Anomali Threat Research

Anomali's Threat Research team continually tracks security threats to identify when new, highly critical security threats emerge. The Anomali Threat Research team's briefings discuss current threats and risks like botnets, data breaches, misconfigurations, ransomware, threat groups, and various vulnerabilities. The team also creates free and premium threat intelligence feeds for Anomali's industry-leading Threat Intelligence Platform, ThreatStream.

Anomali Threat Research Blog

Iranian Cyber Operations Poised for Escalation as Ceasefire Collapses
Iranian Cyber Operations Poised for Escalation as Ceasefire Collapses
Published on:
June 2, 2026
Blog

Iranian Cyber Operations Poised for Escalation as Ceasefire Collapses

Read More
Iranian Cyber Operations Enter Critical Window as Kinetic Conflict Reaches Day 94
Iranian Cyber Operations Enter Critical Window as Kinetic Conflict Reaches Day 94
Published on:
June 1, 2026
Blog

Iranian Cyber Operations Enter Critical Window as Kinetic Conflict Reaches Day 94

Read More
Iran's Cyber Paradox: Degraded APTs, Empowered Proxies, and the Rise of Bootkit Wipers
Iran's Cyber Paradox: Degraded APTs, Empowered Proxies, and the Rise of Bootkit Wipers
Published on:
May 29, 2026
Blog

Iran's Cyber Paradox: Degraded APTs, Empowered Proxies, and the Rise of Bootkit Wipers

Read More
Iran's Cyber War Machine Doesn't Do Ceasefires: What CISOs Need to Know Now
Iran's Cyber War Machine Doesn't Do Ceasefires: What CISOs Need to Know Now
Published on:
May 28, 2026
Blog

Iran's Cyber War Machine Doesn't Do Ceasefires: What CISOs Need to Know Now

Read More
Iranian Cyber Operations Expand Multi-Tool Staging Infrastructure as Conflict Enters Fourth Month
Iranian Cyber Operations Expand Multi-Tool Staging Infrastructure as Conflict Enters Fourth Month
Published on:
May 27, 2026
Blog

Iranian Cyber Operations Expand Multi-Tool Staging Infrastructure as Conflict Enters Fourth Month

Read More
Iranian Cyber Operations Enter Most Dangerous Phase: Physical Destruction Without Malware Under Ceasefire Cover
Iranian Cyber Operations Enter Most Dangerous Phase: Physical Destruction Without Malware Under Ceasefire Cover
Published on:
May 26, 2026
Blog

Iranian Cyber Operations Enter Most Dangerous Phase: Physical Destruction Without Malware Under Ceasefire Cover

Read More
Iran's Cyber War Machine Isn't Stopping for Peace Talks — What CISOs Need to Know Now
Iran's Cyber War Machine Isn't Stopping for Peace Talks — What CISOs Need to Know Now
Published on:
May 25, 2026
Blog

Iran's Cyber War Machine Isn't Stopping for Peace Talks — What CISOs Need to Know Now

Read More
Iran's Cyber Arsenal Is Reloading: What CISOs Must Know About the Post-Decapitation Threat Window
Iran's Cyber Arsenal Is Reloading: What CISOs Must Know About the Post-Decapitation Threat Window
Published on:
May 22, 2026
Blog

Iran's Cyber Arsenal Is Reloading: What CISOs Must Know About the Post-Decapitation Threat Window

Read More
Iranian Cyber Operations Escalate to Military Psychological Warfare as Ceasefire Talks Stall
Iranian Cyber Operations Escalate to Military Psychological Warfare as Ceasefire Talks Stall
Published on:
May 21, 2026
Blog

Iranian Cyber Operations Escalate to Military Psychological Warfare as Ceasefire Talks Stall

Read More
The Silent Countdown: Iran's Cyber Operations Enter a Dangerous Steady State While Critical Blind Spots Grow
The Silent Countdown: Iran's Cyber Operations Enter a Dangerous Steady State While Critical Blind Spots Grow
Published on:
May 20, 2026
Blog

The Silent Countdown: Iran's Cyber Operations Enter a Dangerous Steady State While Critical Blind Spots Grow

Read More
Iran's Cyber Offensive Hits U.S. Fuel Infrastructure: What CISOs Must Know Now
Iran's Cyber Offensive Hits U.S. Fuel Infrastructure: What CISOs Must Know Now
Published on:
May 19, 2026
Blog

Iran's Cyber Offensive Hits U.S. Fuel Infrastructure: What CISOs Must Know Now

Read More
Iran Conflict Cyber Operations: Russia-Iran Infrastructure Cooperation Deepens as Fuel Sector Targeting Confirmed
Iran Conflict Cyber Operations: Russia-Iran Infrastructure Cooperation Deepens as Fuel Sector Targeting Confirmed
Published on:
May 18, 2026
Blog

Iran Conflict Cyber Operations: Russia-Iran Infrastructure Cooperation Deepens as Fuel Sector Targeting Confirmed

Read More
Iran's Drone Strike on a Nuclear Facility Changes the Cyber Calculus: What CISOs Must Do Now
Iran's Drone Strike on a Nuclear Facility Changes the Cyber Calculus: What CISOs Must Do Now
Published on:
May 17, 2026
Blog

Iran's Drone Strike on a Nuclear Facility Changes the Cyber Calculus: What CISOs Must Do Now

Read More
The Coiled Spring: Iran's Cyber Operations Enter Their Most Dangerous Phase
The Coiled Spring: Iran's Cyber Operations Enter Their Most Dangerous Phase
Published on:
May 16, 2026
Blog

The Coiled Spring: Iran's Cyber Operations Enter Their Most Dangerous Phase

Read More
The Loudest Signal in Iranian Cyber Operations Is Silence — And That Should Worry You
The Loudest Signal in Iranian Cyber Operations Is Silence — And That Should Worry You
Published on:
May 15, 2026
Blog

The Loudest Signal in Iranian Cyber Operations Is Silence — And That Should Worry You

Read More
Iranian Cyber Operations at Week 11: Active PLC Exploitation, Destructive Wiper Attacks, and the Silent Threat of Dormant Access
Iranian Cyber Operations at Week 11: Active PLC Exploitation, Destructive Wiper Attacks, and the Silent Threat of Dormant Access
Published on:
May 14, 2026
Blog

Iranian Cyber Operations at Week 11: Active PLC Exploitation, Destructive Wiper Attacks, and the Silent Threat of Dormant Access

Read More
The 10-Week Silence Before the Storm: Iran's Cyber Retaliation Gap Demands Immediate Action
The 10-Week Silence Before the Storm: Iran's Cyber Retaliation Gap Demands Immediate Action
Published on:
May 13, 2026
Blog

The 10-Week Silence Before the Storm: Iran's Cyber Retaliation Gap Demands Immediate Action

Read More
Iran Conflict Day 71: Ceasefire Deadline Converges with Silent APTs and Active Exploitation — What CISOs Must Do Now
Iran Conflict Day 71: Ceasefire Deadline Converges with Silent APTs and Active Exploitation — What CISOs Must Do Now
Published on:
May 9, 2026
Blog

Iran Conflict Day 71: Ceasefire Deadline Converges with Silent APTs and Active Exploitation — What CISOs Must Do Now

Read More
Iranian Cyber Forces in “Coiled Spring” Posture: What CISOs Must Do Before the Window Closes
Iranian Cyber Forces in “Coiled Spring” Posture: What CISOs Must Do Before the Window Closes
Published on:
May 7, 2026
Blog

Iranian Cyber Forces in “Coiled Spring” Posture: What CISOs Must Do Before the Window Closes

Read More
The Calm Before the Storm: Iran’s Cyber Forces Are Pre-Positioning While Diplomats Talk
The Calm Before the Storm: Iran’s Cyber Forces Are Pre-Positioning While Diplomats Talk
Published on:
May 6, 2026
Blog

The Calm Before the Storm: Iran’s Cyber Forces Are Pre-Positioning While Diplomats Talk

Read More
Cyber-Kinetic Convergence Intensifies: Iran's Digital War Machine After the UAE Strike
Cyber-Kinetic Convergence Intensifies: Iran's Digital War Machine After the UAE Strike
Published on:
May 5, 2026
Blog

Cyber-Kinetic Convergence Intensifies: Iran's Digital War Machine After the UAE Strike

Read More
When Silence Is the Loudest Warning: Iranian Cyber Operations on Day 66 of the U.S.–Iran Conflict
When Silence Is the Loudest Warning: Iranian Cyber Operations on Day 66 of the U.S.–Iran Conflict
Published on:
May 4, 2026
Blog

When Silence Is the Loudest Warning: Iranian Cyber Operations on Day 66 of the U.S.–Iran Conflict

Read More
The Ceasefire That Doesn’t Cover Cyber: Iran’s Expanding Digital War on Critical Infrastructure
The Ceasefire That Doesn’t Cover Cyber: Iran’s Expanding Digital War on Critical Infrastructure
Published on:
May 1, 2026
Blog

The Ceasefire That Doesn’t Cover Cyber: Iran’s Expanding Digital War on Critical Infrastructure

Read More
The Cyber Front Intensifies: Iranian Operations Expand Into New Domains as Diplomacy Collapses
The Cyber Front Intensifies: Iranian Operations Expand Into New Domains as Diplomacy Collapses
Published on:
April 30, 2026
Blog

The Cyber Front Intensifies: Iranian Operations Expand Into New Domains as Diplomacy Collapses

Read More
Iran’s Cyber War Isn’t Waiting for a Ceasefire — and Neither Should You
Iran’s Cyber War Isn’t Waiting for a Ceasefire — and Neither Should You
Published on:
April 29, 2026
Blog

Iran’s Cyber War Isn’t Waiting for a Ceasefire — and Neither Should You

Read More
When the Ceasefire Holds but the Hackers Don’t: Iran’s Cyber War Enters Its Ninth Week
When the Ceasefire Holds but the Hackers Don’t: Iran’s Cyber War Enters Its Ninth Week
Published on:
April 28, 2026
Blog

When the Ceasefire Holds but the Hackers Don’t: Iran’s Cyber War Enters Its Ninth Week

Read More
Ceasefire That Isn’t: Day 59 of Iran’s Cyber War on U.S. Critical Infrastructure
Ceasefire That Isn’t: Day 59 of Iran’s Cyber War on U.S. Critical Infrastructure
Published on:
April 27, 2026
Blog

Ceasefire That Isn’t: Day 59 of Iran’s Cyber War on U.S. Critical Infrastructure

Read More
Iran’s Cyber War Machine Is Accelerating — And the Ceasefire Doesn’t Cover It
Iran’s Cyber War Machine Is Accelerating — And the Ceasefire Doesn’t Cover It
Published on:
April 24, 2026
Blog

Iran’s Cyber War Machine Is Accelerating — And the Ceasefire Doesn’t Cover It

Read More
The Ceasefire Is a Lie: Iranian Cyber Operations Are Running at Full Tempo While the World Looks Away
The Ceasefire Is a Lie: Iranian Cyber Operations Are Running at Full Tempo While the World Looks Away
Published on:
April 23, 2026
Blog

The Ceasefire Is a Lie: Iranian Cyber Operations Are Running at Full Tempo While the World Looks Away

Read More
When the Ceasefire Doesn't Apply to Cyberspace: Iran's Dual-Track Doctrine and What It Means for Your Defenses
When the Ceasefire Doesn't Apply to Cyberspace: Iran's Dual-Track Doctrine and What It Means for Your Defenses
Published on:
April 22, 2026
Blog

When the Ceasefire Doesn't Apply to Cyberspace: Iran's Dual-Track Doctrine and What It Means for Your Defenses

Read More
Iran's Cyber War Didn't Stop When the Ceasefire Started — And the Next 72 Hours Are Critical
Iran's Cyber War Didn't Stop When the Ceasefire Started — And the Next 72 Hours Are Critical
Published on:
April 21, 2026
Blog

Iran's Cyber War Didn't Stop When the Ceasefire Started — And the Next 72 Hours Are Critical

Read More
Iran’s Cyber War Didn’t Stop When the Bombs Did — Why the Ceasefire Is the Most Dangerous Phase Yet
Iran’s Cyber War Didn’t Stop When the Bombs Did — Why the Ceasefire Is the Most Dangerous Phase Yet
Published on:
April 20, 2026
Blog

Iran’s Cyber War Didn’t Stop When the Bombs Did — Why the Ceasefire Is the Most Dangerous Phase Yet

Read More
When Silence Is the Loudest Warning: Iran's Cyber Operations Enter a Dangerous New Phase
When Silence Is the Loudest Warning: Iran's Cyber Operations Enter a Dangerous New Phase
Published on:
April 14, 2026
Blog

When Silence Is the Loudest Warning: Iran's Cyber Operations Enter a Dangerous New Phase

Read More
Iran’s Cyber War Enters Its Most Dangerous Phase: Active ICS Exploitation, Geographic Expansion, and Two Critical Zero-Days
Iran’s Cyber War Enters Its Most Dangerous Phase: Active ICS Exploitation, Geographic Expansion, and Two Critical Zero-Days
Published on:
April 13, 2026
Blog

Iran’s Cyber War Enters Its Most Dangerous Phase: Active ICS Exploitation, Geographic Expansion, and Two Critical Zero-Days

Read More
Iran’s Cyber War Is Accelerating — And the Exploitation Window Just Collapsed to Hours
Iran’s Cyber War Is Accelerating — And the Exploitation Window Just Collapsed to Hours
Published on:
April 10, 2026
Blog

Iran’s Cyber War Is Accelerating — And the Exploitation Window Just Collapsed to Hours

Read More
Iran’s Cyber War Machine Isn’t Slowing Down — Six Weeks in, Critical Infrastructure Is Under Active Attack
Iran’s Cyber War Machine Isn’t Slowing Down — Six Weeks in, Critical Infrastructure Is Under Active Attack
Published on:
April 9, 2026
Blog

Iran’s Cyber War Machine Isn’t Slowing Down — Six Weeks in, Critical Infrastructure Is Under Active Attack

Read More
Iran’s Cyber War Didn’t Stop With the Ceasefire — It Just Went Underground
Iran’s Cyber War Didn’t Stop With the Ceasefire — It Just Went Underground
Published on:
April 8, 2026
Blog

Iran’s Cyber War Didn’t Stop With the Ceasefire — It Just Went Underground

Read More
The 48-Hour Window: Iran's Cyber-Kinetic War Machine Reaches Maximum Threat Posture
The 48-Hour Window: Iran's Cyber-Kinetic War Machine Reaches Maximum Threat Posture
Published on:
April 7, 2026
Blog

The 48-Hour Window: Iran's Cyber-Kinetic War Machine Reaches Maximum Threat Posture

Read More
Iran’s Cyber War Machine Doesn’t Need the Internet to Attack You
Iran’s Cyber War Machine Doesn’t Need the Internet to Attack You
Published on:
April 6, 2026
Blog

Iran’s Cyber War Machine Doesn’t Need the Internet to Attack You

Read More
Iran’s IRGC Names Western Tech Giants as “Legitimate Targets”: What CISOs Must Do Now
Iran’s IRGC Names Western Tech Giants as “Legitimate Targets”: What CISOs Must Do Now
Published on:
April 3, 2026
Blog

Iran’s IRGC Names Western Tech Giants as “Legitimate Targets”: What CISOs Must Do Now

Read More
The Iran Cyber Threat Machine Isn’t Slowing Down — Here’s What CISOs Need to Know Now
The Iran Cyber Threat Machine Isn’t Slowing Down — Here’s What CISOs Need to Know Now
Published on:
April 2, 2026
Blog

The Iran Cyber Threat Machine Isn’t Slowing Down — Here’s What CISOs Need to Know Now

Read More
Iran's Cyber War Machine Hits Full Stride: What CISOs Must Do Right Now
Iran's Cyber War Machine Hits Full Stride: What CISOs Must Do Right Now
Published on:
April 1, 2026
Blog

Iran's Cyber War Machine Hits Full Stride: What CISOs Must Do Right Now

Read More
Iran Cyber War, Day 32: FBI Director Breached, Critical Infrastructure Under Siege, and the Silence That Should Worry You Most
Iran Cyber War, Day 32: FBI Director Breached, Critical Infrastructure Under Siege, and the Silence That Should Worry You Most
Published on:
March 31, 2026
Blog

Iran Cyber War, Day 32: FBI Director Breached, Critical Infrastructure Under Siege, and the Silence That Should Worry You Most

Read More
When Ceasefires Don’t Apply to Cyberspace: 30 Days Into the Iran Cyber War, the Threat Has Never Been Higher
When Ceasefires Don’t Apply to Cyberspace: 30 Days Into the Iran Cyber War, the Threat Has Never Been Higher
Published on:
March 30, 2026
Blog

When Ceasefires Don’t Apply to Cyberspace: 30 Days Into the Iran Cyber War, the Threat Has Never Been Higher

Read More
When the Bombs Pause, the Hackers Don't: Iran's Cyber War Enters Its Most Dangerous Phase
When the Bombs Pause, the Hackers Don't: Iran's Cyber War Enters Its Most Dangerous Phase
Published on:
March 27, 2026
Blog

When the Bombs Pause, the Hackers Don't: Iran's Cyber War Enters Its Most Dangerous Phase

Read More
When Ransomware Meets Statecraft: Iran's Cyber War Enters Its Most Dangerous Phase
When Ransomware Meets Statecraft: Iran's Cyber War Enters Its Most Dangerous Phase
Published on:
March 26, 2026
Blog

When Ransomware Meets Statecraft: Iran's Cyber War Enters Its Most Dangerous Phase

Read More
Iran’s Cyber War Enters Its Mature Phase: What CISOs Must Act On Now
Iran’s Cyber War Enters Its Mature Phase: What CISOs Must Act On Now
Published on:
March 25, 2026
Blog

Iran’s Cyber War Enters Its Mature Phase: What CISOs Must Act On Now

Read More
Iran's Cyber War Enters Its Fourth Week: What CISOs Must Do Now
Iran's Cyber War Enters Its Fourth Week: What CISOs Must Do Now
Published on:
March 24, 2026
Blog

Iran's Cyber War Enters Its Fourth Week: What CISOs Must Do Now

Read More
Iran's Cyber War Enters a New Phase: State-directed Destruction, Synchronized Strikes, and the 24-Hour Reconstitution Problem
Iran's Cyber War Enters a New Phase: State-directed Destruction, Synchronized Strikes, and the 24-Hour Reconstitution Problem
Published on:
March 23, 2026
Blog

Iran's Cyber War Enters a New Phase: State-directed Destruction, Synchronized Strikes, and the 24-Hour Reconstitution Problem

Read More
Iran's Cyber War Machine Is Damaged — But Still Firing. Here's What CISOs Need to Know Now.
Iran's Cyber War Machine Is Damaged — But Still Firing. Here's What CISOs Need to Know Now.
Published on:
March 20, 2026
Blog

Iran's Cyber War Machine Is Damaged — But Still Firing. Here's What CISOs Need to Know Now.

Read More
Daily CTI Cycle: Geopolitical/Military on Iran
Daily CTI Cycle: Geopolitical/Military on Iran
Published on:
March 19, 2026
Blog

Daily CTI Cycle: Geopolitical/Military on Iran

Read More
Iran's Cyber War Enters a Dangerous New Phase: What CISOs Must Do Now
Iran's Cyber War Enters a Dangerous New Phase: What CISOs Must Do Now
Published on:
March 18, 2026
Blog

Iran's Cyber War Enters a Dangerous New Phase: What CISOs Must Do Now

Read More
Iran's Cyber War Enters a New Phase: No Malware Needed — What CISOs Must Do Now
Iran's Cyber War Enters a New Phase: No Malware Needed — What CISOs Must Do Now
Published on:
March 17, 2026
Blog

Iran's Cyber War Enters a New Phase: No Malware Needed — What CISOs Must Do Now

Read More
The Cyber Front Is Now a Killing Field: What CISOs Must Know About the Iran Conflict at Day 16
The Cyber Front Is Now a Killing Field: What CISOs Must Know About the Iran Conflict at Day 16
Published on:
March 16, 2026
Blog

The Cyber Front Is Now a Killing Field: What CISOs Must Know About the Iran Conflict at Day 16

Read More
The Iran Cyber War Just Hit Home: What CISOs Need to Know Right Now
The Iran Cyber War Just Hit Home: What CISOs Need to Know Right Now
Published on:
March 13, 2026
Blog

The Iran Cyber War Just Hit Home: What CISOs Need to Know Right Now

Read More
Iran's Cyber War Has Gone Destructive: What CISOs Need to Know Right Now
Iran's Cyber War Has Gone Destructive: What CISOs Need to Know Right Now
Published on:
March 12, 2026
Blog

Iran's Cyber War Has Gone Destructive: What CISOs Need to Know Right Now

Read More
Iran's Cyber War Is Here: What CISOs Need to Know Right Now
Iran's Cyber War Is Here: What CISOs Need to Know Right Now
Published on:
March 11, 2026
Blog

Iran's Cyber War Is Here: What CISOs Need to Know Right Now

Read More
The Iran Conflict’s Cyber Front Is Escalating - And the Most Dangerous Phase Is Still Ahead
The Iran Conflict’s Cyber Front Is Escalating - And the Most Dangerous Phase Is Still Ahead
Published on:
March 10, 2026
Blog

The Iran Conflict’s Cyber Front Is Escalating - And the Most Dangerous Phase Is Still Ahead

Read More
The Silence Before the Storm: Iran's Cyber War Has Moved From Warning to Confirmed Compromise
The Silence Before the Storm: Iran's Cyber War Has Moved From Warning to Confirmed Compromise
Published on:
March 9, 2026
Blog

The Silence Before the Storm: Iran's Cyber War Has Moved From Warning to Confirmed Compromise

Read More
When “Quiet" Means Pre-Positioned: Why Iranian Cyber Threats Are More Dangerous Than Headlines Suggest
When “Quiet" Means Pre-Positioned: Why Iranian Cyber Threats Are More Dangerous Than Headlines Suggest
Published on:
March 6, 2026
Blog

When “Quiet" Means Pre-Positioned: Why Iranian Cyber Threats Are More Dangerous Than Headlines Suggest

Read More
The Deceptive Lull: Why the Iran Cyber Conflict's Real Threat Isn't the One Making Headlines
The Deceptive Lull: Why the Iran Cyber Conflict's Real Threat Isn't the One Making Headlines
Published on:
March 5, 2026
Blog

The Deceptive Lull: Why the Iran Cyber Conflict's Real Threat Isn't the One Making Headlines

Read More
The Silence Before the Storm: Why Saudi Arabia's Financial Sector Faces Its Most Dangerous Cyber Threat Window in a Decade
The Silence Before the Storm: Why Saudi Arabia's Financial Sector Faces Its Most Dangerous Cyber Threat Window in a Decade
Published on:
March 4, 2026
Blog

The Silence Before the Storm: Why Saudi Arabia's Financial Sector Faces Its Most Dangerous Cyber Threat Window in a Decade

Read More
When the Supreme Leader Falls: What Iran's Cyber Arsenal Means for Your Organization Right Now
When the Supreme Leader Falls: What Iran's Cyber Arsenal Means for Your Organization Right Now
Published on:
March 4, 2026
Blog

When the Supreme Leader Falls: What Iran's Cyber Arsenal Means for Your Organization Right Now

Read More
The Cyber Front of Operation Epic Fury: What CISOs Need to Know Right Now
The Cyber Front of Operation Epic Fury: What CISOs Need to Know Right Now
Published on:
March 3, 2026
Blog

The Cyber Front of Operation Epic Fury: What CISOs Need to Know Right Now

Read More
Anomali Cyber Watch: Iran Cyber Threat, Scattered Lapsus$ Hunters Recruits, Medusa Ransomware, and more
Anomali Cyber Watch: Iran Cyber Threat, Scattered Lapsus$ Hunters Recruits, Medusa Ransomware, and more
Published on:
March 3, 2026
Blog

Anomali Cyber Watch: Iran Cyber Threat, Scattered Lapsus$ Hunters Recruits, Medusa Ransomware, and more

Read More
Iran's Cyber Retaliation Clock Is Ticking: What CISOs Need to Know Right Now
Iran's Cyber Retaliation Clock Is Ticking: What CISOs Need to Know Right Now
Published on:
March 2, 2026
Blog

Iran's Cyber Retaliation Clock Is Ticking: What CISOs Need to Know Right Now

Read More
Israel in Focus: Iran Retaliatory Posture
Israel in Focus: Iran Retaliatory Posture
Published on:
February 28, 2026
Blog

Israel in Focus: Iran Retaliatory Posture

Read More
Cyber Threat Briefing: Iran Retaliatory Posture
Cyber Threat Briefing: Iran Retaliatory Posture
Published on:
February 28, 2026
Blog

Cyber Threat Briefing: Iran Retaliatory Posture

Read More
Anomali Cyber Watch: LockBit 5.0, Chrome Zero-Day CVE-2026-2441, Infostealer Targets OpenClaw, and more
Anomali Cyber Watch: LockBit 5.0, Chrome Zero-Day CVE-2026-2441, Infostealer Targets OpenClaw, and more
Published on:
February 24, 2026
Blog

Anomali Cyber Watch: LockBit 5.0, Chrome Zero-Day CVE-2026-2441, Infostealer Targets OpenClaw, and more

Read More
Anomali Cyber Watch: Zero-Click Affects Claude, SolarWinds Vulnerabilities for Velociraptor and more
Anomali Cyber Watch: Zero-Click Affects Claude, SolarWinds Vulnerabilities for Velociraptor and more
Published on:
February 17, 2026
Blog

Anomali Cyber Watch: Zero-Click Affects Claude, SolarWinds Vulnerabilities for Velociraptor and more

Read More
Anomali Cyber Watch: Notepad++ Attack, RAT Uses Hugging Face, Microsoft Office Flaw and more
Anomali Cyber Watch: Notepad++ Attack, RAT Uses Hugging Face, Microsoft Office Flaw and more
Published on:
February 10, 2026
Blog

Anomali Cyber Watch: Notepad++ Attack, RAT Uses Hugging Face, Microsoft Office Flaw and more

Read More
Anomali Cyber Watch: Stanley Malware Toolkit, ShinyHunters, Vulnerability in WhatsApp and more
Anomali Cyber Watch: Stanley Malware Toolkit, ShinyHunters, Vulnerability in WhatsApp and more
Published on:
February 3, 2026
Blog

Anomali Cyber Watch: Stanley Malware Toolkit, ShinyHunters, Vulnerability in WhatsApp and more

Read More
Anomali Cyber Watch: Evelyn Stealer Abuses, PDFSider Malware, Open-Source Tools Deploy RAT and more
Anomali Cyber Watch: Evelyn Stealer Abuses, PDFSider Malware, Open-Source Tools Deploy RAT and more
Published on:
January 27, 2026
Blog

Anomali Cyber Watch: Evelyn Stealer Abuses, PDFSider Malware, Open-Source Tools Deploy RAT and more

Read More
Anomali Cyber Watch: Remcos RAT, BitB phishing, Linux Malware Framework, Supply Chain Intrusion and more
Anomali Cyber Watch: Remcos RAT, BitB phishing, Linux Malware Framework, Supply Chain Intrusion and more
Published on:
January 20, 2026
Blog

Anomali Cyber Watch: Remcos RAT, BitB phishing, Linux Malware Framework, Supply Chain Intrusion and more

Read More
Anomali Cyber Watch: Cisco ISE Flaw, Ni8mare, N8scape, Zero-Click Prompt Injection and more
Anomali Cyber Watch: Cisco ISE Flaw, Ni8mare, N8scape, Zero-Click Prompt Injection and more
Published on:
January 13, 2026
Blog

Anomali Cyber Watch: Cisco ISE Flaw, Ni8mare, N8scape, Zero-Click Prompt Injection and more

Read More
Anomali Cyber Watch: OWASP Agentic AI, MongoBleed, WebRAT Malware, and more
Anomali Cyber Watch: OWASP Agentic AI, MongoBleed, WebRAT Malware, and more
Published on:
January 6, 2026
Blog

Anomali Cyber Watch: OWASP Agentic AI, MongoBleed, WebRAT Malware, and more

Read More
Anomali Cyber Watch: SantaStealer Threat, Christmas Scams of 2025, React2Shell Exploit, Phishing via ISO, and more
Anomali Cyber Watch: SantaStealer Threat, Christmas Scams of 2025, React2Shell Exploit, Phishing via ISO, and more
Published on:
December 23, 2025
Blog

Anomali Cyber Watch: SantaStealer Threat, Christmas Scams of 2025, React2Shell Exploit, Phishing via ISO, and more

Read More
Anomali Cyber Watch: GhostPenguin, SharePoint Exploits, Android Spyware, CastleLoader Malware Expansion, and more
Anomali Cyber Watch: GhostPenguin, SharePoint Exploits, Android Spyware, CastleLoader Malware Expansion, and more
Published on:
December 16, 2025
Blog

Anomali Cyber Watch: GhostPenguin, SharePoint Exploits, Android Spyware, CastleLoader Malware Expansion, and more

Read More
Anomali Cyber Watch: React and Next.js RCE Vulnerabilities, "Evil Twin" Wifi Networks, Record 29.7 Tbps DDoS Attack, and More
Anomali Cyber Watch: React and Next.js RCE Vulnerabilities, "Evil Twin" Wifi Networks, Record 29.7 Tbps DDoS Attack, and More
Published on:
December 9, 2025
Blog

Anomali Cyber Watch: React and Next.js RCE Vulnerabilities, "Evil Twin" Wifi Networks, Record 29.7 Tbps DDoS Attack, and More

Read More
Anomali Cyber Watch: ShadowPad Backdoor, Password Strength Analysis, HashJack, FlexibleFerret, and More
Anomali Cyber Watch: ShadowPad Backdoor, Password Strength Analysis, HashJack, FlexibleFerret, and More
Published on:
December 2, 2025
Blog

Anomali Cyber Watch: ShadowPad Backdoor, Password Strength Analysis, HashJack, FlexibleFerret, and More

Read More
Anomali Cyber Watch: New Chrome Zero-Day, Sneaky 2FA Phishing Kit, DigitStealer, APT24 "BadAudio" Malware, and More
Anomali Cyber Watch: New Chrome Zero-Day, Sneaky 2FA Phishing Kit, DigitStealer, APT24 "BadAudio" Malware, and More
Published on:
November 25, 2025
Blog

Anomali Cyber Watch: New Chrome Zero-Day, Sneaky 2FA Phishing Kit, DigitStealer, APT24 "BadAudio" Malware, and More

Read More
Anomali Cyber Watch: OWASP Top Ten Updates, AI Voice Scams, DanaBot Malware, Lumma Stealer, and More
Anomali Cyber Watch: OWASP Top Ten Updates, AI Voice Scams, DanaBot Malware, Lumma Stealer, and More
Published on:
November 18, 2025
Blog

Anomali Cyber Watch: OWASP Top Ten Updates, AI Voice Scams, DanaBot Malware, Lumma Stealer, and More

Read More
Anomali Cyber Watch: SesameOp Backdoor, DragonForce Cartel, Gootloader Malware, and More
Anomali Cyber Watch: SesameOp Backdoor, DragonForce Cartel, Gootloader Malware, and More
Published on:
November 11, 2025
Blog

Anomali Cyber Watch: SesameOp Backdoor, DragonForce Cartel, Gootloader Malware, and More

Read More
Anomali Cyber Watch: Typosquatted npm Packages, Qilin Ransomware, New Water Saci Campaign, and More
Anomali Cyber Watch: Typosquatted npm Packages, Qilin Ransomware, New Water Saci Campaign, and More
Published on:
November 4, 2025
Blog

Anomali Cyber Watch: Typosquatted npm Packages, Qilin Ransomware, New Water Saci Campaign, and More

Read More
Anomali Cyber Watch: "ROBOT" Malware Suite, GlassWorm, Vidar Stealer 2.0, and More
Anomali Cyber Watch: "ROBOT" Malware Suite, GlassWorm, Vidar Stealer 2.0, and More
Published on:
October 28, 2025
Blog

Anomali Cyber Watch: "ROBOT" Malware Suite, GlassWorm, Vidar Stealer 2.0, and More

Read More
Anomali Cyber Watch: F5 Breach, Mysterious Elephant APT, Malicious MCP Servers, and More
Anomali Cyber Watch: F5 Breach, Mysterious Elephant APT, Malicious MCP Servers, and More
Published on:
October 21, 2025
Blog

Anomali Cyber Watch: F5 Breach, Mysterious Elephant APT, Malicious MCP Servers, and More

Read More
Anomali Cyber Watch: Oracle E-Business Suite Zero-Day, Vampire Bot Malware, XWorm 6.0, and More
Anomali Cyber Watch: Oracle E-Business Suite Zero-Day, Vampire Bot Malware, XWorm 6.0, and More
Published on:
October 14, 2025
Blog

Anomali Cyber Watch: Oracle E-Business Suite Zero-Day, Vampire Bot Malware, XWorm 6.0, and More

Read More
Anomali Cyber Watch: Phantom Taurus, MatrixPDF, Klopatra, and More
Anomali Cyber Watch: Phantom Taurus, MatrixPDF, Klopatra, and More
Published on:
October 7, 2025
Blog

Anomali Cyber Watch: Phantom Taurus, MatrixPDF, Klopatra, and More

Read More
Anomali Cyber Watch: Nimbus Manticore, Spoofed IC3 Portals, a Record-Breaking DDoS Attack, and More
Anomali Cyber Watch: Nimbus Manticore, Spoofed IC3 Portals, a Record-Breaking DDoS Attack, and More
Published on:
September 30, 2025
Blog

Anomali Cyber Watch: Nimbus Manticore, Spoofed IC3 Portals, a Record-Breaking DDoS Attack, and More

Read More
Anomali Cyber Watch: FileFix Phishing, AI-Driven Pen-Testing, the Return of Scattered Spider, and More
Anomali Cyber Watch: FileFix Phishing, AI-Driven Pen-Testing, the Return of Scattered Spider, and More
Published on:
September 23, 2025
Blog

Anomali Cyber Watch: FileFix Phishing, AI-Driven Pen-Testing, the Return of Scattered Spider, and More

Read More
Anomali Cyber Watch: Salesloft Drift Breach, Salty2FA Phishing, GPUGate Malware, and More
Anomali Cyber Watch: Salesloft Drift Breach, Salty2FA Phishing, GPUGate Malware, and More
Published on:
September 16, 2025
Blog

Anomali Cyber Watch: Salesloft Drift Breach, Salty2FA Phishing, GPUGate Malware, and More

Read More
Anomali Cyber Watch: APT 29, APT37, Silver Fox, Grok AI Exploits, and More
Anomali Cyber Watch: APT 29, APT37, Silver Fox, Grok AI Exploits, and More
Published on:
September 9, 2025
Blog

Anomali Cyber Watch: APT 29, APT37, Silver Fox, Grok AI Exploits, and More

Read More
Anomali Cyber Watch: PromptLock Ransomware, Blind Eagle, Lovable Website Attacks, and More
Anomali Cyber Watch: PromptLock Ransomware, Blind Eagle, Lovable Website Attacks, and More
Published on:
September 2, 2025
Blog

Anomali Cyber Watch: PromptLock Ransomware, Blind Eagle, Lovable Website Attacks, and More

Read More
Anomali Cyber Watch: Noodlophile Stealer, GodRAT, Apple ImageIO Zero-Day, and More
Anomali Cyber Watch: Noodlophile Stealer, GodRAT, Apple ImageIO Zero-Day, and More
Published on:
August 26, 2025
Blog

Anomali Cyber Watch: Noodlophile Stealer, GodRAT, Apple ImageIO Zero-Day, and More

Read More
Anomali Cyber Watch: WinRAR Malware, Erlang OTP Exploitation, Charon Ransomware, and More
Anomali Cyber Watch: WinRAR Malware, Erlang OTP Exploitation, Charon Ransomware, and More
Published on:
August 19, 2025
Blog

Anomali Cyber Watch: WinRAR Malware, Erlang OTP Exploitation, Charon Ransomware, and More

Read More
Anomali Cyber Watch: PXA Stealer, ClickFix Malware, Fake TikTok Shops, Throttlestop, and More
Anomali Cyber Watch: PXA Stealer, ClickFix Malware, Fake TikTok Shops, Throttlestop, and More
Published on:
August 12, 2025
Blog

Anomali Cyber Watch: PXA Stealer, ClickFix Malware, Fake TikTok Shops, Throttlestop, and More

Read More
Detecting the ToolShell SharePoint Exploit
Detecting the ToolShell SharePoint Exploit
Published on:
August 11, 2025
Blog

Detecting the ToolShell SharePoint Exploit

Read More
Anomali Cyber Watch: SHUYAL Infostealer, PyPI Phishing Campaign, Gunra Ransomware, UNC2891, and More
Anomali Cyber Watch: SHUYAL Infostealer, PyPI Phishing Campaign, Gunra Ransomware, UNC2891, and More
Published on:
August 4, 2025
Blog

Anomali Cyber Watch: SHUYAL Infostealer, PyPI Phishing Campaign, Gunra Ransomware, UNC2891, and More

Read More
Anomali Cyber Watch: APT41, PoisonSeed Attacks, ToolShell Vulnerability, DCHSpy, Android Malware, and More
Anomali Cyber Watch: APT41, PoisonSeed Attacks, ToolShell Vulnerability, DCHSpy, Android Malware, and More
Published on:
July 28, 2025
Blog

Anomali Cyber Watch: APT41, PoisonSeed Attacks, ToolShell Vulnerability, DCHSpy, Android Malware, and More

Read More
Anomali Cyber Watch: Interlock RAT, North Koreans Flood npm Registry, Stealthy WordPress PHP Malware, and Semiconductor Sector Hacks
Anomali Cyber Watch: Interlock RAT, North Koreans Flood npm Registry, Stealthy WordPress PHP Malware, and Semiconductor Sector Hacks
Published on:
July 22, 2025
Blog

Anomali Cyber Watch: Interlock RAT, North Koreans Flood npm Registry, Stealthy WordPress PHP Malware, and Semiconductor Sector Hacks

Read More
Explore More Resources