# threat-intelligence

Published articles for threat-intelligence.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026

DevFeed: [CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026](<https://devfeed.tech/articles/crowdstrike-named-a-leader-in-the-forrester-wavetm-external-threat-intelligence-service-providers-q3-2026-42119.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-named-leader-forrester-wave-external-threat-intelligence-q3-2026/>)

Author: Counter Adversary Operations

Published: 2026-09-18T01:40:54.157408Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-hunting-intel](<https://devfeed.tech/tags/threat-hunting-intel.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

CrowdStrike was named a Leader in Forrester's Q3 2026 External Threat Intelligence Service Providers evaluation, receiving the highest scores for Strength of Offering and Strength of Strategy. The article highlights platform-native intelligence, endpoint telemetry, threat hunting, vulnerability intelligence, malware analysis, and external threat data.

### Source excerpt

CrowdStrike has been named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026, receiving the highest scores in both Strength of Offering and Strength of Strategy. Learn more!

## Atomic macOS (AMOS) Stealer Activity

DevFeed: [Atomic macOS (AMOS) Stealer Activity](<https://devfeed.tech/articles/atomic-macos-amos-stealer-activity-30906.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/>)

Author: Bradley Duncan

Published: 2026-09-16T10:00:06Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Aeternum](<https://devfeed.tech/topics/aeternum.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Zsh](<https://devfeed.tech/topics/zsh.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [curl](<https://devfeed.tech/tags/curl.md>), [general](<https://devfeed.tech/tags/general.md>), [insights](<https://devfeed.tech/tags/insights.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [unit-42](<https://devfeed.tech/tags/unit-42.md>), [zsh](<https://devfeed.tech/tags/zsh.md>)

### AI overview

This article analyzes a laboratory-generated Atomic macOS (AMOS) stealer infection observed on Aug. 5, 2026. It describes a deceptive macOS toolkit installation page that led users to paste a command into Terminal, retrieving a Zsh script containing an encoded compressed payload and a follow-up script designed to run a Mach-O binary. AMOS targets macOS and can exfiltrate system information, login credentials, and sensitive data from applications including browsers and cryptocurrency wallets.

### Source excerpt

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

## The Dodo Digest: The Report Is the Product

DevFeed: [The Dodo Digest: The Report Is the Product](<https://devfeed.tech/articles/the-dodo-digest-the-report-is-the-product-26683.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/newsletter-september15/>)

Author: Rishabh Goel

Published: 2026-09-15T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [product](<https://devfeed.tech/tags/product.md>), [report](<https://devfeed.tech/tags/report.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [v1](<https://devfeed.tech/tags/v1.md>)

### AI overview

This newsletter discusses Anthropic's report on eight months of AI misuse, including a campaign in which one person built an AI-assisted platform for mass attacks. It argues that startups can use reports to document learning, demonstrate expertise, and build trust, and mentions Dodo Payments v1.113.28 product improvements.

### Source excerpt

Anthropic turned eight months of threat intelligence into a public report. Why every startup should document what it learns, plus v1.113.28: Reports, grace periods, and blocklists.

## SpectrePaste: An AI-Assisted, Fileless PowerShell Malware Delivery System

DevFeed: [SpectrePaste: An AI-Assisted, Fileless PowerShell Malware Delivery System](<https://devfeed.tech/articles/spectrepaste-22546.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/spectrepaste-b20bc2f6ded8?source=rss----905ea2b3d4d1---4>)

Author: Joshua Platt

Published: 2026-07-06T18:54:30Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Polymorphism](<https://devfeed.tech/topics/polymorphism.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Spec Driven Development](<https://devfeed.tech/topics/spec-driven-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [backend](<https://devfeed.tech/tags/backend.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cache](<https://devfeed.tech/tags/cache.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [polymorphism](<https://devfeed.tech/tags/polymorphism.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [spec-driven-development](<https://devfeed.tech/tags/spec-driven-development.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

The article describes SpectrePaste, a previously undocumented fileless malware delivery system that threat actors used with AI as its primary orchestrator and developer. Its early architecture included automated AMSI-bypass generation, XOR-encrypted payloads, resilient command-and-control traffic handling, caching, request queuing, and administrative priority routing.

### Source excerpt

by Joshua Platt and Jason Reaves [TLP:CLEAR] Earlier this year, Google Threat Intelligence[1] reported threat actors are increasingly deploying novel, AI-enabled malware in active operations[2]. While investigating a recent OSINT article[3] on malware campaign activity reported as "DeepLoad", our threat intelligence team identified a separate, previously undocumented fileless delivery system we track as "SpectrePaste". The prior public reporting correctly suspected AI involvement in the "DeepLoad" delivery chain, but our analysis reveals a more conclusive and concerning reality. AI did not just play a supporting role. It acted as the primary orchestrator and developer behind the entire SpectrePaste system. Threat actors internally referred to the early system as "PasteFast Panel." In this initial iteration, the system was highly modular, structured, and designed specifically for resilience against high-volume bot traffic. One of the hallmarks of automated, AI-assisted development. The early architecture functioned as a centralized PowerShell payload delivery system with several notable features: Automated Evasion Generation: The paste builder module automatically prepended Anti-Malware Scan Interface (AMSI) bypass scripts to payloads upon creation, followed by XOR encryption using a custom obfuscator template. This ensured every payload served was dynamically packed. C2 Resilience & High-Load Handling: The most sophisticated feature of the early version was its custom cache manager queue system. The threat actors anticipated massive, simultaneous beaconing from compromised hosts. To prevent database exhaustion, the panel featured an automated threshold toggle. During traffic spikes, the system queued requests, cached the encrypted payloads in memory, and deduplicated IP addresses to ensure a single infected bot could not inadvertently DDoS the command server. Admin Priority Routing: Developer requirements explicitly prioritized operator access. Administrative routes

## AI threats in the wild: The current state of prompt injections on the web

DevFeed: [AI threats in the wild: The current state of prompt injections on the web](<https://devfeed.tech/articles/ai-threats-in-the-wild-the-current-state-of-prompt-injections-on-the-web-19817.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html>)

Author: Kimberly Samra (noreply@blogger.com)

Published: 2026-04-23T21:38:00Z

Content type: article

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Google](<https://devfeed.tech/topics/google.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [google](<https://devfeed.tech/tags/google.md>), [none](<https://devfeed.tech/tags/none.md>), [prompt](<https://devfeed.tech/tags/prompt.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [snapshots](<https://devfeed.tech/tags/snapshots.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Google Threat Intelligence teams describe a public-web investigation into indirect prompt injection, an attack in which malicious instructions embedded in websites, emails, or documents can redirect an AI system away from the user's intent. The article examines whether real-world attackers are operationalizing these attacks and uses Common Crawl snapshots to study known patterns.

### Source excerpt

Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting this vector today - and if so, how? To answer these questions and to uncover real-world abuse, we initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found. The threat of indirect prompt injection Unlike a direct injection where a user "jailbreaks" a chatbot, IPI occurs when an AI system processes content--like a website, email, or document--that contains malicious instructions. When the AI reads this poisoned content, it may silently follow the attacker's commands instead of the user's original intent. This is not a new area of concern for us and Google has been working tirelessly to combat these threats. Our efforts involve cross-functional collaboration between researchers at Google DeepMind (GDM) and defenders like the Google Threat Intelligence Group (GTIG). We have previously detailed our work in this area and researchers have further highlighted the evolving nature of these vulnerabilities. Despite this collective focus, a fundamental question remains: to what degree are real-world malicious actors currently operationalizing these attacks? Proactive monitoring at GoogleThe landscape of IPI on the web There are many channels through which attackers might try to send prompt injections. However, one location is particularly easy to observe - the public web. Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them. Public research confirms these attacks are

## ETH Rangers Program Recap

DevFeed: [ETH Rangers Program Recap](<https://devfeed.tech/articles/eth-rangers-program-recap-17219.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2026/04/16/eth-rangers-recap>)

Author: Protocol Security Team; Grants Management Team

Published: 2026-04-16T00:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [DeFi](<https://devfeed.tech/topics/defi.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [defi](<https://devfeed.tech/tags/defi.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [root-cause-analysis](<https://devfeed.tech/tags/root-cause-analysis.md>), [security](<https://devfeed.tech/tags/security.md>), [smart-contract](<https://devfeed.tech/tags/smart-contract.md>), [state](<https://devfeed.tech/tags/state.md>), [talks](<https://devfeed.tech/tags/talks.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web3](<https://devfeed.tech/tags/web3.md>), [workshops](<https://devfeed.tech/tags/workshops.md>)

### AI overview

The Ethereum Foundation and partner organizations recap the six-month ETH Rangers Program, which funded 17 stipend recipients conducting public-goods security work across the Ethereum ecosystem. Reported outcomes include recovered or frozen funds, vulnerability and bug reports, threat-awareness work, security challenges, educational events, incident responses, and open-source tooling.

### Source excerpt

In late 2024, the Ethereum Foundation, together with Secureum, The Red Guild, and Security Alliance (SEAL), launched the ETH Rangers Program, an initiative to provide stipends for individuals doing public goods security work in the Ethereum ecosystem. The goal of the program was straightforward: to fund independent efforts that...

## Marriott Deploys Cisco Umbrella DNS-Layer Security Across Nearly 5,000 Properties to Block Access to CSAM

DevFeed: [Marriott Deploys Cisco Umbrella DNS-Layer Security Across Nearly 5,000 Properties to Block Access to CSAM](<https://devfeed.tech/articles/marriott-leads-the-way-in-the-fight-to-protect-children-online-20377.md>)

Original publisher: [Read original article](<https://umbrella.cisco.com/blog/marriott-leads-way-in-fight-to-protect-children-online>)

Author: Negisa Taymourian

Published: 2024-03-12T08:00:00Z

Content type: article

Language: en

Sources: [OpenDNS](<https://devfeed.tech/sources/opendns.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [customer-focus](<https://devfeed.tech/tags/customer-focus.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dns-layer-security](<https://devfeed.tech/tags/dns-layer-security.md>), [dns-security](<https://devfeed.tech/tags/dns-security.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [security](<https://devfeed.tech/tags/security.md>), [security-service-edge](<https://devfeed.tech/tags/security-service-edge.md>), [sse](<https://devfeed.tech/tags/sse.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

The article describes Marriott's deployment of Cisco Umbrella DNS-layer security across nearly 5,000 properties to block access to child sexual abuse materials and other malicious or unwanted domains. It highlights deployment speed, scalability, guest-network performance, manageability, and Cisco Talos threat intelligence.

### Source excerpt

Marriott has rapidly deployed Cisco DNS-layer security across thousands of properties to advance human rights by limiting access to CSAM materials. The post Marriott Leads the Way in the Fight to Protect Children Online appeared first on Cisco Umbrella.

## The ISPs sharing your DNS query data

DevFeed: [The ISPs sharing your DNS query data](<https://devfeed.tech/articles/the-isps-sharing-your-dns-query-data-41583.md>)

Original publisher: [Read original article](<https://blog.benjojo.co.uk/post/ISPs-sharing-DNS-query-data>)

Author: ben@benjojo.co.uk

Published: 2018-06-25T15:10:39Z

Content type: article

Language: en

Sources: [benjojo blog](<https://devfeed.tech/sources/benjojo-blog.md>)

Topics: [Internet](<https://devfeed.tech/topics/internet.md>), [Network](<https://devfeed.tech/topics/network.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [1.1.1.1](<https://devfeed.tech/topics/1-1-1-1.md>)

Tags: [1-1-1-1](<https://devfeed.tech/tags/1-1-1-1.md>), [cache](<https://devfeed.tech/tags/cache.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [dns](<https://devfeed.tech/tags/dns.md>), [internet](<https://devfeed.tech/tags/internet.md>), [logging](<https://devfeed.tech/tags/logging.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

The article investigates whether internet service providers share DNS query data with third parties. It explains how unencrypted DNS queries can be observed by network intermediaries and describes an experiment that sent ISP-specific queries to open resolvers to identify which infrastructure handled the lookups.

### Source excerpt

The ISPs sharing your DNS query data DNS is fundamental to how the web works, and for most of the population it's completely transparent. Everything on the web is accessed by a DNS name. Since DNS is an old protocol ([November 1987 in fact](http

## Encrypting IP Addresses

DevFeed: [Encrypting IP Addresses](<https://devfeed.tech/articles/encrypting-ip-addresses-36383.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/encrypting-ip-addresses/>)

Published: 2017-05-07T18:46:14Z

Content type: article

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security](<https://devfeed.tech/topics/security.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [encryption](<https://devfeed.tech/tags/encryption.md>), [internet](<https://devfeed.tech/tags/internet.md>), [networks](<https://devfeed.tech/tags/networks.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [traces](<https://devfeed.tech/tags/traces.md>)

### AI overview

The article examines encrypting IP addresses in network log files as a way to support security analysis while limiting immediate privacy impact. It discusses preserving IP address representation for existing tools and the limitations of zero-padding, XOR, stream ciphers, and block ciphers for encrypting 32-bit IPv4 addresses.

### Source excerpt

On IP address encryption: security analysis with respect for privacy Frequently, privacy concerns and regulations get in the way of security analysis. I'm a big fan of privacy, but I'm also a big fan of security and preventing people from getting hacked. If you are hacked you have no privacy either. Per-customer/subscriber traces are extremely useful for researching the security of networks. Specifically, lists of DNS requests per IP address make spotting infected users or infected devices very easy, especially if you look at "yesterday's traffic" and compare it to today's threat intelligence.