Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
Group-IB Digital Risk Protection Integrates with Google SecOps: Brand Threat Intelligence, Now In Your SOC
Your SOC was half prepared for brand threats, but this integration changes that. Group-IB Digital Risk Protection meets Google SecOps, bringing external brand intelligence directly into your SIEM/SOAR and closing the signal gap your analysts might’ve missed.
The French 2-Step: Exposing a Multi-stage Scam Targeting the National Railway Company in France
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
Digital Brand Protection in Cybersecurity: Why It Matters in 2026
Learn why digital brand protection matters in 2026, how threats like phishing, impersonation, counterfeits, and leaked credentials target brands online, and how organizations can detect and stop them early.
What Is an Incident Response Retainer? (And Why Waiting Until a Breach Is Too Late)
Learn what an incident response retainer is, how it works, and why having one before a cyberattack helps companies reduce response time, contain threats faster, and limit business impact.
The Secret Scriptorium: A Medieval Tale of the Shadow Shop that Forged Identities
The First Whisper – How the Quest Began It was a quiet evening in the citadel of cyber‑defence when a single alert flickered on the watch‑tower’s crystal screen. The Cyber Threat Intelligence Brotherhood, ever‑vigilant guardians of the kingdom’s data, spotted a match: a client’s official…
Unusual Data Exfiltration Paths: Leveraging Rclone for SharePoint Data Theft
Premise As Yarix’s Incident Response Team, our responsibilities are to manage critical issues related to cyber-attacks carried out by cybercriminals, intervening promptly in order to guarantee security to victim companies and to minimize latent risks, analyzing the systems within their infrastructures and indicating precise remediation…
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
Cyble Recognized in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies — and What Cyble Feels It Means for the Next Era of Threat Intel
Cyble has been recognized as a Challenger in the 2026 Gartner® Magic Quadrant™ for CTI. Here’s what it means for the future of threat intelligence.