Arista patches actively exploited VeloCloud Orchestrator zero-day
Microsoft: September Windows updates break Always On VPN connections
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems.
Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies
Explore phishing risk across 5 key US industries and learn how faster detection and threat visibility help mitigate attacks.
Garante privacy, 120 giorni per contestare: resta il nodo dei tempi delle sanzioni
Il Garante privacy ha 120 giorni per notificare la contestazione, non per concludere il procedimento sanzionatorio. La Cassazione chiarisce la distinzione, ma lascia emergere un problema irrisolto: manca un termine finale certo. Una lacuna che incide sulla difesa delle imprese e che l’Autorità potrebbe colmare con il proprio regolamento
EU Turns the Tables on Big Tech Over Children’s Safety
EU KIDS Act proposes new age limits, parental controls and safety requirements for children using social media and online platforms in the EU.
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
CVE-2026-65660 is a SharePoint RCE flaw rated 8.8 that Microsoft first called a 6.5 spoofing bug.
Shiny Hunters Claim FBI Breach, Offer Sample of Alleged Stolen Data
The FBI is investigating after Shiny Hunters claimed it stole thousands of agents' personal data via FBIjobs.go.
Harness’ Rahul Sood: AppSec in the Agentic Era Is About More Than Code. It’s About Authority
The Cyber Express talks to Harness' Rahul Sood about AI-speed development, faster remediation, runtime visibility and limits on AI agents.
AI, il costo nascosto della produttività: quando generare costa meno che verificare
L’intelligenza artificiale sta abbattendo drasticamente il costo necessario per produrre codice, documenti, analisi e informazioni. Verificarli, però, continua a richiedere tempo, competenza e responsabilità. Il rischio è trasformare la produttività individuale in un debito di verifica collettivo
Assessing Cyber Threats to 2024 Worldwide Elections
Sekoia TDR analysts conduct an assessment of threats regarding the major elections that will occur in 2024.
Mallox Ransomware Affiliate Uses PureCrypter in MS-SQL Attacks
Learn about the techniques used by the Mallox ransomware affiliate to compromise an MS-SQL server. Dive into our detailed technical analysis.
How to empower the MSSP business with Sekoia's AI SOC platform?
The Sekoia's AI SOC platform, designed for MSSP, centralizes management, integrates with any infrastructure, and automates tasks with pre-built playbooks. It supports MSSPs' transformation into MDRs, offering an intuitive XDR approach and multi-tenant mod
DoppelGänger: inside the pro-Russian influence campaign
Uncover the details of the DoppelGänger campaign, a Russian influence operation aimed at undermining support for Ukraine.
Meet Sekoia TDR: Our Threat Detection & Research Team
This time, we're not revealing a new cyber threat investigation or analysis, but I want to share some insights about the team behind all Sekoia Threat Intelligence and Detection Engineering reports. Let me introduce you to the Sekoia TDR…
PikaBot: a Guide to its Deep Secrets and Operations
This blog post provides an in-depth analysis of PikaBot, focusing on its anti-analysis techniques implemented in the different malware stages.
Combining Sekoia Intelligence and OpenCTI
The Filigran x Sekoia.io partnership announcement is an opportunity to put the spotlight back on the benefits of the integration between OpenCTI and Sekoia Threat Intelligence.
From On-Premise to SaaS SOC platforms: The Cybersecurity Market Shift
The cybersecurity market is undergoing significant transformation marked by major acquisitions and mergers among key players. Traditional on-premise solutions are being replaced by comprehensive, SaaS-based platforms that offer faster deployment.
Efficiency-Driven SOC Operations: Integrated AI SOC Platform
Discover how new cybersecurity tools can revolutionize SOC operations. Boost efficiency and stay ahead of cyber threats with integrated solutions.
Exploring the Benefits of MITRE ATT&CK in Sekoia SOC Platform
At Sekoia, the integration of the MITRE ATT&CK framework into our Security Operations Center (SOC) platform is a cornerstone of our approach to cybersecurity. The ATT&CK framework serves as a comprehensive knowledge base of cyber adversary behaviours.
MuddyWater replaces Atera by custom MuddyRot implant
Find out how MuddyWater have changed their infection chain and employed a new implant dubbed "MuddyRot" by Sekoia TDR analysts.
Advanced Security Solutions for SMEs: The Technology Shift
In today's digital age, small and medium enterprises (SMEs) are facing unprecedented cybersecurity challenges. The threat landscape has evolved dramatically, with malicious actors constantly seeking out the weakest links.
Solving the 7777 Botnet enigma: A cybersecurity quest
Discover 7777 botnet (aka Quad7) and its activity, targets, and use of TP-Link routers in Microsoft 365 attacks in our latest investigation.
Emulating and Detecting Scattered Spider-like Attacks
Explore a use-case scenario demonstrating how to detect scattered spider attacks in AWS environments and enhance your cloud security.
Enabling New Service Models With SSDP
Discover how SSDP are transforming SOCs and boosts MSSP activities into MDR and now MXDR services, transforming security service delivery.
A glimpse into the Quad7 operators' next moves and associated botnets
Uncover the secrets of the Quad7 botnet and its ever-evolving toolset. Learn about the new backdoors and protocols used by these operators.
Securing Gold : Hunting typosquatted domains during the Olympics
Discover how Sekoia.io proactively hunts for typosquatted domains related to the Paris 2024 Olympics to detect and prevent cyber threats.
WebDAV-as-a-Service: The Infrastructure Behind Emmenhtal
This blogpost examines the use of WebDAV technology in hosting malicious files related to the Emmenhtal loader, then analyses the various final payloads delivered through this infrastructure.
SilentSelfie: Revealing a major campaign against Kurdish websites
Our investigation uncovered 25 kurdish websites compromised by four different variants of a malicious script, ranging from the simplest, which obtains the device's location, to the most complex, which prompts selected users to install a malicious And
Why it’s time to replace your legacy SIEM with a SOC platform
In today’s cybersecurity landscape, upgrading from legacy SIEM solutions to modern SOC platforms is no longer a question of if, but when. As we enter 2024, security teams must adapt to the increasingly complex threats they face.
Hadooken and K4Spreader: The 8220 Gang's Latest Arsenal
On 17 September 2024, Sekoia’s Threat Detection & Research (TDR) team identified a notable infection chain targeting both Windows and Linux systems through our Oracle WebLogic honeypot.