# Reconnaissance

A MITRE ATT&CK tactic in which adversaries gather information to support targeting and plan future operations.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike Delivers the Next Evolution of the Agentic SOC

DevFeed: [CrowdStrike Delivers the Next Evolution of the Agentic SOC](<https://devfeed.tech/articles/crowdstrike-delivers-the-next-evolution-of-the-agentic-soc-8304.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/>)

Author: Brandon Benke

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [data](<https://devfeed.tech/topics/data.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [identity](<https://devfeed.tech/tags/identity.md>), [network](<https://devfeed.tech/tags/network.md>), [operations](<https://devfeed.tech/tags/operations.md>), [platform](<https://devfeed.tech/tags/platform.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>)

### AI overview

CrowdStrike describes the next evolution of its agentic SOC, where analysts and AI agents work together in a unified system to investigate and respond to threats in real time. The Falcon platform combines data generation, enrichment, investigation, orchestration, and governance, with capabilities for detection-ready third-party data and coordinated specialist agents.

### Source excerpt

Expert agents that reason together, learn your environment, and run on data CrowdStrike owns. See how we deliver the agentic SOC. Learn more!

## AI-driven OSINT in the wrong hands - and why everyone could be a target for fraud

DevFeed: [AI-driven OSINT in the wrong hands - and why everyone could be a target for fraud](<https://devfeed.tech/articles/ai-driven-osint-in-the-wrong-hands-and-why-everyone-could-be-a-target-for-fraud-8392.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/privacy/ai-powered-osint-why-everyone-viable-target-fraud/>)

Author: Phil Muncaster

Published: 2026-08-27T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Web](<https://devfeed.tech/topics/web.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [research](<https://devfeed.tech/tags/research.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

AI-powered OSINT is making it faster and easier for cybercriminals to gather publicly available information about potential victims. By linking accounts, relationships, images, and videos at machine speed, these tools can make fraud and social engineering more convincing and scalable, lowering the barrier to entry for attackers.

### Source excerpt

It's getting cheaper and easier for cybercriminals to research potential victims. Here's what's still in your control.

## Frequently asked questions about the active threat to Siemens S7 Series PLCs

DevFeed: [Frequently asked questions about the active threat to Siemens S7 Series PLCs](<https://devfeed.tech/articles/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs-8263.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs>)

Author: Research Special Operations

Published: 2026-08-20T14:01:58Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Script](<https://devfeed.tech/topics/script.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [networks](<https://devfeed.tech/tags/networks.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

This FAQ explains an active threat targeting internet-exposed or insufficiently segmented Siemens S7 Series PLCs. It describes how threat actors use AI-generated exploitation scripts for reconnaissance and capability building, and outlines mitigations including removing direct internet exposure, segmenting OT from IT networks, and hardening access controls.

### Source excerpt

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs. The attackers are leveraging AI to build and refine exploit scripts faster than manual development would allow. AI use lowers the technical bar for ICS attacks in a way defenders haven't had to plan for before. There is no single patch, because there is no single flaw. Mitigation depends on removing Siemens S7 Series PLCs from direct internet exposure, segmenting OT from IT networks and hardening access controls. Background On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint Cybersecurity Advisory (AA26-231A) warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well. According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together this frequently asked questions (FAQ) blog to help security and OT

## What Is AI Pentesting and How Does It Work?

DevFeed: [What Is AI Pentesting and How Does It Work?](<https://devfeed.tech/articles/what-is-ai-pentesting-and-how-does-it-work-8244.md>)

Original publisher: [Read original article](<https://snyk.io/blog/what-is-ai-pentesting/>)

Author: Snyk Team

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [large-language-models](<https://devfeed.tech/topics/large-language-models.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [payload](<https://devfeed.tech/topics/payload.md>), [SQL](<https://devfeed.tech/topics/sql.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [interest](<https://devfeed.tech/tags/interest.md>), [large-language-models](<https://devfeed.tech/tags/large-language-models.md>), [models](<https://devfeed.tech/tags/models.md>), [payload](<https://devfeed.tech/tags/payload.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [sql](<https://devfeed.tech/tags/sql.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

AI pentesting uses reasoning-capable models, deterministic testing tools, independent validation, and target context to continuously find, exploit, and verify application vulnerabilities that traditional scanners may miss. The article explains its workflow and contrasts context-dependent flaws with heuristic-detectable issues such as SQL injection and misconfigurations.

### Source excerpt

AI pentesting uses reasoning-capable models to continuously find and validate the flaws scanners miss, especially broken authorization and business-logic abuse.

## Burp Extensibility 2026: Awards, Talks, and Highlights

DevFeed: [Burp Extensibility 2026: Awards, Talks, and Highlights](<https://devfeed.tech/articles/burp-extensibility-2026-awards-talks-and-highlights-7693.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/burp-extensibility-2026-awards-talks-and-highlights>)

Author: Fran Hutchings

Published: 2026-06-19T12:18:14Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Extension](<https://devfeed.tech/topics/extension.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [awards](<https://devfeed.tech/tags/awards.md>), [community](<https://devfeed.tech/tags/community.md>), [discord](<https://devfeed.tech/tags/discord.md>), [extension](<https://devfeed.tech/tags/extension.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workshops](<https://devfeed.tech/tags/workshops.md>)

### AI overview

PortSwigger's Extensibility Month highlighted Burp Suite extensions, Bambdas, and BChecks through talks, workshops, community sessions, and the 2026 Burp Extension Awards. The article summarizes the community-voted award process and notable tools for reconnaissance, authentication, access control, workflow manipulation, and vulnerability discovery.

### Source excerpt

The 2026 Burp Suite Extension Awards Best Recon & Discovery Best Auth & Access Control Best Workflow & Manipulation Best API & Specialist Testing Hidden Gem Most Nominated The talks In

## Mapping out your unknown: A threat hunter's guide to Salesforce

DevFeed: [Mapping out your unknown: A threat hunter's guide to Salesforce](<https://devfeed.tech/articles/mapping-out-your-unknown-a-threat-hunter-s-guide-to-salesforce-8292.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-salesforce/>)

Author: Julie Agnes Sparks

Published: 2026-06-16T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [API](<https://devfeed.tech/topics/api.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [data](<https://devfeed.tech/tags/data.md>), [guide](<https://devfeed.tech/tags/guide.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [post](<https://devfeed.tech/tags/post.md>), [saas](<https://devfeed.tech/tags/saas.md>), [salesforce](<https://devfeed.tech/tags/salesforce.md>), [security](<https://devfeed.tech/tags/security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

A threat-hunting guide to Salesforce that describes common attack paths, including compromised OAuth applications, stolen SSO and MFA credentials, resource discovery, data extraction, and ransomware. It provides detection queries and explains how Salesforce audit logging tiers support investigation, with queries mapped to MITRE ATT&CK tactics.

### Source excerpt

In this post, we walk through different threats to Salesforce and how to detect them.

## EvilTokens: A phishing attack that doesn't steal your password

DevFeed: [EvilTokens: A phishing attack that doesn't steal your password](<https://devfeed.tech/articles/eviltokens-a-phishing-attack-that-doesn-t-steal-your-password-8347.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/>)

Author: Christian Ali Bravo

Published: 2026-06-15T08:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [process](<https://devfeed.tech/tags/process.md>), [time](<https://devfeed.tech/tags/time.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

EvilTokens is a phishing-as-a-service kit that abuses Microsoft 365's OAuth 2.0 device authorization flow to compromise accounts without directly stealing passwords. Victims authenticate on Microsoft's genuine login page, unknowingly approving an attacker-controlled device; the resulting access and refresh tokens can enable account takeover and business email compromise.

### Source excerpt

A phishing kit subverting Microsoft's legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages

## Webworm: New burrowing techniques

DevFeed: [Webworm: New burrowing techniques](<https://devfeed.tech/articles/webworm-new-burrowing-techniques-8383.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/>)

Author: Eric Howard

Published: 2026-05-20T08:40:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Discord](<https://devfeed.tech/topics/discord.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [API](<https://devfeed.tech/topics/api.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bash](<https://devfeed.tech/tags/bash.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [github](<https://devfeed.tech/tags/github.md>), [ip](<https://devfeed.tech/tags/ip.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [s3](<https://devfeed.tech/tags/s3.md>), [server](<https://devfeed.tech/tags/server.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

ESET researchers analyze Webworm's 2025 activity, including its shift toward Europe, new Discord- and Microsoft Graph API-based backdoors, proxy tools, reconnaissance activity, and GitHub-hosted malware staging.

### Source excerpt

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

## As breakout time accelerates, prevention-first cybersecurity takes center stage

DevFeed: [As breakout time accelerates, prevention-first cybersecurity takes center stage](<https://devfeed.tech/articles/as-breakout-time-accelerates-prevention-first-cybersecurity-takes-center-stage-8326.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/breakout-time-accelerates-prevention-first-cybersecurity-center-stage/>)

Author: Phil Muncaster

Published: 2026-04-07T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-automation](<https://devfeed.tech/tags/ai-automation.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

Threat actors are using AI, automation, credential theft, phishing, zero-day exploits, reconnaissance, and AI-powered scripts to accelerate attacks. The article argues that shrinking breakout times require defenders to adopt a prevention-first cybersecurity strategy.

### Source excerpt

Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.

## Cyber fallout from the Iran war: What to have on your radar

DevFeed: [Cyber fallout from the Iran war: What to have on your radar](<https://devfeed.tech/articles/cyber-fallout-from-the-iran-war-what-to-have-on-your-radar-8329.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cyber-fallout-iran-war-what-have-radar/>)

Author: Tomáš Foltýn

Published: 2026-03-12T14:17:33Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [canada](<https://devfeed.tech/tags/canada.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [iran](<https://devfeed.tech/tags/iran.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The article examines the cybersecurity fallout from the Iran war, including attacks on AWS data centers and the rapid mobilization of pro-Iranian cyber groups. It describes hacktivism, APT reconnaissance and initial access, espionage, disruption, sabotage, and the heightened risks to organizations with Middle East supply-chain or cloud dependencies.

### Source excerpt

The cybersecurity implications of the war in the Middle East extend far beyond the region. Here's where to focus your defenses.

## The big catch: How whaling attacks target top executives

DevFeed: [The big catch: How whaling attacks target top executives](<https://devfeed.tech/articles/the-big-catch-how-whaling-attacks-target-top-executives-8321.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/big-catch-how-whaling-attacks-target-top-executives/>)

Author: Phil Muncaster

Published: 2025-12-09T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Vishing](<https://devfeed.tech/topics/vishing.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [vishing](<https://devfeed.tech/tags/vishing.md>)

### AI overview

This article explains whaling attacks, a form of targeted phishing, vishing, smishing, or business email compromise aimed at senior corporate executives. It describes how attackers exploit executives' limited time, public visibility, and access to sensitive information and financial authority, including through malware-laced Zoom invitations and detailed reconnaissance.

### Source excerpt

Is your organization's senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.

## Exploiting a custom tetris game in CSAW Quals 2020

DevFeed: [Exploiting a custom tetris game in CSAW Quals 2020](<https://devfeed.tech/articles/exploiting-a-custom-tetris-game-in-csaw-quals-2020-39679.md>)

Original publisher: [Read original article](<https://mahaloz.re/2020/09/13/csaw-quals-2020-blox.html>)

Published: 2020-09-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [mahaloz.re](<https://devfeed.tech/sources/mahaloz-re.md>)

Topics: [Code](<https://devfeed.tech/topics/code.md>), [arcade](<https://devfeed.tech/topics/arcade.md>), [Ghidra](<https://devfeed.tech/topics/ghidra.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [ctf](<https://devfeed.tech/tags/ctf.md>), [game](<https://devfeed.tech/tags/game.md>), [ghidra](<https://devfeed.tech/tags/ghidra.md>), [pwn](<https://devfeed.tech/tags/pwn.md>), [reversing](<https://devfeed.tech/tags/reversing.md>), [solve](<https://devfeed.tech/tags/solve.md>), [writeup](<https://devfeed.tech/tags/writeup.md>)

### AI overview

This writeup explains how a custom Tetris game in CSAW Quals 2020 was analyzed and exploited. The challenge involved discovering cheat-piece placements, obtaining the binary, reverse-engineering its checks, and using an out-of-bounds write to obtain a partial write primitive and ultimately the flag.

### Source excerpt

Pwning a custom Tetris game through an out-of-bounds write to memory through block manipulation and changes to the `.text` segment.