Jeremy Brown, VP of Threat Analysis, Trinity Cyber A threat discovered by one security team should always give the next team a head start. Making that happen takes work: examining the evidence, dec...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 22/09/2026
CTA member Maltiverse by Lumu published the results of their investigation into a payment fraud operations focused on the Latam region lumu.io/blog/shadowp... #cybersecurity #fraud
lumu.io
Unmasking ShadowParasite: The Invisible Cyber Fraud Network Hijacking Everyday Payments
An investigation by Lumu CTI exposes a Colombian payment fraud network using fake payment portals to hijack everyday utility bills and harvest banking credentials.
010
Cyber Threat Alliance @cyberalliance.bsky.social · 21/09/2026
Have you registered? Webinar Sept 29 @ 7 pm PT: Addressing the New APAC Battleground: #Geopolitics, #Cybercrime, and Data in Motion tinyurl.com/ycy6xtjp Hear how APAC cyber leaders can strengthen resilience through intelligence sharing & real-time cross-border collaboration amid rising threats.
010
Cyber Threat Alliance @cyberalliance.bsky.social · 21/09/2026
AI is transforming vuln discovery at an unprecedented scale, challenging #cybersecurity policies. As zero-days shift from a trickle to a flood, @cyallianceprez.bsky.social & Jason Healey argue it's time to rethink the balance between offensive cyber ops & collective defense tinyurl.com/3hdb33cj
lawfaremedia.org
After the Flood: Moving Beyond the U.S. Vulnerabilities Equities Process
The oncoming AI-driven flood of vulnerabilities demands changes to the U.S. process for retaining them for offensive cyber operations.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 18/09/2026
CTA member @reversinglabs.com Chainmail Weekly News: www.linkedin.com/pulse/cisa-a... #cybersecurity #vulnerabilties
linkedin.com
CISA: AI is accelerating exploitation of software's oldest flaws
CISA data shows AI is accelerating exploitation of the same decades-old flaws, making Secure by Design newly urgent. Plus: Palo Alto Networks details a 10-hour AI-powered breach, CISOs rank agent secu...
010
Cyber Threat Alliance @cyberalliance.bsky.social · 18/09/2026
Webinar Sept 29 @ 7 pm PT: Addressing the New APAC Battleground: Geopolitics, Cybercrime, and Data in Motion tinyurl.com/ycy6xtjp Hear how APAC cybersecurity leaders can boost regional resilience through scalable intelligence sharing & real-time cross-border collaboration amid rising cyber threats
000
Cyber Threat Alliance @cyberalliance.bsky.social · 17/09/2026
"Luminis patients should be “extra vigilant” about any emails, texts or other communications they receive that purport to be from their medical providers, in case they’re from a bad actor." @cyallianceprez.bsky.social tinyurl.com/ytkkxv43 #cybersecurity #cyberattack #healthcare #phishing
thebanner.com
Luminis Health cyberattack: What we know
It’s been more than two weeks since Luminis Health, which operates hospitals in Anne Arundel and Prince George’s counties, said it was the target of a cyberattack. Here’s what we know.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @sonicwall.bsky.social Capture Labs has been tracking a Telegram bot malware capable of silently stealing cryptocurrency. The malware is a #cryptocurrency clipboard hijacker and keylogger. It replaces wallet addresses & exfiltrates everything via the Telegram bot API tinyurl.com/mr2vp83e
sonicwall.com
TeleClip: A native 64-bit Telegram RAT with Multi-Coin Crypto Clipboard hijack and Keylogger
The malware is a cryptocurrency clipboard hijacker and keylogger written in C (GCC/MinGW, native 64-bit PE). It replaces wallet addresses copied to the clipboard with attacker-controlled addresses across 23 coin types, logs keystrokes, and exfiltrates everything exclusively via the Telegram bot API — no custom C2 domain required. On first run it installs three persistent copies of itself under names that impersonate legitimate Windows processes, registers three independent persistence mechanisms (Run key, COM CLSID hijack, WMI subscription), and spawns a watchdog thread to reinstate any that are removed. Live analysis confirmed the C2 channel is active.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @sonicwall.bsky.social on security spending: "You know what’s worse than a bad defense? A bad defense you paid a fortune for. And you know what’s worse than that? Finding out afterward that the expensive thing wasn’t broken, it was just misconfigured out of the gate" tinyurl.com/48m38usw
sonicwall.com
New Toys, Same Problems
Lessons security professionals can learn from the Chargers and Rams' week one losses.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @silentpush.bsky.social on how the fast-flux technique has evolved, making it easier for threat actors to use in phishing campaigns and harder for defenders to detect and apprehend cybercriminals. www.silentpush.com/blog/fast-fl... #cybersecurity #fastflux #phishing
silentpush.com
Silent Push Tracks a Mass Phishing Operation Through Fast Flux
Silent Push became a fast-flux customer to explore its inner workings. We identified an active, nearly impossible-to-detect global operation.
001
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @reversinglabs.com on AI coding. The software industry is entering the AI era burdened by legacy flaws and weaknesses, making Secure by Design essential www.reversinglabs.com/blog/ai-secu... #cybersecurity #SecurebyDesign
reversinglabs.com
AI coding puts Secure by Design in the spotlight | RL Blog
The software industry is entering the AI era burdened by legacy flaws and weaknesses, making Secure by Design essential.
010
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA Member PentaSecurity explains the EU Cyber Resilience Act (CRA) reporting requirements that go into affect Dec 11, 2027. www.pentasecurity.com/blog/cra-rep... #cybersecurity #cyberresilience #CRA
pentasecurity.com
CRA Reporting Requirements Explained: Checklist
Prepare for CRA reporting obligations from September 2026, including 24-hour alerts, SRP reporting, legacy products, and 2027 EU compliance.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA Member @mcafee.com on how to spot fake ads on social media According to the FTC, nearly 30% of people who reported losing money to a scam in 2025 said that it started on social media. And the reported losses hit a whopping $2.1 billion last year www.mcafee.com/blogs/tips-t... #cybersecurity
mcafee.com
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member LevelBlue discussing how digitial risk has expanded far beyond the traditional security perimeter Each platform, app, tool, marketplace used represents an opportunity to connect with customers. Each also creates opportunities for abuse. www.levelblue.com/blogs/levelb... #cybersecurity
levelblue.com
Digital Risk Protection in the Age of AI
Digital risk has expanded far beyond the traditional security perimeter.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA Member Lumu dives into CastleRAT and Operations Device Manager A single click on a fake verification box can hand cybercriminals total control of your enterprise network. lumu.io/blog/castler... #cybersecurity #RAT #cyberattack #cyberthreatintelligence
lumu.io
From Fake CAPTCHA to Hidden Desktop: Unpacking CastleRAT and Operation Device Manager
New research from Lumu CTI dissects how TAG-150’s CastleRAT abuses ClickFix, Ethereum, and Steam to bypass enterprise defenses.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member CyberCX asks - Autonomous AI is accelerating cyber risk - is your organization prepared? cybercx.com.au/blog/autonom... #cybersecurity #AI #autonomousAI #cyberisk
cybercx.com.au
Autonomous AI is accelerating cyber risk: Is your organisation prepared?
Published by Brendan Wilkinolls, Technical Director Secure AI and Cyber Intelligence on September 3 2026 This blog was originally published...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA Member @brandefense.bsky.social on Passkey attacks... brandefense.io/blog/passkey... #cybersecurity #passkeys #cyberattack
brandefense.io
Passkey Attacks: Where Account Takeover Actually Lands
68% of organisations deploy passkeys, 28% are fully passwordless. Where passkey attacks actually land, and the takeover chain that never touches a passkey.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member Telefonica Tech on social enginner and cyber fraud: when people, not technology, are the target: telefonicatech.com/en/blog/soci... Social engineering shows that many attacks succeed when people act under pressure, place too much trust in others or are unaware of the risk. #cybersecurity
telefonicatech.com
Social engineering and cyber fraud: common scams, risks and how to stay protected
Social engineering uses manipulation in cyber fraud such as CEO fraud and romance scams. Learn the risks, warning signs and measures that can help protect people and organisations.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member Sophos on the emergence of Luciferus aligns with a broader trend in which threat actors are increasingly commercializing AI through underground forums, Telegram channels, and cybercriminal marketplaces. www.sophos.com/en-us/blog/u... #cybersecurity #AI
sophos.com
Devil’s advocate? Uncensored Luciferus AI service advertised underground
Uncensored refers to a lack of typical guardrails or ethical restrictions, lowering the technical barrier of entry into cybercrime
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member Ikusi discusses how the network is critical in preventing and disrupting a #ransomware attack www.ikusi.com/en/blog/can-... #cybersecurity #cyberdefense
ikusi.com
Can the Network Help You Stop a Ransomware Attack? - Ikusi
The answer is unequivocal: yes. The network is a critical element in preventing and disrupting a ransomware attack. It is […]
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @gendigital.bsky.social discovered a critical remote code execution vulnerability in Sogou INput Method, one of the most widely used Chinese-language input method editors with hunderds of millions of installs. www.gendigital.com/blog/insight... #cybersecurity #vulnerabilities
gendigital.com
Gray Rabbits and the Tale of a One-Click Backdoor
One click. Three critical failures. One backdoor.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @talosintelligence.com on securing the unpatchable in an age of AI-driven vulnerabilities blog.talosintelligence.com/securing-the... #cybersecurity #AI #vulnerabilities
blog.talosintelligence.com
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 16/09/2026
CTA member @paloaltonetworks.com's blog dives into the indicators from AMOS stealer unit42.paloaltonetworks.com/atomic-macos... #cybersecurity #macOS
unit42.paloaltonetworks.com
Atomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.
000
Cyber Threat Alliance @cyberalliance.bsky.social · 14/09/2026
Webinar Sept 29 @ 7 pm PT: Addressing the New APAC Battleground: Geopolitics, Cybercrime, and Data in Motion tinyurl.com/ycy6xtjp Hear how APAC cybersecurity leaders can boost regional resilience through scalable intelligence sharing & real-time cross-border collaboration amid rising cyber threats
031
Cyber Threat Alliance @cyberalliance.bsky.social · 11/09/2026
Congratulations to @cyallianceprez.bsky.social on being recognized as a Washingtonian 2026 Tech Titan! Tech Titans are entrepreneurs, venture capitalists, government leaders, AI experts, and other influential innovators shaping the future of technology in the Washington region tinyurl.com/5dz6unf7
washingtonian.com
Meet DC’s 2026 Tech Titans
The entrepreneurs, venture capitalists, government officials, AI experts, and other innovative, influential people driving the local technology scene
000
Cyber Threat Alliance @cyberalliance.bsky.social · 10/09/2026
If you are attending the Digi Americas LATAM CISO Summit in Cancun this week - don't miss @cyallianceprez.bsky.social speaking about 'The CISO's Strategic Mandate — Priorities Across Global Enterprises' w/Chainguard, Falabella and AWS. events.digiamericas.org/Summit2026 #cybersecurity #CISO #LATAM
events.digiamericas.org
Digi Americas LATAM CISO Summit 2026
The LATAM CISO Summit 2026 will convene in Cancún, Mexico, bringing together the region’s foremost cybersecurity leaders
000
Cyber Threat Alliance @cyberalliance.bsky.social · 08/09/2026
We are thrilled to share our Q3 newsletter. Defense Without Borders is more than a theme. It's a shared commitment reflected in the work of CTA members & partners who turn collaboration into collective intelligence and meaningful action that proects us all www.cyberthreatalliance.org/resources/as...
cyberthreatalliance.org
CTA in Focus (September 2026) - Cyber Threat Alliance
041
Cyber Threat Alliance @cyberalliance.bsky.social · 04/09/2026
Read CTA member TrinityCyber blog on how attackers are using blockchain hosted smart contracts to rotate infrastructure, hide malicious code, and keep ClickFix campaigns alive. www.trinitycyber.com/blog/when-bl... #cybersecurity #blockchain #threatintelligence
trinitycyber.com
000
Cyber Threat Alliance @cyberalliance.bsky.social · 04/09/2026
CTA member @mcafee.com on what to know with this weeks scams www.mcafee.com/blogs/securi... #scam #cybersecurity #threatintelligence
mcafee.com
000
Cyber Threat Alliance @cyberalliance.bsky.social · 04/09/2026
CTA member CyberCX on AI is supercharing scams... cybercx.com.au/blog/the-cha... #cybersecurity #scams #threatintelligence #AI #scammers
cybercx.com.au
The changing face of fraud: How AI is supercharging scams
Published by Shameela Gonzalez, Financial Services Industry Lead on August 27 2026   As we reflect on the theme of...
000
Cyber Threat Alliance @cyberalliance.bsky.social · 04/09/2026
CTA member @brandefense.bsky.social The phishing-as-a-service kit is no longer a script a criminal downloads and self-hosts. In 2026, it is a subscription product with a dashboard, customer support, templated AI lures, real-time token capture, and more: brandefense.io/blog/phishin... #cybersecurity
brandefense.io
Phishing-as-a-Service Kits: MFA Bypass Without a Fake Page
A phishing-as-a-service kit no longer needs a fake login page. Inside EvilTokens, Kali365 and the Microsoft OAuth device code abuse behind a 1,380% surge.
000