<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Threat Advisories</title>
    <link>https://www.uvcyber.com/resources/threat-advisories</link>
    <description>Stay ahead of threats with UltraViolet TIDE. Browse all threat advisories and in-depth reports for actionable insights, IOCs, and mitigation strategies.</description>
    <language>en</language>
    <pubDate>Tue, 06 Oct 2026 18:44:21 GMT</pubDate>
    <dc:date>2026-10-06T18:44:21Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Threat Advisory: NeedyMantis Malware</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-needymantis-malware</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-needymantis-malware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/0-2769105407376612907.png" alt="Threat Advisory: NeedyMantis Malware" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;NeedyMantis is a modular post-compromise malware framework Microsoft disclosed on September 28, 2026. It was observed in targeted intrusions dating back to at least October 2025. It matters because of what it represents, not just what it does: a purpose-built tool used specifically after an attacker already has a foothold, designed to maintain long-term access and quietly extend an operator's capabilities through additional modules. The malware's architecture, built around custom encrypted archives, disguised file formats, and DLL sideloading into trusted software, is engineered specifically to resist analysis and blend into legitimate activity. The malware's use has been tied to Storm-3069, the actor behind the DAEMON Tools supply-chain compromise, and observed activity aligns with patterns Microsoft associates with China-based threat actors (though full attribution to a single operator remains unconfirmed). Victims have spanned the telecommunication industry, universities, medical nonprofits, intergovernmental organizations, and government contractors. This indicates a selective targeting pattern consistent with deliberate intelligence-gathering rather than more simple criminal intent.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Monitor for DLL sideloading into known legitimate applications, particularly unexpected DLLs bundled alongside common open-source tools.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Watch for outbound network connections using unusual or outdated user-agent strings inconsistent with the initiating application.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Flag hands-on-keyboard activity involving credential and lateral-movement toolkits following any suspected initial compromise.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Extend monitoring to post-compromise behavior, not just initial access, since this malware is deployed after a foothold already exists.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity. UltraViolet is also maximizing detection coverage proactively through Equinox.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory_NeedyMantis_sept30_2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-needymantis-malware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/0-2769105407376612907.png" alt="Threat Advisory: NeedyMantis Malware" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;NeedyMantis is a modular post-compromise malware framework Microsoft disclosed on September 28, 2026. It was observed in targeted intrusions dating back to at least October 2025. It matters because of what it represents, not just what it does: a purpose-built tool used specifically after an attacker already has a foothold, designed to maintain long-term access and quietly extend an operator's capabilities through additional modules. The malware's architecture, built around custom encrypted archives, disguised file formats, and DLL sideloading into trusted software, is engineered specifically to resist analysis and blend into legitimate activity. The malware's use has been tied to Storm-3069, the actor behind the DAEMON Tools supply-chain compromise, and observed activity aligns with patterns Microsoft associates with China-based threat actors (though full attribution to a single operator remains unconfirmed). Victims have spanned the telecommunication industry, universities, medical nonprofits, intergovernmental organizations, and government contractors. This indicates a selective targeting pattern consistent with deliberate intelligence-gathering rather than more simple criminal intent.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Monitor for DLL sideloading into known legitimate applications, particularly unexpected DLLs bundled alongside common open-source tools.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Watch for outbound network connections using unusual or outdated user-agent strings inconsistent with the initiating application.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Flag hands-on-keyboard activity involving credential and lateral-movement toolkits following any suspected initial compromise.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Extend monitoring to post-compromise behavior, not just initial access, since this malware is deployed after a foothold already exists.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity. UltraViolet is also maximizing detection coverage proactively through Equinox.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory_NeedyMantis_sept30_2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-needymantis-malware&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 30 Sep 2026 19:02:22 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-needymantis-malware</guid>
      <dc:date>2026-09-30T19:02:22Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: The Dangers of Long Dwell Malware</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-dangers-of-long-dwell-malware</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-dangers-of-long-dwell-malware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/0-5276483784011767953.png" alt="Threat Advisory: The Dangers of Long Dwell Malware" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Long dwell malware refers to tools built not for speed, but for stealth and deeper penetration of targets. Imagine code designed to sit undetected inside a network for months or, in extreme cases, years while quietly collecting intelligence, harvesting credentials, or preparing for a later, more damaging action. This category represents one of the more monumental shifts in the current threat landscape: as detection tooling has matured, sophisticated actors have responded by prioritizing stealth and legitimate-looking behavior over speed and destructiveness. The result is intrusions that frequently outlast an organization's log retention windows, meaning by the time an incident is discovered, the evidence needed to fully understand it may already have aged out.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Malware like BRICKSTORM, GOLDVEIN.JAVA, and Daxin (and the associated “Stupig”) are examples of long dwell attack vectors. Furthermore, tooling like Cobalt Strike, which has legitimate use cases for penetration testing, is commonly abused for quiet and malicious operations. As such, in this advisory, we will briefly illustrate the range of tradecraft seen in long dwell operations today, from repurposed commercial frameworks to purpose-built nation-state implants.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Recommended priorities for monitoring this class of threat:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Consider extending log and network flow retention well beyond standard windows, since dwell times for this malware class routinely exceed a year, and the earliest evidence of access is often the first thing to age out.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Treat network appliances, hypervisors, and virtualization management platforms as high-value assets requiring dedicated monitoring, since they often sit outside standard endpoint coverage entirely.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Maintain independent, out-of-band visibility into appliance configuration and traffic, since devices used for long dwell persistence can't always be trusted to self-report accurately.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Build historical log review into routine practice, not just incident response, since a single confirmed indicator may point to a compromise far older than initial evidence suggests.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Recognize that legitimate administrative tools and frameworks can be repurposed for long-term persistence, and account for that risk in how those tools are governed.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory_long_dwell_malware_sept23_2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-dangers-of-long-dwell-malware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/0-5276483784011767953.png" alt="Threat Advisory: The Dangers of Long Dwell Malware" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Long dwell malware refers to tools built not for speed, but for stealth and deeper penetration of targets. Imagine code designed to sit undetected inside a network for months or, in extreme cases, years while quietly collecting intelligence, harvesting credentials, or preparing for a later, more damaging action. This category represents one of the more monumental shifts in the current threat landscape: as detection tooling has matured, sophisticated actors have responded by prioritizing stealth and legitimate-looking behavior over speed and destructiveness. The result is intrusions that frequently outlast an organization's log retention windows, meaning by the time an incident is discovered, the evidence needed to fully understand it may already have aged out.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Malware like BRICKSTORM, GOLDVEIN.JAVA, and Daxin (and the associated “Stupig”) are examples of long dwell attack vectors. Furthermore, tooling like Cobalt Strike, which has legitimate use cases for penetration testing, is commonly abused for quiet and malicious operations. As such, in this advisory, we will briefly illustrate the range of tradecraft seen in long dwell operations today, from repurposed commercial frameworks to purpose-built nation-state implants.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Recommended priorities for monitoring this class of threat:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Consider extending log and network flow retention well beyond standard windows, since dwell times for this malware class routinely exceed a year, and the earliest evidence of access is often the first thing to age out.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Treat network appliances, hypervisors, and virtualization management platforms as high-value assets requiring dedicated monitoring, since they often sit outside standard endpoint coverage entirely.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Maintain independent, out-of-band visibility into appliance configuration and traffic, since devices used for long dwell persistence can't always be trusted to self-report accurately.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Build historical log review into routine practice, not just incident response, since a single confirmed indicator may point to a compromise far older than initial evidence suggests.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Recognize that legitimate administrative tools and frameworks can be repurposed for long-term persistence, and account for that risk in how those tools are governed.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory_long_dwell_malware_sept23_2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-the-dangers-of-long-dwell-malware&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 23 Sep 2026 20:05:33 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-dangers-of-long-dwell-malware</guid>
      <dc:date>2026-09-23T20:05:33Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: The Historical and Ongoing Threat of APT29</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-historical-and-ongoing-threat-of-apt29</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-historical-and-ongoing-threat-of-apt29" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/APT29.png" alt="Threat Advisory: The Historical and Ongoing Threat of APT29" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;APT29, also tracked as Midnight Blizzard and Cozy Bear, is a long-running Russian state-sponsored espionage group widely assessed as almost certainly tied to Russia's Foreign Intelligence Service (SVR). The group has spent over a decade running intelligence-gathering operations against governments, diplomatic missions, defense contractors, and research institutions, with a historical focus on Western and NATO-aligned targets.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;A recent Anthropic disclosure gives fresh visibility into an active cluster of this activity, internally labeled GTG-20006, that ran from roughly December 2025 through August 2026. The operation hit more than 20 organizations concentrated in Europe and Ukraine, including government ministries, defense and intelligence bodies, embassies, think tanks, and companies tied to military drone supply chains. Confirmed outcomes included large-scale mailbox theft, hijacked hotel Wi-Fi networks used to intercept traveling officials' traffic, compromised messaging accounts, and a breach of a North African government identity database exceeding 300,000 records.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;This overview uses that disclosure as a recent, well-documented data point illustrating APT29's current operational tempo and priorities, while situating it within the group's broader, longer-standing pattern of tradecraft and targeting.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Harden identity infrastructure. Enforce phishing-resistant MFA and eliminate unnecessary device-code/OAuth flows to close the access paths this actor has relied on most.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Assume travel networks are hostile. Require encrypted VPN tunneling for all staff traveling internationally, particularly diplomatic, defense, and executive personnel.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Reduce blast radius on identity systems. Segment and monitor central identity/VPN infrastructure so a single compromised credential can't cascade into a full-scale breach.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Shift detection strategy. Invest in behavior-based detection to keep pace with an actor that iterates on its tooling faster than static signatures can be updated.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Audit third-party and IoT integrations. Review camera, surveillance, and other connected platforms for authorization gaps that could expose data or access beyond their intended scope.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-APT29_sept16_2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-historical-and-ongoing-threat-of-apt29" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/APT29.png" alt="Threat Advisory: The Historical and Ongoing Threat of APT29" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;APT29, also tracked as Midnight Blizzard and Cozy Bear, is a long-running Russian state-sponsored espionage group widely assessed as almost certainly tied to Russia's Foreign Intelligence Service (SVR). The group has spent over a decade running intelligence-gathering operations against governments, diplomatic missions, defense contractors, and research institutions, with a historical focus on Western and NATO-aligned targets.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;A recent Anthropic disclosure gives fresh visibility into an active cluster of this activity, internally labeled GTG-20006, that ran from roughly December 2025 through August 2026. The operation hit more than 20 organizations concentrated in Europe and Ukraine, including government ministries, defense and intelligence bodies, embassies, think tanks, and companies tied to military drone supply chains. Confirmed outcomes included large-scale mailbox theft, hijacked hotel Wi-Fi networks used to intercept traveling officials' traffic, compromised messaging accounts, and a breach of a North African government identity database exceeding 300,000 records.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;This overview uses that disclosure as a recent, well-documented data point illustrating APT29's current operational tempo and priorities, while situating it within the group's broader, longer-standing pattern of tradecraft and targeting.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Harden identity infrastructure. Enforce phishing-resistant MFA and eliminate unnecessary device-code/OAuth flows to close the access paths this actor has relied on most.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Assume travel networks are hostile. Require encrypted VPN tunneling for all staff traveling internationally, particularly diplomatic, defense, and executive personnel.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Reduce blast radius on identity systems. Segment and monitor central identity/VPN infrastructure so a single compromised credential can't cascade into a full-scale breach.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Shift detection strategy. Invest in behavior-based detection to keep pace with an actor that iterates on its tooling faster than static signatures can be updated.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Audit third-party and IoT integrations. Review camera, surveillance, and other connected platforms for authorization gaps that could expose data or access beyond their intended scope.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-APT29_sept16_2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-the-historical-and-ongoing-threat-of-apt29&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 16 Sep 2026 18:21:59 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-historical-and-ongoing-threat-of-apt29</guid>
      <dc:date>2026-09-16T18:21:59Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: PEEP Browser Exploit Framework</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-peep-browser-exploit-framework</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-peep-browser-exploit-framework" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/PEEP.png" alt="Threat Advisory: PEEP Browser Exploit Framework" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;PEEP demonstrates that the modern web browser has become a primary post-compromise attack surface, using forged Chromium integrity checks and a native-messaging bridge to turn Chrome and Edge into persistent, host-level backdoors capable of credential theft, session hijacking, and command execution once an attacker already has a foothold on a device. Because the malware operates inside a signed, trusted browser process and relies on layered persistence that survives partial remediation, organizations cannot rely solely on outsourced network and endpoint monitoring to close this gap; several of the most effective mitigations require internal policy decisions and governance changes that only the organization itself can authorize and enforce.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Set enterprise browser policy to disable developer mode and enforce extension allow listing. Define which extensions are permitted via Group Policy or MDM and require business justification for any exception, since this removes the primary delivery path PEEP depends on.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Adopt phishing-resistant MFA (FIDO2/WebAuthn) as organizational policy for all identity and session-sensitive systems. This limits the value of stolen session cookies and credentials even if an endpoint is already compromised.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Establish and communicate an internal AI tool usage policy that addresses "authorized testing" or "CTF" framing as a potential guardrail-bypass tactic. Employees and internal developers should know that such framing is a known technique for lowering AI safety filters during malware development.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Require formal change management approval for any native-messaging host registration or enterprise force-install policy. These are legitimate enterprise mechanisms that PEEP abuses directly, so ownership and sign-off should sit with IT leadership, not be left to default configurations.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-PEEP-Browser-Exploit-Framework-9SEP26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-peep-browser-exploit-framework" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/PEEP.png" alt="Threat Advisory: PEEP Browser Exploit Framework" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;PEEP demonstrates that the modern web browser has become a primary post-compromise attack surface, using forged Chromium integrity checks and a native-messaging bridge to turn Chrome and Edge into persistent, host-level backdoors capable of credential theft, session hijacking, and command execution once an attacker already has a foothold on a device. Because the malware operates inside a signed, trusted browser process and relies on layered persistence that survives partial remediation, organizations cannot rely solely on outsourced network and endpoint monitoring to close this gap; several of the most effective mitigations require internal policy decisions and governance changes that only the organization itself can authorize and enforce.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Set enterprise browser policy to disable developer mode and enforce extension allow listing. Define which extensions are permitted via Group Policy or MDM and require business justification for any exception, since this removes the primary delivery path PEEP depends on.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Adopt phishing-resistant MFA (FIDO2/WebAuthn) as organizational policy for all identity and session-sensitive systems. This limits the value of stolen session cookies and credentials even if an endpoint is already compromised.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Establish and communicate an internal AI tool usage policy that addresses "authorized testing" or "CTF" framing as a potential guardrail-bypass tactic. Employees and internal developers should know that such framing is a known technique for lowering AI safety filters during malware development.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Require formal change management approval for any native-messaging host registration or enterprise force-install policy. These are legitimate enterprise mechanisms that PEEP abuses directly, so ownership and sign-off should sit with IT leadership, not be left to default configurations.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-PEEP-Browser-Exploit-Framework-9SEP26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-peep-browser-exploit-framework&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 09 Sep 2026 14:53:54 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-peep-browser-exploit-framework</guid>
      <dc:date>2026-09-09T14:53:54Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: Aurora Ransomware and AI-Assisted Exploitation</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-aurora-ransomware-and-ai-assisted-exploitation</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-aurora-ransomware-and-ai-assisted-exploitation" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Threat%20Advisory%20Template%20%282%29.png" alt="Threat Advisory: Aurora Ransomware and AI-Assisted Exploitation" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;A Russian-speaking affiliate operating the Aurora ransomware has been directly observed relying on an AI coding assistant to plan and execute network intrusions. Research from CloudSEK, drawn from an exposed operator server, revealed activity against more than twenty organizations across nine countries between April and July 2026, with domain-level access achieved at seventeen; four victims have since appeared on Aurora's public extortion site. A separate investigation by Gambit Security found the same tooling used for hands-on exploitation against ten additional targets, and identified a further cluster, attributed with medium confidence, hitting eight more victims across Israel, Germany, Austria, Spain, the U.S., and Argentina.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;The ransomware is cross-platform, built from a single Zig codebase for Windows and Linux/ESXi, with strong anti-recovery features. Researchers also traced ransom payments on-chain and uncovered a laundering network pooling proceeds from multiple victims, with the affiliate's cut varying per victim rather than following a fixed split. This indicates AI-assisted intrusion is an operational pattern within a sustained, financially significant campaign, not an isolated incident.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px; font-weight: bold;"&gt;Immediate Priorities:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Certificate services risk:&lt;/strong&gt; Audit Active Directory Certificate Services templates for exploitable misconfigurations, since this is a primary path attackers use to escalate to domain administrator access.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Backup infrastructure exposure:&lt;/strong&gt; Isolate backup systems on separate credentials and network segments, as compromised backups often signal an imminent encryption event is about to occur.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Virtualization targeting:&lt;/strong&gt; Segment and closely monitor ESXi and vCenter management interfaces, and maintain offline immutable backups, given this ransomware deliberately terminates virtual machines before encrypting them.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Social engineering entry points:&lt;/strong&gt; Verify help-desk and remote-access requests through formal callback procedures, since impersonation calls and email-bombing campaigns remain common initial-access techniques for this operator.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Reconnaissance tooling:&lt;/strong&gt; Hunt for and alert on common enumeration utilities like NetExec, BloodHound, and Nmap, since AI-agent-driven attacks still rely on these off-the-shelf tools to scan and map victim networks.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-Aurora-Ransomware-2sep26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-aurora-ransomware-and-ai-assisted-exploitation" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Threat%20Advisory%20Template%20%282%29.png" alt="Threat Advisory: Aurora Ransomware and AI-Assisted Exploitation" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;A Russian-speaking affiliate operating the Aurora ransomware has been directly observed relying on an AI coding assistant to plan and execute network intrusions. Research from CloudSEK, drawn from an exposed operator server, revealed activity against more than twenty organizations across nine countries between April and July 2026, with domain-level access achieved at seventeen; four victims have since appeared on Aurora's public extortion site. A separate investigation by Gambit Security found the same tooling used for hands-on exploitation against ten additional targets, and identified a further cluster, attributed with medium confidence, hitting eight more victims across Israel, Germany, Austria, Spain, the U.S., and Argentina.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;The ransomware is cross-platform, built from a single Zig codebase for Windows and Linux/ESXi, with strong anti-recovery features. Researchers also traced ransom payments on-chain and uncovered a laundering network pooling proceeds from multiple victims, with the affiliate's cut varying per victim rather than following a fixed split. This indicates AI-assisted intrusion is an operational pattern within a sustained, financially significant campaign, not an isolated incident.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px; font-weight: bold;"&gt;Immediate Priorities:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Certificate services risk:&lt;/strong&gt; Audit Active Directory Certificate Services templates for exploitable misconfigurations, since this is a primary path attackers use to escalate to domain administrator access.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Backup infrastructure exposure:&lt;/strong&gt; Isolate backup systems on separate credentials and network segments, as compromised backups often signal an imminent encryption event is about to occur.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Virtualization targeting:&lt;/strong&gt; Segment and closely monitor ESXi and vCenter management interfaces, and maintain offline immutable backups, given this ransomware deliberately terminates virtual machines before encrypting them.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Social engineering entry points:&lt;/strong&gt; Verify help-desk and remote-access requests through formal callback procedures, since impersonation calls and email-bombing campaigns remain common initial-access techniques for this operator.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Reconnaissance tooling:&lt;/strong&gt; Hunt for and alert on common enumeration utilities like NetExec, BloodHound, and Nmap, since AI-agent-driven attacks still rely on these off-the-shelf tools to scan and map victim networks.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-Aurora-Ransomware-2sep26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-aurora-ransomware-and-ai-assisted-exploitation&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 02 Sep 2026 16:22:17 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-aurora-ransomware-and-ai-assisted-exploitation</guid>
      <dc:date>2026-09-02T16:22:17Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory Special Report: AtSign SSHNPD Vulnerabilities</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-special-report-atsign-sshnpd-vulnerabilities</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-special-report-atsign-sshnpd-vulnerabilities" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Threat%20Advisory%20Template%20%281%29.png" alt="Threat Advisory Special Report: AtSign SSHNPD Vulnerabilities" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Atsign is the company behind atProtocol and NoPorts, a remote-access platform built around the idea of removing exposed inbound ports as the primary trust boundary. Rather than granting access based on network reachability, such as whether a device can be reached on a given IP and port, NoPorts verifies cryptographic identity and establishes end-to-end encrypted sessions through relay infrastructure. The Atsign Foundation, a nonprofit, maintains the open-source protocol specification and reference implementations, including the sshnpd daemon at the center of this disclosure, making the codebase directly relevant to the security guarantees the product advertises.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Aaron/“Zonifer,” an UltraViolet Cyber Offensive Security Services Team member, discovered two vulnerabilities in Atsign's NoPorts C daemon (sshnpd) that, when chained, allowed an attacker holding any valid atSign identity, not just an authorized manager, to inject a malicious SSH key into a target's authorized_keys file and reach that system's SSH service through NoPorts' own relay, despite the service never being exposed to the network. The root cause was a missing authorization check in the request-dispatch path combined with an inverted validation function that caused SSH public-key checks to fail open. Atsign patched the issue within four days of disclosure, and a CVE is pending, but any organization running the C implementation should treat this as a priority action item. UVCyber Threat Intelligence and Detection Engineering (TIDE) Team have begun implementing Detections for this vulnerability and performing Threat Hunts surrounding AtSign infrastructure in UVCyber customers environments.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Patch immediately:&lt;/strong&gt; Update all NoPorts C-daemon deployments to the fixed release and confirm the version in use no longer matches the vulnerable build before assuming remediation is complete.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Audit authorized_keys and manager configuration:&lt;/strong&gt; Review authorized_keys files on systems that ran the affected daemon (especially with -s enabled) for unrecognized keys, and verify the --manager list reflects only intended, trusted atSigns.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Add negative authorization testing:&lt;/strong&gt; For NoPorts and any similar identity-first remote-access tooling, build tests that confirm authenticated-but-unauthorized identities are explicitly denied, not just that authorized identities succeed, particularly when logic is ported across languages or implementations.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;The original vulnerability disclosure article by Aaron/“Zonifer” can be found at: &lt;a href="https://zonifer.dev/posts/noports.html"&gt;https://zonifer.dev/posts/noports.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity. Given that this vulnerability was discovered by a UVCyber researcher, these detections are unique and exclusive to UVCyber Managed SOC customers.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-AtSign-SSHNPD-Vulnerabilities-25AUG26%20(1).pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-special-report-atsign-sshnpd-vulnerabilities" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Threat%20Advisory%20Template%20%281%29.png" alt="Threat Advisory Special Report: AtSign SSHNPD Vulnerabilities" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Atsign is the company behind atProtocol and NoPorts, a remote-access platform built around the idea of removing exposed inbound ports as the primary trust boundary. Rather than granting access based on network reachability, such as whether a device can be reached on a given IP and port, NoPorts verifies cryptographic identity and establishes end-to-end encrypted sessions through relay infrastructure. The Atsign Foundation, a nonprofit, maintains the open-source protocol specification and reference implementations, including the sshnpd daemon at the center of this disclosure, making the codebase directly relevant to the security guarantees the product advertises.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Aaron/“Zonifer,” an UltraViolet Cyber Offensive Security Services Team member, discovered two vulnerabilities in Atsign's NoPorts C daemon (sshnpd) that, when chained, allowed an attacker holding any valid atSign identity, not just an authorized manager, to inject a malicious SSH key into a target's authorized_keys file and reach that system's SSH service through NoPorts' own relay, despite the service never being exposed to the network. The root cause was a missing authorization check in the request-dispatch path combined with an inverted validation function that caused SSH public-key checks to fail open. Atsign patched the issue within four days of disclosure, and a CVE is pending, but any organization running the C implementation should treat this as a priority action item. UVCyber Threat Intelligence and Detection Engineering (TIDE) Team have begun implementing Detections for this vulnerability and performing Threat Hunts surrounding AtSign infrastructure in UVCyber customers environments.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Patch immediately:&lt;/strong&gt; Update all NoPorts C-daemon deployments to the fixed release and confirm the version in use no longer matches the vulnerable build before assuming remediation is complete.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Audit authorized_keys and manager configuration:&lt;/strong&gt; Review authorized_keys files on systems that ran the affected daemon (especially with -s enabled) for unrecognized keys, and verify the --manager list reflects only intended, trusted atSigns.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;&lt;strong&gt;Add negative authorization testing:&lt;/strong&gt; For NoPorts and any similar identity-first remote-access tooling, build tests that confirm authenticated-but-unauthorized identities are explicitly denied, not just that authorized identities succeed, particularly when logic is ported across languages or implementations.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;The original vulnerability disclosure article by Aaron/“Zonifer” can be found at: &lt;a href="https://zonifer.dev/posts/noports.html"&gt;https://zonifer.dev/posts/noports.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity. Given that this vulnerability was discovered by a UVCyber researcher, these detections are unique and exclusive to UVCyber Managed SOC customers.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-AtSign-SSHNPD-Vulnerabilities-25AUG26%20(1).pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-special-report-atsign-sshnpd-vulnerabilities&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Intelligence</category>
      <pubDate>Tue, 25 Aug 2026 20:21:34 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-special-report-atsign-sshnpd-vulnerabilities</guid>
      <dc:date>2026-08-25T20:21:34Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: TWINLOOT Malware Threats</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-twinloot-malware-threats</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-twinloot-malware-threats" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/TWINLOOT.png" alt="Threat Advisory: TWINLOOT Malware Threats" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;TWINLOOT is a newly disclosed Python implant that operates entirely inside trusted Microsoft 365 infrastructure, using SharePoint dead-drops, Teams TURN relays, and a headless instance of the victim's own Edge browser to blend command-and-control traffic with legitimate enterprise activity, while harvesting Windows credentials via fake lock-screen prompts and enabling lateral movement through an integrated SOCKS5 proxy. Initial access relies on Teams-based social engineering where attackers impersonate IT support, and the malware's abuse of trusted cloud services reflects a broader pattern now seen across at least three independent threat actors in the past year. Organizations should take the following steps to reduce exposure:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Restrict and audit PowerShell execution policy enterprise-wide, requiring signed scripts and disabling unrestricted execution for standard users to break the initial infection chain.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Enforce Teams external communication controls, restricting or requiring approval for messages from external tenants and reinforcing user training on IT-support impersonation tactics specifically within Teams.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Disable or tightly govern browser remote debugging interfaces (e.g., Edge/Chrome DevTools Protocol) via group policy, since TWINLOOT and comparable tools depend on CDP access to drive the victim's browser as a C2 transport.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Enforce phishing-resistant MFA and conditional access policies on Microsoft 365 and Azure AD accounts to limit the value of credentials harvested through fake lock-screen prompts, and restrict SharePoint/Graph API app permissions to reduce dead-drop viability.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-TWINLOOT-Malware-Threats-19AUG26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-twinloot-malware-threats" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/TWINLOOT.png" alt="Threat Advisory: TWINLOOT Malware Threats" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;TWINLOOT is a newly disclosed Python implant that operates entirely inside trusted Microsoft 365 infrastructure, using SharePoint dead-drops, Teams TURN relays, and a headless instance of the victim's own Edge browser to blend command-and-control traffic with legitimate enterprise activity, while harvesting Windows credentials via fake lock-screen prompts and enabling lateral movement through an integrated SOCKS5 proxy. Initial access relies on Teams-based social engineering where attackers impersonate IT support, and the malware's abuse of trusted cloud services reflects a broader pattern now seen across at least three independent threat actors in the past year. Organizations should take the following steps to reduce exposure:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Restrict and audit PowerShell execution policy enterprise-wide, requiring signed scripts and disabling unrestricted execution for standard users to break the initial infection chain.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Enforce Teams external communication controls, restricting or requiring approval for messages from external tenants and reinforcing user training on IT-support impersonation tactics specifically within Teams.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Disable or tightly govern browser remote debugging interfaces (e.g., Edge/Chrome DevTools Protocol) via group policy, since TWINLOOT and comparable tools depend on CDP access to drive the victim's browser as a C2 transport.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Enforce phishing-resistant MFA and conditional access policies on Microsoft 365 and Azure AD accounts to limit the value of credentials harvested through fake lock-screen prompts, and restrict SharePoint/Graph API app permissions to reduce dead-drop viability.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-TWINLOOT-Malware-Threats-19AUG26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-twinloot-malware-threats&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber attacks</category>
      <category>AI</category>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 19 Aug 2026 16:35:16 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-twinloot-malware-threats</guid>
      <dc:date>2026-08-19T16:35:16Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: Gunra Ransomware Group Targeting Vulnerable Fortinet Devices</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-gunra-ransomware-group-targeting-vulnerable-fortinet-devices</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-gunra-ransomware-group-targeting-vulnerable-fortinet-devices" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Gunra.png" alt="Threat Advisory: Gunra Ransomware Group Targeting Vulnerable Fortinet Devices" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;CISA, the FBI, NSA, DC3, the U.S. Secret Service, and South Korea's National Police Agency issued a joint advisory this week warning that Gunra ransomware actors are actively targeting critical infrastructure worldwide. Gunra is a double-extortion ransomware-as-a-service operation built on leaked Conti source code that first appeared in spring 2025 and has since expanded into a structured affiliate program recruiting financially motivated criminals through dark web forums.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;The group primarily gains initial access by exploiting two long-known Fortinet FortiOS/FortiProxy authentication bypass flaws, both of which have sat in CISA's Known Exploited Vulnerabilities catalog for over a year yet remain unpatched at many organizations. Once inside, affiliates hijack VPN and virtual desktop infrastructure, defeat multi-factor authentication, and combine data theft with encryption before threatening public leaks.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Patch Fortinet FortiOS/FortiProxy devices now as two known flaws remain actively exploited over a year after disclosure&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Don't rely on MFA alone; always verify authentication files and portals haven't been tampered with&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Keep backups offline and immutable as Gunra deletes them before and after encrypting&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Watch for overnight activity and unusual credential access, which are key signs of Gunra's tradecraft&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Assume you're a target regardless of region and be mindful that healthcare, finance, government, and manufacturing are all in scope&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-Gunra-Ransomware-Fortinet-Exploits.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-gunra-ransomware-group-targeting-vulnerable-fortinet-devices" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Gunra.png" alt="Threat Advisory: Gunra Ransomware Group Targeting Vulnerable Fortinet Devices" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;CISA, the FBI, NSA, DC3, the U.S. Secret Service, and South Korea's National Police Agency issued a joint advisory this week warning that Gunra ransomware actors are actively targeting critical infrastructure worldwide. Gunra is a double-extortion ransomware-as-a-service operation built on leaked Conti source code that first appeared in spring 2025 and has since expanded into a structured affiliate program recruiting financially motivated criminals through dark web forums.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;The group primarily gains initial access by exploiting two long-known Fortinet FortiOS/FortiProxy authentication bypass flaws, both of which have sat in CISA's Known Exploited Vulnerabilities catalog for over a year yet remain unpatched at many organizations. Once inside, affiliates hijack VPN and virtual desktop infrastructure, defeat multi-factor authentication, and combine data theft with encryption before threatening public leaks.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Patch Fortinet FortiOS/FortiProxy devices now as two known flaws remain actively exploited over a year after disclosure&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Don't rely on MFA alone; always verify authentication files and portals haven't been tampered with&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Keep backups offline and immutable as Gunra deletes them before and after encrypting&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Watch for overnight activity and unusual credential access, which are key signs of Gunra's tradecraft&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Assume you're a target regardless of region and be mindful that healthcare, finance, government, and manufacturing are all in scope&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-Gunra-Ransomware-Fortinet-Exploits.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-gunra-ransomware-group-targeting-vulnerable-fortinet-devices&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber attacks</category>
      <category>AI</category>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 12 Aug 2026 17:21:50 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-gunra-ransomware-group-targeting-vulnerable-fortinet-devices</guid>
      <dc:date>2026-08-12T17:21:50Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: SMOKESCREEN RMM Abuse</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-smokescreen-rmm-abuse</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-smokescreen-rmm-abuse" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Threat%20Advisory%20Template.png" alt="Threat Advisory: SMOKESCREEN RMM Abuse" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Security researchers have identified an active campaign, SMOKE#SCREEN, that impersonates Adobe and Zoom software updates, business document reviews, and system maintenance utilities to trick users into installing ConnectWise ScreenConnect, a legitimate RMM tool that provides attackers with full, persistent remote desktop access. The actor uses a rotating toolkit of obfuscated scripts and compiled loaders, some of which disable Windows Defender and SmartScreen before installation. They deliver payloads through trusted platforms like Dropbox and Cloudflare Tunnels to evade domain reputation filtering. Because the final payload is a validly signed, vendor-trusted binary, the threat is effective against organizations that rely primarily on certificate and reputation-based controls rather than behavioral detection. The campaign targets both Windows and macOS and shows clear evidence the actor is actively adjusting tradecraft in response to specific EDR products.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Inventory and restrict RMM tools: identify which remote access tools (ScreenConnect, AnyDesk, Atera, etc.) are approved for use in your environment, and block installation or execution of any RMM client not on that list via application control policy.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Implement AppLocker or WDAC rules to prevent MSI and EXE execution from user-writable locations such as %TEMP%, Downloads, and AppData, where these payloads are staged.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Set UAC to "Always notify" and remove local admin rights from standard users where feasible, to prevent silent privilege escalation during installation.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Run targeted user awareness training on fake software update prompts, specifically warning staff not to download or run Zoom, Adobe, or "system check" updates delivered via email links, and to route update installation through IT rather than end-user action.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-SMOKESCREEN-RMM-Abuse-5AUG26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-smokescreen-rmm-abuse" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Threat%20Advisory%20Template.png" alt="Threat Advisory: SMOKESCREEN RMM Abuse" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Security researchers have identified an active campaign, SMOKE#SCREEN, that impersonates Adobe and Zoom software updates, business document reviews, and system maintenance utilities to trick users into installing ConnectWise ScreenConnect, a legitimate RMM tool that provides attackers with full, persistent remote desktop access. The actor uses a rotating toolkit of obfuscated scripts and compiled loaders, some of which disable Windows Defender and SmartScreen before installation. They deliver payloads through trusted platforms like Dropbox and Cloudflare Tunnels to evade domain reputation filtering. Because the final payload is a validly signed, vendor-trusted binary, the threat is effective against organizations that rely primarily on certificate and reputation-based controls rather than behavioral detection. The campaign targets both Windows and macOS and shows clear evidence the actor is actively adjusting tradecraft in response to specific EDR products.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Inventory and restrict RMM tools: identify which remote access tools (ScreenConnect, AnyDesk, Atera, etc.) are approved for use in your environment, and block installation or execution of any RMM client not on that list via application control policy.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Implement AppLocker or WDAC rules to prevent MSI and EXE execution from user-writable locations such as %TEMP%, Downloads, and AppData, where these payloads are staged.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Set UAC to "Always notify" and remove local admin rights from standard users where feasible, to prevent silent privilege escalation during installation.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Run targeted user awareness training on fake software update prompts, specifically warning staff not to download or run Zoom, Adobe, or "system check" updates delivered via email links, and to route update installation through IT rather than end-user action.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-SMOKESCREEN-RMM-Abuse-5AUG26.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-smokescreen-rmm-abuse&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber attacks</category>
      <category>AI</category>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 05 Aug 2026 14:45:04 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-smokescreen-rmm-abuse</guid>
      <dc:date>2026-08-05T14:45:04Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
    <item>
      <title>Threat Advisory: The Ongoing Threat of Anubis Ransomware</title>
      <link>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-ongoing-threat-of-anubis-ransomware</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-ongoing-threat-of-anubis-ransomware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Anubis.png" alt="Threat Advisory: The Ongoing Threat of Anubis Ransomware" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Anubis is a ransomware-as-a-service (RaaS) operation that has been active since December 2024, when it emerged under an earlier test name, "Sphinx," before rebranding. It has since built out a functioning affiliate program on Russian-language cybercrime forums, offering negotiable revenue splits and multiple monetization paths beyond a standard ransom, including separate programs for data extortion and access sales. This flexible business model, combined with technical capabilities that go beyond typical encryption (namely, an optional file-wiping feature) makes Anubis a more destructive and adaptable threat than many of its RaaS peers. The group gained significant attention in July 2026 after publicly claiming an attack on Coca-Cola's Fairlife dairy subsidiary, alleging theft of roughly 1 TB of data and later publishing that data after Coca-Cola did not meet its ransom deadline. The incident disrupted U.S. dairy production, required SEC disclosure, and ultimately led to confirmed data theft. This illustrates how a mid-sized subsidiary can become the entry point for an attack with enterprise-wide consequences. Looking at the victimology, it is worth noting that Anubis's victims are broken out across multiple, unrelated, sectors with seemingly no geographic boundaries. That spread, consistent with many RaaS operations, points to opportunistic targeting and indicates that organizations should not assume they are at a lower risk for Anubis attacks based on their individual industry.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Backups alone won't save you: Anubis's wiper can permanently destroy files even after encryption, so offline, immutable backups are essential rather than optional.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Phishing is the entry point: The group relies on spear-phishing for initial access, making email/web filtering and user training a frontline defense.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Watch for privilege escalation and shadow-copy deletion: These are the clearest early warning signs of an active Anubis intrusion and should be tuned into EDR/SIEM alerting.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Assume dual extortion from day one: Plan incident response, legal, and communications playbooks around both an operational outage and a data leak, since paying (or refusing to pay) doesn't guarantee data stays private.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-Anubis-Ransomware-july-2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-ongoing-threat-of-anubis-ransomware" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.uvcyber.com/hubfs/Anubis.png" alt="Threat Advisory: The Ongoing Threat of Anubis Ransomware" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;a&gt;&lt;/a&gt; 
&lt;h2 style="padding-left: 0cm; line-height: 1.5; text-align: left;"&gt;&lt;span&gt;Executive Snapshot&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span style="line-height: 18.3458px;"&gt;Anubis is a ransomware-as-a-service (RaaS) operation that has been active since December 2024, when it emerged under an earlier test name, "Sphinx," before rebranding. It has since built out a functioning affiliate program on Russian-language cybercrime forums, offering negotiable revenue splits and multiple monetization paths beyond a standard ransom, including separate programs for data extortion and access sales. This flexible business model, combined with technical capabilities that go beyond typical encryption (namely, an optional file-wiping feature) makes Anubis a more destructive and adaptable threat than many of its RaaS peers. The group gained significant attention in July 2026 after publicly claiming an attack on Coca-Cola's Fairlife dairy subsidiary, alleging theft of roughly 1 TB of data and later publishing that data after Coca-Cola did not meet its ransom deadline. The incident disrupted U.S. dairy production, required SEC disclosure, and ultimately led to confirmed data theft. This illustrates how a mid-sized subsidiary can become the entry point for an attack with enterprise-wide consequences. Looking at the victimology, it is worth noting that Anubis's victims are broken out across multiple, unrelated, sectors with seemingly no geographic boundaries. That spread, consistent with many RaaS operations, points to opportunistic targeting and indicates that organizations should not assume they are at a lower risk for Anubis attacks based on their individual industry.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Backups alone won't save you: Anubis's wiper can permanently destroy files even after encryption, so offline, immutable backups are essential rather than optional.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Phishing is the entry point: The group relies on spear-phishing for initial access, making email/web filtering and user training a frontline defense.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Watch for privilege escalation and shadow-copy deletion: These are the clearest early warning signs of an active Anubis intrusion and should be tuned into EDR/SIEM alerting.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Assume dual extortion from day one: Plan incident response, legal, and communications playbooks around both an operational outage and a data leak, since paying (or refusing to pay) doesn't guarantee data stays private.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;div style="text-align: left;"&gt; 
 &lt;p style="font-weight: bold;"&gt;&lt;span style="color: #6314ff;"&gt;What UltraViolet Cyber is Doing&lt;/span&gt;&lt;/p&gt; 
 &lt;ul style="list-style-type: disc;"&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Tracking new CVEs and high impact vulnerabilities, analyzing and deploying public Proof-Of-Concept code against custom built targets.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Proactively enabling custom detections based on the collected artifacts, tactics, techniques, and procedures identified in this activity.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Performing hypothesis driven threat hunts based on threat actor behavior and artifacts. UVCyber customers will be informed of the results through secure channels.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Parsing available victim dump data for any social, financial, business, or technical relations to UVCyber Clients and partner organizations.&lt;/span&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;span style="color: #231f20; line-height: 18.3458px;"&gt;Aggregating threat intelligence from myriad sources and applying the most up-to-date knowledge to proactive threat hunting and response.&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="text-align: left;"&gt;&lt;a href="https://www.uvcyber.com/hubfs/ThreatAdvisory-Anubis-Ransomware-july-2026.pdf" style="background-color: #6314ff; padding: 10px 15px; border-radius: 3px; text-decoration: none; color: #ffffff; font-weight: bold; text-transform: uppercase;"&gt;DOWNLOAD THE PDF REPORT&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24091716&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.uvcyber.com%2Fresources%2Fthreat-advisories%2Fthreat-advisory-the-ongoing-threat-of-anubis-ransomware&amp;amp;bu=https%253A%252F%252Fwww.uvcyber.com%252Fresources%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber attacks</category>
      <category>AI</category>
      <category>Threat Intelligence</category>
      <pubDate>Wed, 29 Jul 2026 19:47:29 GMT</pubDate>
      <guid>https://www.uvcyber.com/resources/threat-advisories/threat-advisory-the-ongoing-threat-of-anubis-ransomware</guid>
      <dc:date>2026-07-29T19:47:29Z</dc:date>
      <dc:creator>UltraViolet Cyber</dc:creator>
    </item>
  </channel>
</rss>
