Heroes, your curated look at the current cybersecurity landscape for May 08, 2026.
Critical Threats
Canvas Attackers Compromise 275M Users and Escalate Extortion Tactics
Varonis·5:27 PM
▾
A massive cyberattack on the Canvas learning management system has compromised the data of 275 million students, teachers, and staff across thousands of educational institutions. The threat actor, ShinyHunters, has escalated the attack by defacing school login portals with ransom messages, forcing dozens of universities to reschedule final exams.
Business Impact
This large-scale data theft and operational disruption exposes educational institutions to massive class-action lawsuits, severe reputational damage, and regulatory scrutiny under privacy laws.
Recommended Action
Ask your IT team: Are we utilizing Canvas, and if so, have we enforced mandatory password resets and multi-factor authentication for all faculty and student accounts?
Linux Kernel 'Dirty Frag' LPE Exploit Enables Root Access Across Major Distributions
The Hacker News·4:58 PM
▾
A new unpatched local privilege escalation (LPE) vulnerability known as "Dirty Frag" has emerged in the Linux kernel, acting as a successor to the recent "Copy Fail" flaw. Public exploit code is already available, allowing local users to gain root access, and tests show it behaves like an unconfined threat in Kubernetes environments like EKS and GKE.
Business Impact
If exploited, attackers who have already gained initial access can elevate their privileges to full root control, leading to complete server compromise, data exfiltration, and significant operational downtime. This could result in severe regulatory fines and loss of customer trust.
Recommended Action
Ask your IT team: Have we implemented runtime monitoring to detect anomalous kernel-level behaviors, and are we prepared to deploy mitigations for Dirty Frag across our Kubernetes clusters?
Ivanti EPMM RCE Under Active Exploitation Added to CISA KEV
The Hacker News·6:03 PM·CVE-2026-6973
▾
CISA has added a high-severity remote code execution vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog. The flaw stems from improper input validation and grants attackers admin-level access, with limited attacks already observed in the wild.
Business Impact
Exploitation grants attackers administrative control over mobile endpoint management infrastructure, potentially exposing sensitive corporate data across all managed devices. This triggers mandatory breach disclosures, potential compliance penalties, and widespread operational disruption.
Recommended Action
Ask your IT team: Have we updated our Ivanti EPMM instances to version 12.6.1.1, 12.7.0.1, or 12.8.0.1 to mitigate this actively exploited vulnerability?
Critical Apache HTTP Server HTTP/2 Vulnerability Could Enable Remote Code Execution
Orca Security·3:15 PM·CVE-2026-23918
▾
A high-severity vulnerability in the Apache HTTP Server allows attackers to potentially achieve remote code execution through specially crafted HTTP/2 requests. Immediate patching is required due to the risk of complete server compromise and denial-of-service conditions.
Business Impact
A successful attack could allow unauthorized actors to execute arbitrary code on web servers, leading to website defacement, customer data theft, and extended service outages that directly impact revenue generation.
Recommended Action
Ask your IT team: Are our Apache HTTP Servers exposed to the internet, and have we applied the latest security patches to address the HTTP/2 vulnerability?
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
The Hacker News·3:08 PM
▾
Fraudulent Android apps on the Google Play Store tricked users into paying for fake call history data, resulting in financial losses. The 28 malicious applications amassed over 7.3 million downloads before being discovered.
Business Impact
While primarily a consumer threat, employees using compromised personal devices for work (BYOD) could expose corporate networks to secondary infections or credential theft, leading to potential data breaches.
Recommended Action
Ask your IT team: Do our mobile device management (MDM) policies restrict the installation of unapproved third-party applications on devices used for corporate access?
Microsoft Edge Plaintext Password Behavior Deemed "By Design"
Malwarebytes·12:48 PM
▾
Security researchers discovered that Microsoft Edge loads saved passwords into computer memory in plaintext upon startup, making them easily accessible to info-stealing malware. Microsoft has stated that this behavior is "by design."
Business Impact
If an employee's device is compromised, attackers can easily harvest corporate credentials stored in the browser, bypassing perimeter defenses and leading to unauthorized access to sensitive business applications.
Recommended Action
Ask your IT team: Are we enforcing policies that prohibit saving corporate passwords in web browsers, and do we mandate the use of enterprise password managers?
Rapid7 highlights the shift towards "Detection as Code," urging security teams to adopt software engineering practices like version control, testing, and CI/CD pipelines for detection logic to keep pace with modern threats.
Rapid7 and OpenAI have announced a Trusted Access for Cyber program, acknowledging that advances in frontier AI are accelerating the threat environment and requiring security operating models to evolve.
The ongoing legal battle between Elon Musk and OpenAI leaders highlights broader industry concerns regarding the rapid advancement of artificial intelligence and its potential risks to humanity and enterprise security.
Why Netskope Today: Today's threat landscape highlights severe risks from exposed edge infrastructure, compromised SaaS accounts, and endpoint credential theft. Netskope addresses these by replacing vulnerable public-facing services with Zero Trust Network Access (ZTNA), utilizing UEBA to detect compromised accounts, and leveraging SWG/DLP to sever command-and-control communications from info-stealing malware.
Canvas Attackers Compromise 275M Users and Escalate Extortion Tactics
Advanced Analytics: Navigate to Advanced Analytics > User Behavior Analytics (UEBA). Enable and tune policies for "Compromised Credentials" and "Anomalous Data Download" to detect unusual access patterns from internal users who may have had their Canvas credentials compromised.
DLP: Navigate to Policies > Real-time Protection. Create a new policy where Cloud App = Canvas (or generic Web traffic if Canvas is not a predefined connector in your tenant), Activity = Download/Upload, Profile = [Your PII/Student Data Exact Data Match profile], Action = Block.
Coverage Assessment — Moderate
Integration Note — Netskope cannot patch the external Canvas platform, but integration with Okta Identity or Abnormal Security allows Netskope to trigger automated remediation (like forcing MFA or password resets) when account takeover behavior is detected.
Ivanti EPMM RCE Under Active Exploitation Added to CISA KEV
Threat — Ivanti EPMM RCE Under Active Exploitation Added to CISA KEV
ZTNA Next: Navigate to Settings > Security Cloud Platform > Netskope Private Access. Migrate remote access policies off legacy Ivanti VPNs and onto Netskope Publishers. This removes the vulnerable EPMM management interfaces from the public internet entirely.
Intelligent SSE: Navigate to Policies > Real-time Protection. Ensure default block policies are active for "Malware" and "Command and Control" categories to prevent post-exploitation callbacks if an unpatched Ivanti appliance is already compromised on your network.
Coverage Assessment — Strong
Critical Apache HTTP Server HTTP/2 Vulnerability Could Enable Remote Code Execution
Threat — Critical Apache HTTP Server HTTP/2 Vulnerability Could Enable Remote Code Execution
ZTNA Next: Navigate to Policies > Private Apps. Configure application definitions for internal Apache servers to require identity-aware, context-adaptive access via Netskope Publishers, shielding them from unauthenticated external HTTP/2 requests.
Cloud Firewall: Navigate to Policies > Cloud Firewall. Create a rule blocking inbound traffic to internal Apache server IP ranges from untrusted external networks, restricting access strictly to the Netskope ZTNA publisher.
Coverage Assessment — Strong
Microsoft Edge Plaintext Password Behavior Deemed "By Design"
Threat — Microsoft Edge Plaintext Password Behavior Deemed "By Design"
SWG: Navigate to Policies > Real-time Protection. Create a Web Access policy blocking categories: "Malware", "Botnet", and "Phishing" to prevent info-stealer malware from communicating with C2 servers. Ensure TLS/SSL inspection is enabled (Settings > Manage > Certificates) to inspect encrypted C2 traffic.
DLP: Navigate to Policies > Profiles > DLP. Ensure credential fingerprinting profiles are active to detect and block plaintext passwords traversing the network outbound.
Coverage Assessment — Integration-Dependent
Integration Note — Because this is a local memory vulnerability, Netskope relies on integration with CrowdStrike Falcon Insight XDR or SentinelOne Singularity XDR to detect and terminate the actual info-stealer malware executing on the endpoint.
Coverage Gaps:
Exactly half of today's major threats (the Linux Kernel 'Dirty Frag' LPE, the Fake Call History Android Apps, and the Microsoft Edge memory behavior) are local OS, mobile app store, or endpoint-level vulnerabilities. Because Netskope operates at the network and cloud edge (SSE/SASE), it does not provide standalone local privilege escalation prevention or mobile app execution control. Addressing these specific threats requires heavy reliance on your deployed EDR/XDR and MDM integration partners (e.g., CrowdStrike, SentinelOne, VMware Workspace ONE).
Detection & Response
Detection & Response Kit(4 items)▾
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. Vendor Platform Configuration - Netskope
# Netskope Configuration Guidance
# Generated: 2026-05-08 18:17:21
# Refer to per-threat guidance in the Vendor Spotlight section above
$computers = "localhost", "SERVER01", "WKSTN01"
foreach ($computer in $computers) {
if (Test-Connection -ComputerName $computer -Count 1 -Quiet) {
# Check for Apache HTTP Server service to identify potential CVE-2026-23918 exposure
$apacheService = Get-Service -ComputerName $computer -Name "Apache*" -ErrorAction SilentlyContinue
if ($apacheService) {
Write-Host "[!] Apache service found on $computer. Verify HTTP/2 configuration and patch status." -ForegroundColor Red
} else {
Write-Host "[+] No Apache service detected on $computer." -ForegroundColor Green
}
}
}
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!
Cookie Notice
We use essential cookies to provide our cybersecurity newsletter service and analytics cookies to improve your experience.
About STIX 2.1: Structured Threat Information eXpression (STIX) is the machine language of cybersecurity. This bundle contains validated threat objects, indicators, and relationships that can be directly imported into your SIEM, TIP, or security orchestration platform.
Usage: Download or copy the JSON below and import it directly into your threat intelligence platform, SIEM, or security orchestration tools for automated threat detection and response.
{
"type": "bundle",
"id": "bundle--57436e16-7a54-4f43-8f33-45c6bdd1fa3a",
"objects": [
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487",
"created": "2022-10-01T00:00:00.000Z",
"definition_type": "tlp:2.0",
"name": "TLP:CLEAR",
"definition": {
"tlp": "clear"
}
},
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--e8be913a-4c5f-47a6-8884-f3554f2c96a5",
"created": "2026-05-08T14:57:20.282Z",
"modified": "2026-05-08T14:57:20.282Z",
"name": "MikeGPT Intelligence Platform",
"description": "AI-powered threat intelligence collection and analysis platform providing automated cybersecurity intelligence feeds",
"identity_class": "organization",
"sectors": [
"technology",
"defense"
],
"contact_information": "Website: https://mikegptai.com | Email: intel@mikegptai.com",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--c2654372-dcc4-429e-a34e-e7b3c6337af7",
"created": "2026-05-08T14:57:20.282Z",
"modified": "2026-05-08T14:57:20.282Z",
"name": "Threat Intelligence Report - 2026-05-08",
"description": "Threat Intelligence Report - 2026-05-08\n\nThis report consolidates actionable cybersecurity intelligence from 81 sources, processed through automated threat analysis and relationship extraction.\n\nKEY FINDINGS:\n• Microsoft says Edge’s plaintext password behavior is “by design” (Score: 100)\n• Zero Chaos: Scaling Detection Engineering at the Speed of Software, with Detection As Code (Score: 100)\n• The Good, the Bad and the Ugly in Cybersecurity – Week 19 (Score: 100)\n• AI, Cyberwarfare, and Autonomous Weapons: Inside America’s New Military Strategy (Score: 100)\n• CVE-2025-68670: discovering an RCE vulnerability in xrdp (Score: 100)\n\nEXTRACTED ENTITIES:\n• 36 Attack Pattern(s)\n• 29 Domain Name(s)\n• 35 File(s)\n• 74 Indicator(s)\n• 4 Ipv4 Addr(s)\n• 3 Malware(s)\n• 1 Marking Definition(s)\n• 116 Relationship(s)\n• 6 Threat Actor(s)\n• 6 Url(s)\n• 13 Vulnerability(s)\n\nCONFIDENCE ASSESSMENT:\nVariable confidence scoring applied based on entity type and intelligence source reliability. Confidence ranges from 30-95% reflecting professional intelligence assessment practices.\n\nGENERATION METADATA:\n- Processing Time: Automated\n- Validation: Three-LLM consensus committee\n- Standards Compliance: STIX 2.1\n",
"published": "2026-05-08T14:57:20.282Z",
"object_refs": [
"identity--e8be913a-4c5f-47a6-8884-f3554f2c96a5",
"identity--08dad444-0d55-4ed2-a88b-086c37d76c5c",
"identity--d7b2b636-3a3b-4955-8425-21f44189be7a",
"identity--e6eec92a-f639-45e5-a2b1-7314cc103f42",
"identity--89c66628-698d-41c6-a616-d159a9f64219",
"identity--daab77e6-85d1-4e69-8b9d-e228d91902c2",
"identity--fe19caea-135f-4ae7-b916-2d6d2e207d24",
"identity--17d85fe0-e189-492a-8b69-6e8f0b6a5007",
"identity--e82541d6-05a3-4ed7-bd7e-a089527ebf7a",
"identity--4c8e1191-64c4-4d4a-bcaa-5128f7801780",
"identity--9c1f6f17-ae1e-4709-980c-59da7555d857",
"identity--b92b7f6e-658c-4676-a0ce-bc086c0423ef",
"identity--2d369946-57f6-4cc6-a1d3-6188c068b6af",
"identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"identity--792b4bf1-e245-4bf6-a7af-691ec493cc67",
"identity--036d98c5-47f7-4ecc-8d8e-84b85d74b95a",
"identity--b874e6b9-ad2a-4d73-8bbc-2b64a47324f1",
"identity--c539c8f3-fdc6-4c01-b021-6a692276b1b5",
"identity--cba6a4c8-d7c2-4920-b40a-dfd14c79a315",
"identity--a62b1e64-cbfc-428c-8f32-0c02de244d90",
"identity--a701bce6-5a88-4421-9f4b-d196320675d4",
"identity--c9c2c807-7468-47a8-aa26-d2a1939bdf1a",
"identity--60728444-0fa0-4364-b9e8-7b13a2a0a39e",
"identity--30a4e96a-17e1-41fd-b1d0-42f314afcbad",
"identity--6abf94d1-d954-405e-941f-ac19be8b0640",
"identity--852c500f-d494-493e-8cdc-762b3da4a046",
"identity--149103ca-f973-4eaa-9358-0d0abf73d77c",
"identity--4729e454-c683-4bf2-8731-994d267945a2",
"identity--a02a40d2-8fdb-42c8-974f-39ecb9c104c8",
"identity--56da7213-126d-42f1-b6ac-f1c7c35720c7",
"identity--04f59a5c-4fe5-4f13-ad37-7123f37c8450",
"identity--b8250ab1-b20a-4e5f-9625-92a0c9db94c2",
"identity--f39292dd-feed-4e72-a612-fb949a6500cd",
"identity--e9e98e9c-e6ca-42cf-926f-04ce2888b75b",
"identity--cd5ed758-3f50-4269-947a-07bbfc1783c0",
"identity--1edb34d6-de9f-48f1-a5f2-49ef98c18a90",
"identity--295982ad-ddb1-4489-9ef1-6f43ba98450c",
"identity--fce10657-5cda-421f-85e9-530cd86b0408",
"identity--1d62e7d4-1f43-46f6-ba79-9ab52c2a62f2",
"identity--4bf3d4a8-1103-476e-b6bb-1267d01718d3",
"identity--ccc9b83b-5193-41b2-a598-9a4888c74b96",
"identity--236f1c98-0841-4a49-a71e-63cf85a45a6e",
"identity--d02156cb-f104-4738-87e3-fb107aa15293",
"identity--9c9a50b3-8f28-433e-8034-a4431d57b580",
"identity--89135b2b-d14e-47f3-a531-2650c6d88ae5",
"identity--501888aa-3916-4d84-814e-fb12df358536",
"identity--38c76e8d-c1c2-46d3-aabb-da1708265fe7",
"identity--758080f3-e58d-4a25-9f17-619337e93a95",
"identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"identity--c877be6e-5a87-41d2-b67e-fc0c6a8c863a",
"identity--aff57248-6ec1-443e-9dc0-cdae100286c3",
"identity--bd0da006-193f-4abe-b494-a048201209ee",
"identity--6a6aecea-5a9e-466a-af52-df7afbc29d08",
"identity--f0a10bc6-27f4-4701-aec6-e9e7ec9af3f9",
"identity--526a6fdb-60c2-4e97-a6f6-f89c3ba04348",
"identity--5e70026d-b8e8-4c0d-b5de-258da0948c51",
"identity--16cbb957-5f20-4aad-b5fe-b977c87a13ad",
"identity--7a9e545a-d22b-4107-8f1d-ca070a62a509",
"identity--019fc5a5-b3a1-4243-bfdc-2077b4adb1b9",
"identity--abdb1961-a887-426a-9f7e-9efa89f21d60",
"identity--a46bd5c4-8af7-4dc1-94a4-ac7372ebaf7b",
"identity--d2ef45c2-8dbc-4d22-935f-5ff8ec8de775",
"identity--c36f0970-fd2f-4eaa-ad45-15199baf6989",
"identity--14cac2c6-ef9d-4d1f-a86f-3af976bf4414",
"identity--d6a33a5d-44c7-407c-b437-28e7861ae6e8",
"identity--4a0ea356-910b-4135-8390-c178705bb54c",
"identity--dfec3c7f-6c46-4cac-80cc-167b73dd3d1d",
"identity--36d83c8e-6507-4c69-9f17-6ed6ab75a4bb",
"identity--808befef-50a2-4662-93fb-72d77116b132",
"identity--e0ae0533-20cc-4659-89e4-28556a17d19e",
"identity--fd115d83-07a0-47ac-a02b-9a673cd744ab",
"identity--5b9dbb78-fc03-4eb4-9d70-4bee7cbfd972",
"identity--d84c4873-2277-44f8-b5e2-745a72741ebe",
"identity--e579f0b6-29fc-4f87-be26-0870951a61da",
"identity--ec0c1d7a-7d0a-4df5-bda2-e0e470408f63",
"identity--820d45b6-ab79-4ad8-833e-625b97e265fd",
"identity--a08d4c29-b21a-4dd7-a9a1-4886ea585e24",
"identity--044fde07-eb6c-4c20-922f-0b39f08e3011",
"identity--fc9b3eeb-bb7f-4624-95dd-75bf425ded59",
"identity--161fc746-cd49-4615-ab48-81a93a1b16b4",
"identity--2daf3eee-ee2d-4a01-b724-90e3ce3a3f4f",
"identity--4f7dd0b7-e698-4315-842d-423f0e087543",
"identity--2e53c328-2ca3-45f0-83f3-fa57d820b563",
"identity--ff7fd6dd-7fc3-4198-bbee-c9e3f269a5a5",
"identity--6b22e13c-2eb9-45bc-a13e-e9ea98dff190",
"identity--cf099ab9-0bef-4468-b24e-ac6319addc2e",
"identity--681f4631-bbe3-4600-ac06-5613e29c9cbd",
"identity--f9f67fe7-735c-4107-8f6e-5dc3164bc5ce",
"identity--a343afe6-1d0e-400a-8a27-09ce11198c99",
"vulnerability--3def0baa-88d9-4bec-85e7-2c5cecf77a3e",
"vulnerability--9b3f5a1e-a7a9-4b98-b171-2dee5840f329",
"vulnerability--e3e71ecc-fec4-4862-a001-4c33159df6be",
"vulnerability--c40fdbce-958f-4e64-9ab1-21854ee00947",
"vulnerability--64f1084c-d47d-40a1-99df-ad6c1c6f5608",
"vulnerability--8d7c4a88-ce42-4945-8ec6-c3457d00fd16",
"vulnerability--40b77602-9d0f-436c-9f38-b1b3836a002e",
"vulnerability--68788c3d-bce1-4d03-95c1-e37006ca5e61",
"vulnerability--b749c82d-36dd-45b2-bb6a-3af87c2516ab",
"vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"vulnerability--202ddc5d-7c58-4a53-b475-4167098c2e61",
"vulnerability--d320478d-ee2b-4f15-9b93-823cfc797a94",
"vulnerability--0a7cd6eb-6e7d-4471-a46e-60fda6a10285",
"threat-actor--23532327-1fb0-44d5-9abd-363bfb924874",
"threat-actor--1c24883b-5440-48be-89b4-b0c9d2b0646b",
"threat-actor--5ea0d2af-c73f-44b7-9596-ae5f9a3ff7f3",
"threat-actor--edfc3090-ec61-44a7-8e38-e5c05bfd4909",
"threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"threat-actor--3de981ea-bc76-46c4-86f0-6159ae1637cc",
"malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"malware--edf00ddd-9f52-489e-be39-c330ca2a6690",
"malware--536cf582-37c8-439a-aa79-38b89bc7c52d",
"attack-pattern--d5f68c3e-3583-497a-8fd3-6fe32b38bf5f",
"attack-pattern--e8d516a9-a107-4c4b-806f-bc9c612eef18",
"attack-pattern--5aa11eb6-804f-4920-a45f-1fae275ef314",
"attack-pattern--2c821981-fda2-4cb8-926c-6edd4905d65c",
"attack-pattern--01df90e4-619d-4268-90c9-6e2aa84079d9",
"attack-pattern--771ed4e5-6dde-43a8-9c72-d006b0c83e3d",
"attack-pattern--e5974f70-5745-450a-908a-6483ad9c4678",
"attack-pattern--d5229cf6-f11b-41bc-8aca-0df713047400",
"attack-pattern--9ba6495b-e273-4e8d-a4ce-dbcd56ec33f2",
"attack-pattern--280ebd89-59bc-4ae2-a9db-1c01a56e50dc",
"attack-pattern--13fc9cbe-9444-4eba-872b-a44565ae3ab7",
"attack-pattern--06cf8802-38e4-4421-a699-33a0bae74d96",
"attack-pattern--2e52cc86-c2ef-43d7-9f1e-2fc59c4845ee",
"attack-pattern--943edc6f-c0f9-48f1-b8d4-4666aa0abae1",
"attack-pattern--f33f5834-6a9a-4727-88a5-9d35eeba1cff",
"attack-pattern--2d26e3d0-4bbf-44c3-aa9e-5aeab4937638",
"attack-pattern--2da268b5-7100-4dbc-b23b-d5deafdf268c",
"attack-pattern--baad7d00-8591-4c49-8f48-fabb6a35df65",
"attack-pattern--c627c29c-1385-4d76-9046-9c2db86dab11",
"attack-pattern--ce39e6f2-b20f-421e-83e1-242a773e1927",
"attack-pattern--b0e5285c-e953-4745-a8d6-56e03a076a5c",
"attack-pattern--4a2578d4-fdf6-48d3-b66a-93c681e1e21e",
"attack-pattern--68a5c7b8-09b4-49b1-8149-bc23ed0260c9",
"attack-pattern--298cad89-6cfc-4a7e-a231-76b81f275a3a",
"attack-pattern--181753c8-21ea-4cce-a21e-fc6cfbaee56b",
"attack-pattern--0ec57ff0-0257-4287-888c-8f20c7e08c6b",
"attack-pattern--3cfe33ad-33e7-4370-a083-fd1b2c9457ab",
"attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"attack-pattern--88428b3c-f02f-45b8-a38a-0541b2287509",
"attack-pattern--d2a77ce3-d278-4f77-97f0-227b744a33d3",
"attack-pattern--a6ff86fe-f269-42e5-9428-ab17d04e30e2",
"attack-pattern--27b36b6d-ae90-4767-b07a-563ecef589ea",
"attack-pattern--ed3369e1-8515-458a-99e3-cb9283fb73d1",
"attack-pattern--5cf0f3fb-3459-4a3d-ad3c-4700efcfecd8",
"attack-pattern--cfdf109a-1036-48eb-a479-ee1f681a1c11",
"attack-pattern--172f3845-7870-4c1c-80bd-251e10ce9f1e",
"relationship--48f84fe3-4b3f-4bf7-9599-f1e7cbc6b34f",
"relationship--e4ff26a5-876b-445b-a6a7-7e7cf3c46829",
"relationship--43ae0778-99c3-482f-90d8-18adb0a2ee06",
"relationship--6e9b06a4-8037-405f-8f61-60d8e4e66d36",
"relationship--02c2ad37-f72c-4c58-90a2-90fad9961b3b",
"relationship--32e4c09f-927a-43b8-b494-bc3ae5948986",
"relationship--912142ef-7ddc-4d3d-87dd-c099552eab96",
"relationship--9430d612-3ae1-4bed-b2f0-d4c9def50df2",
"relationship--8cfa4fa6-ddd4-4189-aae8-ba6cc0894bb5",
"relationship--ac8cc184-6ea8-46c9-9801-6632851ab8d1",
"relationship--0ebfe468-7418-4ac1-b5b2-09d48da2bfb4",
"relationship--7bd08db7-a16e-4a56-866b-61fa06fd74f9",
"relationship--38d6b61d-522c-42a0-80bb-14623a623319",
"relationship--604c2866-393e-4bcc-aa44-c53d34db8c6e",
"relationship--c85ff316-8872-439a-ae7f-2093e90f8197",
"relationship--061d6410-351f-42bc-a889-7899955d4a6a",
"relationship--b51a4ce3-ef49-49c0-ba21-cf7c71b07129",
"relationship--8c8a6706-6eaa-4015-900c-016ebcd085c1",
"relationship--c51abcce-894a-4d37-91fe-e827135d9b6c",
"relationship--7a4b80bb-544e-4208-8b9b-e3f99b98f3c7",
"relationship--ba8b55f9-a543-49f7-ac7d-4985b77bef27",
"relationship--cb2d2062-e545-465f-8e7c-b113444876e3",
"relationship--ee36c8d6-b1f2-4cbe-815c-0391a0ddc737",
"relationship--10912c64-4fe0-476e-acb4-392c8a3a7cfb",
"relationship--58a52156-0510-4a3f-9e07-af57145f042f",
"relationship--c8bd7b28-1313-4380-bdb4-b3fbfe07a490",
"relationship--7ee4d53e-9e2c-47bb-9e44-0bacb52f3c32",
"relationship--87627ab4-4fa7-47a2-98df-5398ca88fc1b",
"relationship--f564068c-ff66-422b-add0-55876d8934e0",
"relationship--8eb154c5-6e40-4374-835d-e99350e9d30c",
"relationship--aa7bd7b7-fd21-4a1d-b445-6f52b968e38e",
"relationship--3c0be556-f5af-4668-b090-858b9556a259",
"relationship--5748d798-706d-48cb-a045-e6408cb3389e",
"relationship--4abe7d34-ec73-490c-ab5e-9a3a07b6bdb3",
"relationship--255248f7-a611-4144-b648-b57d6583b1f6",
"relationship--77cf90d1-ebf5-43d4-a2e8-0314ac133e1c",
"relationship--dae3027b-68fa-4d39-b1c2-04837c6c4294",
"relationship--94817487-b376-49c6-bfd1-c14d51522291",
"relationship--2d0d573f-7b16-4cd6-9d90-19152163c480",
"relationship--ad0ac28a-9557-4e95-84a3-de1da11739cb",
"relationship--8309b882-49c7-4f20-815d-01aab312d61a",
"relationship--b93a5ed3-1d73-44e8-8e25-81d7a7b8146d",
"ipv4-addr--fcf9628c-46ee-4edd-8552-8e890e71f271",
"ipv4-addr--398631a3-2e68-4b99-9fda-54f70ba0e582",
"ipv4-addr--67b1fe8b-a3a1-478c-9a36-4e6d2c2a5556",
"ipv4-addr--a5d4b3ba-ab5d-4c86-8046-30480c7daded",
"file--99b57e02-f77b-489f-a871-74fce6113ee6",
"file--0b34e0d6-ec1c-4f31-9803-109aad01dce9",
"file--ed611eba-6db4-4557-899e-5b979f8c6594",
"file--cdd07d77-85b3-4ab8-9895-4b25771c7e8f",
"file--99af8978-ff6d-4350-9560-7e35a39ce833",
"file--82931dde-1bfe-41e8-96ed-0adbd7371ee5",
"file--ce952501-f160-4d19-aeba-e052a9275351",
"file--bf0c4613-58fb-4693-8c03-2c5760c29aeb",
"file--c7dc8c85-8223-40b0-bafc-e565545c0804",
"file--e6e80c7a-3ef5-4113-98b6-7b35923fff66",
"file--fa972639-2121-4b38-b07e-9f611571de4b",
"file--4c15829b-c9f7-4705-a136-54df96f3e81c",
"file--78093583-ed9c-4a78-a408-78540711dad5",
"file--1bef0928-f61c-4de3-9583-d549a0a61340",
"file--7f6b73e1-71a5-4928-ba7e-a7d424da5261",
"file--8e3c53c8-0f35-4917-8be6-25e54a773733",
"file--84fe9cd3-b640-40d1-84f1-4993d16e4a8d",
"file--1376cd0f-6cfd-4b5c-8d39-e019c9921b12",
"domain-name--30fe8fb8-23b8-497a-9afd-0769b5c73565",
"domain-name--0294587c-f38c-42fa-b687-8371012afd2f",
"file--36d8f279-8ff1-49a2-a74f-ceddb59de59a",
"file--1c8cd1e3-13ba-4560-af1a-68b94ae4d208",
"file--fc159c6a-cbbc-48b6-b9c5-b9d11dc308dc",
"url--007a390b-ae5c-41ea-8d83-75475c8863b4",
"url--0c8a0b99-5259-4856-a05d-fc0d8fdf3130",
"url--7e3e8791-000a-4d83-b1bc-2d2ef77ef361",
"domain-name--efc14d82-8b97-4e0a-9883-58a8a94159d8",
"domain-name--ddfc1d32-6440-4540-8187-f0f6e0ac6ac3",
"domain-name--ffb0d50c-d04b-428f-81e5-2e6089155d07",
"file--7925dd7f-fffa-4046-b14e-aad2c769e80c",
"domain-name--b31b3aed-28d4-4323-a196-a30173214292",
"file--8bac32f8-d87e-45e4-aed5-4ce1edf54766",
"file--333175c3-f421-4596-87d8-88a35151ba3e",
"file--94ffe6cb-fa37-4cba-bb6e-22f15fcc0f07",
"file--79f80763-776e-418d-ae7e-04750d99709a",
"file--4322174b-e54a-43d9-bea2-f789964dae65",
"file--9119ab3e-b456-4773-94ca-6d5807456a17",
"file--012569f1-63f2-4b87-8454-9430e3918960",
"file--bcac6dff-8d37-4d25-b8a4-de5f312aca1a",
"file--4e241c1a-39d5-4517-9e6d-bd8c64c9c290",
"file--4801bd56-5685-4fd4-8708-7b8d0066ba6d",
"file--069808d1-aa93-48b0-8772-d7fa42df6a1a",
"file--3460d037-0755-42a2-b9c1-d30cdbf42d89",
"file--c9ac9738-5dc0-402e-bcb5-6e8b9c893d98",
"url--19b8373f-8afa-4c1b-921c-f33833daabf2",
"domain-name--5b2fadde-50a0-43b1-82cc-ac906b7d7596",
"domain-name--0c4e404a-a048-4ca7-b9ad-90b7edf3fc60",
"url--10c79a48-c78f-4ff5-992d-db190386eab4",
"url--538bb72d-ee7d-411e-bd70-cf8032f6a99d",
"domain-name--62adba55-6e03-405b-8965-e47a6445ede3",
"domain-name--6b507e8a-ab34-47ec-8a60-7b2863948bcb",
"domain-name--df828e3e-85a8-4ee0-826f-deb316e746fa",
"domain-name--74be08f3-bd23-45e6-8d59-84492a4780a4",
"domain-name--28e9d7c8-0b79-4e22-b594-da2291b0c3af",
"domain-name--b308d0ef-e8bc-4be4-b03a-661339743bf5",
"domain-name--bb4bbf8f-8930-4e91-879d-2d505c5175f1",
"domain-name--80ffe91c-3a3c-450a-8cf7-6dd47fcd7072",
"domain-name--d55c2760-6f63-4228-9d33-987a519fda0a",
"domain-name--2f57b158-e2c7-4db9-9f40-b80afafd2d62",
"domain-name--391ac3cf-a457-45da-b2ce-42b96918eabc",
"domain-name--9ba644e6-8d5b-44de-8410-0ee596bbe47b",
"domain-name--976696e7-8a15-405c-8174-3339573aa204",
"domain-name--418ce282-95bf-4b4b-bfe2-6bb15a40d24c",
"domain-name--9f1fc006-128c-4a35-aff9-1189f46f3a6e",
"domain-name--2d0ca9fe-8b44-4d7d-9f4d-6982043163c2",
"domain-name--27e6fd86-874b-4daf-b94e-88fb39f40a47",
"domain-name--8206c595-f663-4051-b7ef-f6239a1c0636",
"domain-name--d0c82521-7ef2-4948-bfcb-4b1df6d7e798",
"domain-name--45c5ea35-0cc1-44ca-ab7a-9f8b22a66250",
"domain-name--a571934d-b012-49a0-bc9b-3cc31e010e59",
"indicator--3737f004-0f2b-41e0-89fd-b49cd9f3791d",
"relationship--b279757d-daf3-44c0-8697-158e88eab854",
"indicator--222fb629-adc4-4ad2-84c2-513e4aaae7eb",
"relationship--6dbe468f-6be1-40b1-9dac-446593eb3a2d",
"indicator--c9370069-b197-4cc2-8627-dc88ee96f4ab",
"relationship--a0b3e41d-7d3e-437e-b6b5-7dd3eb4fbfdd",
"indicator--7996bfe4-3d91-495f-843d-fc32cc8c9d3d",
"relationship--52923c5b-dc35-42b8-9d72-f5025df4a5e0",
"indicator--46f4d47e-a42c-4531-a4e9-7b6defc9ffab",
"relationship--5805ce93-d1a2-490a-9f4e-9abcd2ff92ba",
"indicator--0d14a12b-6921-47a6-bc93-1dc87192a060",
"relationship--ded5768e-927c-487a-8444-7bb5dc26ead1",
"indicator--1fffda73-7b0a-4033-83ae-bdaf2f2dd788",
"relationship--7269624e-a880-4f19-9d12-28a9987195f7",
"indicator--a49cc7de-6154-411c-88ea-c9b3eb194dcc",
"relationship--94c725ea-0e36-419e-8669-83a87f9f4e0d",
"indicator--74c946b6-0004-42e8-bf8e-489e5bf9cbaa",
"relationship--4416a98c-e048-420d-9c37-56bf147dde00",
"indicator--d038a601-abfb-49f1-a600-78b9fd77cb07",
"relationship--95226818-ee24-47a0-b2a2-62123742382a",
"indicator--cfa5cc77-7f4f-4dff-994f-e2e0897fdb85",
"relationship--ed446572-5c85-4f27-99ae-c56380d9bbb7",
"indicator--999b2cfb-e4ca-40d5-9719-cbe28bda117a",
"relationship--40c1281a-ff34-429d-8354-030d481d04b0",
"indicator--87755302-fafd-4ae3-9a73-8fc351f09768",
"relationship--eab88738-408f-4cd6-9ec5-01696e16a4ac",
"indicator--4724a470-d53f-49c1-aa0a-2992d369112a",
"relationship--a629e544-9b5f-4209-9871-1915dbe784a8",
"indicator--25891cad-bf27-45e7-8b05-11348825d00c",
"relationship--1247286b-7d48-4ea0-ae32-2320bc1cfdf7",
"indicator--13dd4672-0a1d-48b9-9e90-8bc0ba6e796d",
"relationship--ff8ea414-b64a-40a6-9d6f-42cc213f18f0",
"indicator--ab06cb65-46de-4149-85ea-69eb7f394826",
"relationship--bb47a588-536d-45db-a7f5-8d2004d89f2c",
"indicator--793ac21b-491d-4fbd-966c-91e220776790",
"relationship--6668ab45-82f7-48b4-bbe1-4e954c0c41ce",
"indicator--730d36c8-c593-45a4-b417-afc0fcb16a64",
"relationship--93740008-f911-4122-9c05-bbc01e9b3b10",
"indicator--fb0591cd-f547-4081-af7c-c6084a29a480",
"relationship--04816d97-cd7e-49c2-aa34-8c8172b6e451",
"indicator--6a020350-6536-45a7-b163-8cfbbfce8c65",
"relationship--8e7ca3a7-1c2a-40c5-908d-2748fb37ca5b",
"indicator--c0c08ed1-8e4b-4a96-8b2b-8c01196cf52e",
"relationship--b4246c74-8fb9-4eab-8875-ad9b21dd9bf5",
"indicator--0638421d-0ea0-40c9-9c01-ba1956f7ceb5",
"relationship--091131d5-f2bf-4d35-b94b-9b798aee5959",
"indicator--56a0fee6-9cf2-42c1-93e3-ba7c4a8dc640",
"relationship--0325d5bd-98be-4c0e-8431-db8de0d06823",
"indicator--1ef63244-3232-4c1f-a9a7-afc46789b06e",
"relationship--5cc47bf7-d37f-4f39-ada4-edda32c3c1f7",
"indicator--b31b89c8-9cf5-443d-a2e4-16836da9099a",
"relationship--7eff61fb-a1ca-413c-a0f8-c2c487093832",
"indicator--9897a661-c77e-4c4e-a3cd-f2d79a684f89",
"relationship--545fc567-a68c-4408-9eaa-c69a8a0cefb3",
"indicator--abf6326c-ebe0-415d-869b-556efe0c400c",
"relationship--5cfd0e4b-b2b6-447c-86d8-4309f3efebd7",
"indicator--3deeef52-fe28-4cf5-a3e3-c6cd6765a6e6",
"relationship--efe47c35-eff1-4d87-a2ec-08a1e70ec6a3",
"indicator--9b72bc53-c523-43e0-905a-059a5ff0a0fb",
"relationship--e71f29e6-d674-4450-9b77-8f748e298a20",
"indicator--d598d739-4f88-4cc4-bd75-9ee929f11ec4",
"relationship--76ba4ee0-bf1c-4896-a13b-17aef6ae522d",
"indicator--12dbd412-bc93-489b-b6fe-7b01c1041dc3",
"relationship--1f7fe038-c95d-4687-8842-a90bb83d0951",
"indicator--2a7de07e-5a66-4299-aea3-e2373960d96c",
"relationship--a7eb95dd-49c1-43a8-804c-811741735335",
"indicator--e4b924a8-36ee-486d-8e81-75ee2fa45455",
"relationship--81192100-2de1-4ad4-9f19-42d7fa0a9b02",
"indicator--e2bb4aae-e13a-4e80-9fe0-56969946b999",
"relationship--83203b02-545a-447d-a5f5-9274b99fb057",
"indicator--f6759fb4-83dc-442d-96a5-b067ff866182",
"relationship--49a0c1e9-d9e9-4683-909d-e7caa1ebc09f",
"indicator--f01dff36-a09e-4302-b53a-0a7f9a8de800",
"relationship--57f7e749-9a87-4576-9915-86cd5ea69df7",
"indicator--1573198e-ac23-4f09-8706-cd66f3e35253",
"relationship--742ae493-808b-4779-b6ee-bd2a71f531fa",
"indicator--aff4b601-5c3c-49e9-9032-aa53343b3e72",
"relationship--3807e6f1-2c43-4583-9210-298c64827b23",
"indicator--7130cd0b-cffd-43d7-9373-43c03e79ec75",
"relationship--bcb0220a-46d6-4126-8c88-079623e72961",
"indicator--dcd31d31-e328-428f-b7e3-851b1fe9de52",
"relationship--d7f7b681-fd0e-48a6-a3bc-594181b45e71",
"indicator--15d7a563-d657-402f-b00a-7d7e016d2dd9",
"relationship--525152fb-0580-4862-bef1-c8e6a41855f7",
"indicator--36abf4a1-0626-48ce-88a7-ac4731ab9d2c",
"relationship--a844c4bc-d87f-4ee2-a2a8-362a40d6c4c1",
"indicator--deb86168-e00b-41c6-8f7a-cf774bbff169",
"relationship--42b6a511-70d4-4342-be74-45d2d505d958",
"indicator--7ffe8762-9d18-4848-8b86-05362e1f789a",
"relationship--f7eeccdd-b09c-4114-93cc-12a534c6ac45",
"indicator--5a20f3f5-cec5-4aba-a5c3-c3cddec2a787",
"relationship--51e93463-294d-43fc-b484-aec46ba9109e",
"indicator--5cb65448-a86a-4ec2-bb3e-5a0ce7a38cda",
"relationship--c6308b85-526b-4061-80ac-5ec641dacbce",
"indicator--8abd1692-d843-40dd-9156-1a77e3a2dcad",
"relationship--07223623-a0ca-45b1-9dc7-994df0e13219",
"indicator--0ddebffe-8ebf-46d5-84bb-340ced6f8cbf",
"relationship--e2e397b7-1348-4867-a713-23a1abf5710c",
"indicator--3fd9a3d6-704e-4be1-918f-d43c6b36285a",
"relationship--93da6b60-9360-43e4-b1fb-2242cd4ad605",
"indicator--a5bafdcb-b820-4a86-8828-785c1b560ecd",
"relationship--8e9285b8-b873-4ccb-97cd-043dc3c381bf",
"indicator--54ea5c64-cd37-48d8-b792-61b9df2964b4",
"relationship--62c50bb3-3d83-4667-b3c9-b858ad6b4f0d",
"indicator--c1599584-b529-4b8f-9b74-8a439c47a6d9",
"relationship--34acd7e6-7968-49db-b7e8-3fa6c4458bd5",
"indicator--c9e3aee3-bc2b-4fcf-8cf3-59c7e35c8c66",
"relationship--7c6bf2f8-4e9e-458a-a256-17e33e3926f5",
"indicator--0aabb538-8f14-483a-b01c-c22d84d59f29",
"relationship--bbfe67e0-a90a-41d3-aacb-9be05a5ab4ed",
"indicator--e7608f70-1278-4214-82fa-9b1f5aa81e3a",
"relationship--403174e9-078b-4eca-a0d5-3603e5a6c248",
"indicator--f0da10b8-8aa2-4b32-b7bb-6b3e8b3e60ae",
"relationship--24c7e63d-f345-4918-81a3-cf51a2ec1aa6",
"indicator--96fe08c8-9261-41ab-bbfb-70b55be19e7d",
"relationship--3e09c8fb-1f88-4ffb-8894-49ba613e2689",
"indicator--37e78efa-aff9-4ecb-ad1e-e65c08e2266b",
"relationship--5539cf9d-1220-480e-bbf5-7b23505e8e47",
"indicator--6807be85-c2c0-4018-9f40-57e414618ffc",
"relationship--30fc30ee-45fb-4742-9357-6490a9a7095d",
"indicator--4758589f-65fd-4c8a-a89f-ca6e25040980",
"relationship--62caa360-3c23-4bbe-974b-62e3feb09793",
"indicator--89183394-9a69-46be-999f-118521070062",
"relationship--cfb738f0-e0a2-4c5f-8682-40b11a4b2d2a",
"indicator--186178b1-0251-467a-b185-218db858fc28",
"relationship--9ca024be-b1fc-4a7a-a12d-80d2a5a208c2",
"indicator--2d5953de-e767-4555-be85-efd552896be8",
"relationship--b08a5303-a212-44fb-a95a-938f80b47caa",
"indicator--c320b2fd-1972-4746-9959-032903ccf1f8",
"relationship--73773b7f-04e2-45b1-819e-89cbc0bbcdc3",
"indicator--930c6000-68ca-41f6-8ffb-a9450d2a661f",
"relationship--8d8b3d20-e976-461b-b0b7-b695f1cb2572",
"indicator--31aadb97-e8c8-4a7e-8a8c-74017b8dd1dd",
"relationship--95552b18-461f-4ed5-a515-6704e0809b70",
"indicator--0af750d9-370a-4045-8e93-1f03bb62583b",
"relationship--99116855-694e-4585-bdd8-7628932e80c2",
"indicator--3f41a446-df69-4d61-944f-753010cbee01",
"relationship--68e9a820-33fc-46bb-bada-998ac016e66f",
"indicator--2c2f5b19-ea28-4578-b447-aa7968d94bca",
"relationship--fccf5b4e-cc93-40fe-85e6-79c0d6423e69",
"indicator--e1815691-2274-4ff2-8bef-37478d267c47",
"relationship--ddaebeb0-c877-44ab-b184-7e90addc0c15",
"indicator--ee1b0ec0-f921-40db-8c67-b45b94f06fba",
"relationship--ecc67cda-e976-4b83-83e4-9125457dcfc6",
"indicator--71287744-8540-45b7-8507-910dd65a5358",
"relationship--2ae2adb9-0c9f-4213-a986-7fd443b8de3e",
"indicator--b47badd0-1be0-4d56-aa16-02cf0f545b8c",
"relationship--ebf5e693-7ed0-43a1-bc34-e525db0f0201"
],
"labels": [
"threat-report",
"threat-intelligence"
],
"created_by_ref": "identity--e8be913a-4c5f-47a6-8884-f3554f2c96a5",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.211Z",
"modified": "2026-05-08T14:57:19.211Z",
"confidence": 95,
"type": "identity",
"id": "identity--08dad444-0d55-4ed2-a88b-086c37d76c5c",
"name": "United States Cybersecurity Institute",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "An organization focused on cybersecurity education and research.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.212Z",
"modified": "2026-05-08T14:57:19.212Z",
"confidence": 95,
"type": "identity",
"id": "identity--d7b2b636-3a3b-4955-8425-21f44189be7a",
"name": "Common Vulnerabilities and Exposures",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "A list of publicly known cybersecurity vulnerabilities.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--e6eec92a-f639-45e5-a2b1-7314cc103f42",
"name": "OpenAI’s Trusted Access for Cyber",
"identity_class": "system",
"labels": [
"identity"
],
"description": "A product or service developed by OpenAI",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--89c66628-698d-41c6-a616-d159a9f64219",
"name": "Microsoft Entra External ID",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Microsoft Entra External ID is a service for managing external user identities.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--daab77e6-85d1-4e69-8b9d-e228d91902c2",
"name": "Common Platform Enumeration",
"identity_class": "system",
"labels": [
"identity"
],
"description": "A list of applications, operating systems, and hardware platforms.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--fe19caea-135f-4ae7-b916-2d6d2e207d24",
"name": "Common Weakness Enumeration",
"identity_class": "system",
"labels": [
"identity"
],
"description": "A list of software weaknesses.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--17d85fe0-e189-492a-8b69-6e8f0b6a5007",
"name": "Bitdefender GravityZone",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "Bitdefender GravityZone is a cybersecurity product.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--e82541d6-05a3-4ed7-bd7e-a089527ebf7a",
"name": "Cybersecurity Ventures",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A company providing cybersecurity research and analysis",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.217Z",
"modified": "2026-05-08T14:57:19.217Z",
"confidence": 95,
"type": "identity",
"id": "identity--4c8e1191-64c4-4d4a-bcaa-5128f7801780",
"name": "Container-Optimized OS",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "Container-Optimized OS is a Linux distribution.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--9c1f6f17-ae1e-4709-980c-59da7555d857",
"name": "Kaspersky Thin Client",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "A thin client operating system offered by Kaspersky.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--b92b7f6e-658c-4676-a0ce-bc086c0423ef",
"name": "Cushman & Wakefield",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A real estate company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--2d369946-57f6-4cc6-a1d3-6188c068b6af",
"name": "Deniss Zolotarjovs",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "Deniss Zolotarjovs is an individual.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"name": "Palo Alto Networks",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity company.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--792b4bf1-e245-4bf6-a7af-691ec493cc67",
"name": "Manu Chandrasekhar",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--036d98c5-47f7-4ecc-8d8e-84b85d74b95a",
"name": "WCYB Digital Radio",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "A digital radio station.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--b874e6b9-ad2a-4d73-8bbc-2b64a47324f1",
"name": "Riggs Goodman III",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--c539c8f3-fdc6-4c01-b021-6a692276b1b5",
"name": "Sentrium Security",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--cba6a4c8-d7c2-4920-b40a-dfd14c79a315",
"name": "Ubuntu’s AppArmor",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "AppArmor is a Linux security module.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--a62b1e64-cbfc-428c-8f32-0c02de244d90",
"name": "Matthew Campagna",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual, possibly a researcher or security expert.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--a701bce6-5a88-4421-9f4b-d196320675d4",
"name": "KrebsOnSecurity",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "KrebsOnSecurity is a cybersecurity news and investigation website run by Brian Krebs.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--c9c2c807-7468-47a8-aa26-d2a1939bdf1a",
"name": "Vaishnav Murthy",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--60728444-0fa0-4364-b9e8-7b13a2a0a39e",
"name": "Ivanti Endpoint",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A specific company or product",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--30a4e96a-17e1-41fd-b1d0-42f314afcbad",
"name": "SecurityAffairs",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "SecurityAffairs is a cybersecurity news site.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--6abf94d1-d954-405e-941f-ac19be8b0640",
"name": "Todd MacDermid",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--852c500f-d494-493e-8cdc-762b3da4a046",
"name": "Michael Fuller",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual, possibly a researcher or security expert.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--149103ca-f973-4eaa-9358-0d0abf73d77c",
"name": "AWS CloudTrail",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "AWS CloudTrail is a service that helps you govern, comply, and audit your AWS account.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--4729e454-c683-4bf2-8731-994d267945a2",
"name": "Ivanti Neurons",
"identity_class": "system",
"labels": [
"identity"
],
"description": "Ivanti Neurons is a cybersecurity platform.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--a02a40d2-8fdb-42c8-974f-39ecb9c104c8",
"name": "JulietSecurity",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "JulietSecurity is a specific named organization or company.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--56da7213-126d-42f1-b6ac-f1c7c35720c7",
"name": "Luigi Gubello",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A specific individual, possibly a researcher or expert.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.218Z",
"modified": "2026-05-08T14:57:19.218Z",
"confidence": 95,
"type": "identity",
"id": "identity--04f59a5c-4fe5-4f13-ad37-7123f37c8450",
"name": "Matthew Knoot",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or security expert",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--b8250ab1-b20a-4e5f-9625-92a0c9db94c2",
"name": "Prafful Gupta",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--f39292dd-feed-4e72-a612-fb949a6500cd",
"name": "Prisma Access",
"identity_class": "system",
"labels": [
"identity"
],
"description": "A cloud-based security platform by Palo Alto Networks",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--e9e98e9c-e6ca-42cf-926f-04ce2888b75b",
"name": "Ivanti Sentry",
"identity_class": "system",
"labels": [
"identity"
],
"description": "Ivanti Sentry is a cybersecurity platform.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--cd5ed758-3f50-4269-947a-07bbfc1783c0",
"name": "NSFOCUS CERT",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "NSFOCUS CERT is a cybersecurity team.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--1edb34d6-de9f-48f1-a5f2-49ef98c18a90",
"name": "Erick Prince",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A person, possibly a security expert or researcher",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--295982ad-ddb1-4489-9ef1-6f43ba98450c",
"name": "Corey Thomas",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a security expert or researcher",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--fce10657-5cda-421f-85e9-530cd86b0408",
"name": "Anshu Bathla",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--1d62e7d4-1f43-46f6-ba79-9ab52c2a62f2",
"name": "Victor Lungu",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--4bf3d4a8-1103-476e-b6bb-1267d01718d3",
"name": "Sourav Kundu",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--ccc9b83b-5193-41b2-a598-9a4888c74b96",
"name": "Cydney Stude",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--236f1c98-0841-4a49-a71e-63cf85a45a6e",
"name": "Jason Garman",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--d02156cb-f104-4738-87e3-fb107aa15293",
"name": "Vivek Gautam",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--9c9a50b3-8f28-433e-8034-a4431d57b580",
"name": "AWS ProServe",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A company or service name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--89135b2b-d14e-47f3-a531-2650c6d88ae5",
"name": "Tobias Nickl",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual, possibly a researcher or security expert.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--501888aa-3916-4d84-814e-fb12df358536",
"name": "Jeff Pollard",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A specific individual",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--38c76e8d-c1c2-46d3-aabb-da1708265fe7",
"name": "Allie Mellen",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A specific individual",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"name": "SentinelLABS",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity research organization",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"name": "Shadowserver",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity organization that tracks and reports on malicious activity",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--c877be6e-5a87-41d2-b67e-fc0c6a8c863a",
"name": "Cisco Talos",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity research organization",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--aff57248-6ec1-443e-9dc0-cdae100286c3",
"name": "Rashmi Iyer",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--bd0da006-193f-4abe-b494-a048201209ee",
"name": "Mark Ryland",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--6a6aecea-5a9e-466a-af52-df7afbc29d08",
"name": "Arpit Gupta",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--f0a10bc6-27f4-4701-aec6-e9e7ec9af3f9",
"name": "Hyunwoo Kim",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A specific individual, possibly a researcher or expert.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--526a6fdb-60c2-4e97-a6f6-f89c3ba04348",
"name": "Amy Herzog",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a researcher or expert in the field of cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--5e70026d-b8e8-4c0d-b5de-258da0948c51",
"name": "Ryan Gomes",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--16cbb957-5f20-4aad-b5fe-b977c87a13ad",
"name": "Dipan Mann",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A person, possibly a cybersecurity researcher",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--7a9e545a-d22b-4107-8f1d-ca070a62a509",
"name": "CloudWatch",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "Amazon CloudWatch, a monitoring and logging service",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--019fc5a5-b3a1-4243-bfdc-2077b4adb1b9",
"name": "Cloudskope",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Cybersecurity company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--abdb1961-a887-426a-9f7e-9efa89f21d60",
"name": "Braintrust",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A specific group or organization, possibly related to cybersecurity.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.219Z",
"modified": "2026-05-08T14:57:19.219Z",
"confidence": 95,
"type": "identity",
"id": "identity--a46bd5c4-8af7-4dc1-94a4-ac7372ebaf7b",
"name": "Indusface",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Indusface is a cybersecurity company.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--d2ef45c2-8dbc-4d22-935f-5ff8ec8de775",
"name": "EasyDMARC",
"identity_class": "system",
"labels": [
"identity"
],
"description": "EasyDMARC is a tool designed to help organizations implement DMARC (Domain-based Message Authentication, Reporting, and Conformance) to protect against email spoofing.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--c36f0970-fd2f-4eaa-ad45-15199baf6989",
"name": "Matt Meck",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--14cac2c6-ef9d-4d1f-a86f-3af976bf4414",
"name": "Forrester",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A specific company or organization",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--d6a33a5d-44c7-407c-b437-28e7861ae6e8",
"name": "AlmaLinux",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "AlmaLinux is a Linux distribution.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--4a0ea356-910b-4135-8390-c178705bb54c",
"name": "LinkedIn",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "LinkedIn is a social networking platform designed for professionals and businesses to connect and share information. As a major online platform, LinkedIn's data is a valuable target for threat actors seeking to exploit professional networks for social engineering attacks. The exposure of 4.3 billion professional records, including LinkedIn data, poses a significant risk to individuals and organizations, enabling large-scale AI-driven social engineering attacks.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--dfec3c7f-6c46-4cac-80cc-167b73dd3d1d",
"name": "MojoAuth",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "MojoAuth is a cybersecurity company.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--36d83c8e-6507-4c69-9f17-6ed6ab75a4bb",
"name": "Woolwine",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "A specific individual, Wade Woolwine",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--808befef-50a2-4662-93fb-72d77116b132",
"name": "DigiCert",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A company providing digital certificate services.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--e0ae0533-20cc-4659-89e4-28556a17d19e",
"name": "Panorama",
"identity_class": "system",
"labels": [
"identity"
],
"description": "A network security management platform by Palo Alto Networks",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--fd115d83-07a0-47ac-a02b-9a673cd744ab",
"name": "Mastodon",
"identity_class": "system",
"labels": [
"identity"
],
"description": "Mastodon is a social media platform.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--5b9dbb78-fc03-4eb4-9d70-4bee7cbfd972",
"name": "Paessler",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Paessler is a German software company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--d84c4873-2277-44f8-b5e2-745a72741ebe",
"name": "Kratikal",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Cybersecurity company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--e579f0b6-29fc-4f87-be26-0870951a61da",
"name": "Android",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Android is a company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--ec0c1d7a-7d0a-4df5-bda2-e0e470408f63",
"name": "Trellix",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A cybersecurity company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--820d45b6-ab79-4ad8-833e-625b97e265fd",
"name": "Pwn2Own",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "A cybersecurity competition and conference",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--a08d4c29-b21a-4dd7-a9a1-4886ea585e24",
"name": "Cognito",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A company or product name.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--044fde07-eb6c-4c20-922f-0b39f08e3011",
"name": "Gartner",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A research and advisory company.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--fc9b3eeb-bb7f-4624-95dd-75bf425ded59",
"name": "Twitter",
"identity_class": "system",
"labels": [
"identity"
],
"description": "A social media platform",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--161fc746-cd49-4615-ab48-81a93a1b16b4",
"name": "GitHub",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "GitHub is a company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--2daf3eee-ee2d-4a01-b724-90e3ce3a3f4f",
"name": "Thales",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Multinational company that provides cybersecurity solutions",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.220Z",
"modified": "2026-05-08T14:57:19.220Z",
"confidence": 95,
"type": "identity",
"id": "identity--4f7dd0b7-e698-4315-842d-423f0e087543",
"name": "Fedora",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "A Linux distribution and operating system.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--2e53c328-2ca3-45f0-83f3-fa57d820b563",
"name": "PAN-OS",
"identity_class": "unknown",
"labels": [
"identity"
],
"description": "A network security operating system developed by Palo Alto Networks",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--ff7fd6dd-7fc3-4198-bbee-c9e3f269a5a5",
"name": "SpaceX",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A private aerospace manufacturer and space transport services company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--6b22e13c-2eb9-45bc-a13e-e9ea98dff190",
"name": "Seceon",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "Cybersecurity company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--cf099ab9-0bef-4468-b24e-ac6319addc2e",
"name": "Replit",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "A specific company or organization, possibly related to software development.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--681f4631-bbe3-4600-ac06-5613e29c9cbd",
"name": "Auth0",
"identity_class": "organization",
"labels": [
"identity"
],
"description": "An authentication platform company",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--f9f67fe7-735c-4107-8f6e-5dc3164bc5ce",
"name": "CISOs",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "Chief Information Security Officers",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "identity",
"id": "identity--a343afe6-1d0e-400a-8a27-09ce11198c99",
"name": "Siauw",
"identity_class": "individual",
"labels": [
"identity"
],
"description": "An individual's name or surname.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--3def0baa-88d9-4bec-85e7-2c5cecf77a3e",
"name": "Semantic Kernel CVE-2026-26030",
"description": "A specific vulnerability in the Semantic Kernel with a CVE identifier.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 85,
"type": "vulnerability",
"id": "vulnerability--9b3f5a1e-a7a9-4b98-b171-2dee5840f329",
"name": "Palo Alto Zero-Day",
"description": "A zero-day vulnerability in Palo Alto products.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--e3e71ecc-fec4-4862-a001-4c33159df6be",
"name": "CVE-2026-25592",
"description": "Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem has been fixed in Microsoft.SemanticKernel.Core version 1.71.0. As a mitigation, users can create a Function Invocation Filter which checks the arguments being passed to any calls to DownloadFileAsync or UploadFileAsync and e. CVSS Score: 9.9 (CRITICAL). EPSS: 0.1% exploitation probability",
"x_cvss_score": 9.9,
"x_cvss_severity": "CRITICAL",
"x_kev_status": false,
"x_epss_score": 0.00067,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-25592",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25592"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-25592",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25592"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--c40fdbce-958f-4e64-9ab1-21854ee00947",
"name": "CVE-2026-31431",
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings. Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.. CVSS Score: 7.8 (HIGH). CISA KEV: Active exploitation confirmed. EPSS: 3.9% exploitation probability",
"x_cvss_score": 7.8,
"x_cvss_severity": "HIGH",
"x_kev_status": true,
"x_epss_score": 0.03912,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-31431",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-31431"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-31431",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31431"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--64f1084c-d47d-40a1-99df-ad6c1c6f5608",
"name": "CVE-2026-23918",
"description": "Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.\n\nThis issue affects Apache HTTP Server: 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.. CVSS Score: 8.8 (HIGH). EPSS: 0.1% exploitation probability",
"x_cvss_score": 8.8,
"x_cvss_severity": "HIGH",
"x_kev_status": false,
"x_epss_score": 0.00061,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-23918",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23918"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-23918",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23918"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--8d7c4a88-ce42-4945-8ec6-c3457d00fd16",
"name": "CVE-2025-68670",
"description": "xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execut. CVSS Score: 9.1 (CRITICAL). EPSS: 0.1% exploitation probability",
"x_cvss_score": 9.1,
"x_cvss_severity": "CRITICAL",
"x_kev_status": false,
"x_epss_score": 0.00123,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2025-68670",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68670"
},
{
"source_name": "nvd",
"external_id": "CVE-2025-68670",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68670"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--40b77602-9d0f-436c-9f38-b1b3836a002e",
"name": "CVE-2022-27666",
"description": "A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.. CVSS Score: 7.8 (HIGH). EPSS: 0.8% exploitation probability",
"x_cvss_score": 7.8,
"x_cvss_severity": "HIGH",
"x_kev_status": false,
"x_epss_score": 0.00797,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2022-27666",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27666"
},
{
"source_name": "nvd",
"external_id": "CVE-2022-27666",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27666"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--68788c3d-bce1-4d03-95c1-e37006ca5e61",
"name": "CVE-2026-43284",
"description": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: avoid in-place decrypt on shared skb frags\n\nMSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP\nmarks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),\nso later paths that may modify packet data can first make a private\ncopy. The IPv4/IPv6 datagram append paths did not set this flag when\nsplicing pages into UDP skbs.\n\nThat leaves an ESP-in-UDP packet made from shared pipe pages looking\n. CVSS Score: 7.8 (HIGH). EPSS: 0.0% exploitation probability",
"x_cvss_score": 7.8,
"x_cvss_severity": "HIGH",
"x_kev_status": false,
"x_epss_score": 0.00014,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-43284",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43284"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-43284",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43284"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--b749c82d-36dd-45b2-bb6a-3af87c2516ab",
"name": "CVE-2026-6973",
"description": "An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.. CVSS Score: 7.2 (HIGH). CISA KEV: Active exploitation confirmed. EPSS: 5.0% exploitation probability",
"x_cvss_score": 7.2,
"x_cvss_severity": "HIGH",
"x_kev_status": true,
"x_epss_score": 0.05009,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-6973",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6973"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-6973",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6973"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"name": "CVE-2026-0300",
"description": "A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. \n\nThe risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by r. CVSS Score: 9.8 (CRITICAL). CISA KEV: Active exploitation confirmed. EPSS: 4.7% exploitation probability",
"x_cvss_score": 9.8,
"x_cvss_severity": "CRITICAL",
"x_kev_status": true,
"x_epss_score": 0.0465,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-0300",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0300"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-0300",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0300"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--202ddc5d-7c58-4a53-b475-4167098c2e61",
"name": "CVE-2026-3854",
"description": "An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers. Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fi. CVSS Score: 8.8 (HIGH). EPSS: 0.3% exploitation probability",
"x_cvss_score": 8.8,
"x_cvss_severity": "HIGH",
"x_kev_status": false,
"x_epss_score": 0.00303,
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2026-3854",
"url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3854"
},
{
"source_name": "nvd",
"external_id": "CVE-2026-3854",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3854"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 80,
"type": "vulnerability",
"id": "vulnerability--d320478d-ee2b-4f15-9b93-823cfc797a94",
"name": "ClaudeBleed",
"description": "A specific security flaw or vulnerability",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "vulnerability",
"id": "vulnerability--0a7cd6eb-6e7d-4471-a46e-60fda6a10285",
"name": "Dirty Frag",
"description": "A local privilege escalation vulnerability in the Linux kernel.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"vulnerability"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 92,
"type": "threat-actor",
"id": "threat-actor--23532327-1fb0-44d5-9abd-363bfb924874",
"name": "Courts Sentence Karakurt",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "A threat actor group known as Karakurt",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "threat-actor",
"id": "threat-actor--1c24883b-5440-48be-89b4-b0c9d2b0646b",
"name": "ShinyHunters",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "A threat actor group.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "threat-actor",
"id": "threat-actor--5ea0d2af-c73f-44b7-9596-ae5f9a3ff7f3",
"name": "RansomHouse",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "RansomHouse is a threat actor group.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "threat-actor",
"id": "threat-actor--edfc3090-ec61-44a7-8e38-e5c05bfd4909",
"name": "MuddyWater",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "A threat actor group known for conducting cyber espionage activities.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 92,
"type": "threat-actor",
"id": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"name": "TeamPCP",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "A threat actor group associated with the PCPJack malware.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "threat-actor",
"id": "threat-actor--3de981ea-bc76-46c4-86f0-6159ae1637cc",
"name": "APT41",
"threat_actor_types": [
"hacker"
],
"labels": [
"threat-actor"
],
"description": "A specific threat actor group or intrusion set.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.222Z",
"modified": "2026-05-08T14:57:19.222Z",
"confidence": 95,
"type": "malware",
"id": "malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"name": "Karakurt Ransomware",
"is_family": true,
"malware_types": [
"ransomware"
],
"labels": [
"malicious-activity"
],
"description": "Karakurt Ransomware is a specific malware family.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.223Z",
"modified": "2026-05-08T14:57:19.223Z",
"confidence": 95,
"type": "malware",
"id": "malware--edf00ddd-9f52-489e-be39-c330ca2a6690",
"name": "Chaos ransomware",
"is_family": true,
"malware_types": [
"ransomware"
],
"labels": [
"malicious-activity"
],
"description": "A specific ransomware family known as Chaos",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.223Z",
"modified": "2026-05-08T14:57:19.223Z",
"confidence": 82,
"type": "malware",
"id": "malware--536cf582-37c8-439a-aa79-38b89bc7c52d",
"name": "HorsePecker",
"is_family": true,
"malware_types": [
"trojan"
],
"labels": [
"malicious-activity"
],
"description": "HorsePecker is a malware family known for its malicious activities.",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.223Z",
"modified": "2026-05-08T14:57:19.223Z",
"confidence": 95,
"type": "attack-pattern",
"id": "attack-pattern--d5f68c3e-3583-497a-8fd3-6fe32b38bf5f",
"name": "T1059",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "unknown"
}
],
"description": "T1059 is a MITRE ATT&CK technique for Command and Scripting Interpreter",
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": []
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:19.223Z",
"modified": "2026-05-08T14:57:19.223Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--e8d516a9-a107-4c4b-806f-bc9c612eef18",
"name": "Adversary-in-the-Middle",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "credential-access"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "collection"
}
],
"x_mitre_id": "T1557",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1557/",
"external_id": "T1557"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--5aa11eb6-804f-4920-a45f-1fae275ef314",
"name": "Remote Services",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "lateral-movement"
}
],
"x_mitre_id": "T1021",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1021/",
"external_id": "T1021"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--2c821981-fda2-4cb8-926c-6edd4905d65c",
"name": "Lateral Tool Transfer",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "lateral-movement"
}
],
"x_mitre_id": "T1570",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1570/",
"external_id": "T1570"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--01df90e4-619d-4268-90c9-6e2aa84079d9",
"name": "PowerShell",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
}
],
"x_mitre_id": "T1059.001",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1059/001/",
"external_id": "T1059.001"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--771ed4e5-6dde-43a8-9c72-d006b0c83e3d",
"name": "Command and Scripting Interpreter",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
}
],
"x_mitre_id": "T1059",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1059/",
"external_id": "T1059"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--e5974f70-5745-450a-908a-6483ad9c4678",
"name": "Exploitation for Client Execution",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
}
],
"x_mitre_id": "T1203",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1203/",
"external_id": "T1203"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--d5229cf6-f11b-41bc-8aca-0df713047400",
"name": "Boot or Logon Autostart Execution",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1547",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1547/",
"external_id": "T1547"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--9ba6495b-e273-4e8d-a4ce-dbcd56ec33f2",
"name": "Scheduled Task/Job",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1053",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1053/",
"external_id": "T1053"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--280ebd89-59bc-4ae2-a9db-1c01a56e50dc",
"name": "Exploit Public-Facing Application",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1190",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1190/",
"external_id": "T1190"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--13fc9cbe-9444-4eba-872b-a44565ae3ab7",
"name": "Supply Chain Compromise",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1195",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1195/",
"external_id": "T1195"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--06cf8802-38e4-4421-a699-33a0bae74d96",
"name": "System Information Discovery",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "discovery"
}
],
"x_mitre_id": "T1082",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1082/",
"external_id": "T1082"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--2e52cc86-c2ef-43d7-9f1e-2fc59c4845ee",
"name": "File and Directory Discovery",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "discovery"
}
],
"x_mitre_id": "T1083",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1083/",
"external_id": "T1083"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--943edc6f-c0f9-48f1-b8d4-4666aa0abae1",
"name": "Process Discovery",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "discovery"
}
],
"x_mitre_id": "T1057",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1057/",
"external_id": "T1057"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--f33f5834-6a9a-4727-88a5-9d35eeba1cff",
"name": "Abuse Elevation Control Mechanism",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1548",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1548/",
"external_id": "T1548"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--2d26e3d0-4bbf-44c3-aa9e-5aeab4937638",
"name": "Access Token Manipulation",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "stealth"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1134",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1134/",
"external_id": "T1134"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--2da268b5-7100-4dbc-b23b-d5deafdf268c",
"name": "Spearphishing Attachment",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1566.001",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1566/001/",
"external_id": "T1566.001"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--baad7d00-8591-4c49-8f48-fabb6a35df65",
"name": "Spearphishing Link",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1566.002",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1566/002/",
"external_id": "T1566.002"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--c627c29c-1385-4d76-9046-9c2db86dab11",
"name": "Spearphishing via Service",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1566.003",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1566/003/",
"external_id": "T1566.003"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--ce39e6f2-b20f-421e-83e1-242a773e1927",
"name": "Create or Modify System Process",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1543",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1543/",
"external_id": "T1543"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--b0e5285c-e953-4745-a8d6-56e03a076a5c",
"name": "Valid Accounts",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "stealth"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "initial-access"
}
],
"x_mitre_id": "T1078",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1078/",
"external_id": "T1078"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--4a2578d4-fdf6-48d3-b66a-93c681e1e21e",
"name": "Application Layer Protocol",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "command-and-control"
}
],
"x_mitre_id": "T1071",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1071/",
"external_id": "T1071"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 90,
"type": "attack-pattern",
"id": "attack-pattern--68a5c7b8-09b4-49b1-8149-bc23ed0260c9",
"name": "Non-Application Layer Protocol",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "command-and-control"
}
],
"x_mitre_id": "T1095",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1095/",
"external_id": "T1095"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.280Z",
"modified": "2026-05-08T14:57:20.280Z",
"confidence": 85,
"type": "attack-pattern",
"id": "attack-pattern--298cad89-6cfc-4a7e-a231-76b81f275a3a",
"name": "Query Public AI Services",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "reconnaissance"
}
],
"x_mitre_id": "T1682",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1682/",
"external_id": "T1682"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 85,
"type": "attack-pattern",
"id": "attack-pattern--181753c8-21ea-4cce-a21e-fc6cfbaee56b",
"name": "Kernel Modules and Extensions",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1547.006",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1547/006/",
"external_id": "T1547.006"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 85,
"type": "attack-pattern",
"id": "attack-pattern--0ec57ff0-0257-4287-888c-8f20c7e08c6b",
"name": "Cloud Secrets Management Stores",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "credential-access"
}
],
"x_mitre_id": "T1555.006",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1555/006/",
"external_id": "T1555.006"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 82,
"type": "attack-pattern",
"id": "attack-pattern--3cfe33ad-33e7-4370-a083-fd1b2c9457ab",
"name": "Pluggable Authentication Modules",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "defense-impairment"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "credential-access"
}
],
"x_mitre_id": "T1556.003",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1556/003/",
"external_id": "T1556.003"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 82,
"type": "attack-pattern",
"id": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"name": "Vulnerabilities",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "resource-development"
}
],
"x_mitre_id": "T1588.006",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1588/006/",
"external_id": "T1588.006"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 72,
"type": "attack-pattern",
"id": "attack-pattern--88428b3c-f02f-45b8-a38a-0541b2287509",
"name": "LSA Secrets",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "credential-access"
}
],
"x_mitre_id": "T1003.004",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1003/004/",
"external_id": "T1003.004"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--d2a77ce3-d278-4f77-97f0-227b744a33d3",
"name": "Archive via Utility",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "collection"
}
],
"x_mitre_id": "T1560.001",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1560/001/",
"external_id": "T1560.001"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--a6ff86fe-f269-42e5-9428-ab17d04e30e2",
"name": "Screen Capture",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "collection"
}
],
"x_mitre_id": "T1113",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1113/",
"external_id": "T1113"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--27b36b6d-ae90-4767-b07a-563ecef589ea",
"name": "Scheduled Task",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "execution"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1053.005",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1053/005/",
"external_id": "T1053.005"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--ed3369e1-8515-458a-99e3-cb9283fb73d1",
"name": "Socket Filters",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "stealth"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "command-and-control"
}
],
"x_mitre_id": "T1205.002",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1205/002/",
"external_id": "T1205.002"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 70,
"type": "attack-pattern",
"id": "attack-pattern--5cf0f3fb-3459-4a3d-ad3c-4700efcfecd8",
"name": "Boot or Logon Initialization Scripts",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1037",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1037/",
"external_id": "T1037"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 68,
"type": "attack-pattern",
"id": "attack-pattern--cfdf109a-1036-48eb-a479-ee1f681a1c11",
"name": "Login Items",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
},
{
"kill_chain_name": "mitre-attack",
"phase_name": "privilege-escalation"
}
],
"x_mitre_id": "T1547.015",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1547/015/",
"external_id": "T1547.015"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"spec_version": "2.1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"confidence": 65,
"type": "attack-pattern",
"id": "attack-pattern--172f3845-7870-4c1c-80bd-251e10ce9f1e",
"name": "Browser Extensions",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "persistence"
}
],
"x_mitre_id": "T1176.001",
"external_references": [
{
"source_name": "MITRE ATT&CK",
"url": "https://attack.mitre.org/techniques/T1176/001/",
"external_id": "T1176.001"
}
],
"object_marking_refs": [
"marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
],
"labels": [
"mitre-attack"
]
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--48f84fe3-4b3f-4bf7-9599-f1e7cbc6b34f",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--1d62e7d4-1f43-46f6-ba79-9ab52c2a62f2",
"target_ref": "identity--7a9e545a-d22b-4107-8f1d-ca070a62a509",
"confidence": 85,
"description": "Author: Victor Lungu | Published: April 29, 2026 Learn to integrate responsible AI concepts into Amazon Bedrock applications, including abuse detection, Amazon CloudWatch monitoring, Bedrock Guardrails configuration, and the abuse response process.",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e4ff26a5-876b-445b-a6a7-7e7cf3c46829",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "identity--2e53c328-2ca3-45f0-83f3-fa57d820b563",
"confidence": 85,
"description": "\\n\\n\\n\\n Palo Alto Networks warned that suspected state-sponsored hackers have been exploiting the critical PAN-OS zero-day CVE-2026-0300 for nearly a month.",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--43ae0778-99c3-482f-90d8-18adb0a2ee06",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"confidence": 85,
"description": "\\n\\n\\n\\n Palo Alto Networks warned that suspected state-sponsored hackers have been exploiting the critical PAN-OS zero-day CVE-2026-0300 for nearly a month.",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6e9b06a4-8037-405f-8f61-60d8e4e66d36",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "threat-actor--edfc3090-ec61-44a7-8e38-e5c05bfd4909",
"target_ref": "malware--edf00ddd-9f52-489e-be39-c330ca2a6690",
"confidence": 85,
"description": "[ARTICLE_BOUNDARY]\n\nIncident responders from cybersecurity firm Rapid7 published a report about a recent intrusion that initially appeared to be a Chaos ransomware attack but was later discovered to be an attack attributed to MuddyWater, an Iranian APT group tied to the country’s Ministry of Intelligence and Security (MOIS).",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--02c2ad37-f72c-4c58-90a2-90fad9961b3b",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--60728444-0fa0-4364-b9e8-7b13a2a0a39e",
"target_ref": "vulnerability--b749c82d-36dd-45b2-bb6a-3af87c2516ab",
"confidence": 85,
"description": "None, 'base': '', 'value': ' \\n The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog \\n\\n\\n\\n The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-6973 (CVSS score of 7.1), to its Known Exploited Vulnerabilities (KEV) catalog .",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--32e4c09f-927a-43b8-b494-bc3ae5948986",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "vulnerability--b749c82d-36dd-45b2-bb6a-3af87c2516ab",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 85,
"description": "None, 'base': '', 'value': ' \\n The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog \\n\\n\\n\\n The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-6973 (CVSS score of 7.1), to its Known Exploited Vulnerabilities (KEV) catalog .",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--912142ef-7ddc-4d3d-87dd-c099552eab96",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--2d369946-57f6-4cc6-a1d3-6188c068b6af",
"target_ref": "identity--04f59a5c-4fe5-4f13-ad37-7123f37c8450",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--9430d612-3ae1-4bed-b2f0-d4c9def50df2",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--2d369946-57f6-4cc6-a1d3-6188c068b6af",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8cfa4fa6-ddd4-4189-aae8-ba6cc0894bb5",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--2d369946-57f6-4cc6-a1d3-6188c068b6af",
"target_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ac8cc184-6ea8-46c9-9801-6632851ab8d1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "identity--04f59a5c-4fe5-4f13-ad37-7123f37c8450",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--0ebfe468-7418-4ac1-b5b2-09d48da2bfb4",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7bd08db7-a16e-4a56-866b-61fa06fd74f9",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--38d6b61d-522c-42a0-80bb-14623a623319",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--604c2866-393e-4bcc-aa44-c53d34db8c6e",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--fd1e3790-7e3a-48a3-8684-16f17330c96f",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c85ff316-8872-439a-ae7f-2093e90f8197",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--04f59a5c-4fe5-4f13-ad37-7123f37c8450",
"target_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--061d6410-351f-42bc-a889-7899955d4a6a",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--04f59a5c-4fe5-4f13-ad37-7123f37c8450",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b51a4ce3-ef49-49c0-ba21-cf7c71b07129",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "uses",
"source_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"target_ref": "identity--1edb34d6-de9f-48f1-a5f2-49ef98c18a90",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8c8a6706-6eaa-4015-900c-016ebcd085c1",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c51abcce-894a-4d37-91fe-e827135d9b6c",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "drops",
"source_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7a4b80bb-544e-4208-8b9b-e3f99b98f3c7",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"target_ref": "identity--2e53c328-2ca3-45f0-83f3-fa57d820b563",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ba8b55f9-a543-49f7-ac7d-4985b77bef27",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"target_ref": "vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--cb2d2062-e545-465f-8e7c-b113444876e3",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "targets",
"source_ref": "threat-actor--23532327-1fb0-44d5-9abd-363bfb924874",
"target_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ee36c8d6-b1f2-4cbe-815c-0391a0ddc737",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "targets",
"source_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"target_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--10912c64-4fe0-476e-acb4-392c8a3a7cfb",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--758080f3-e58d-4a25-9f17-619337e93a95",
"target_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--58a52156-0510-4a3f-9e07-af57145f042f",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"target_ref": "identity--2e53c328-2ca3-45f0-83f3-fa57d820b563",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c8bd7b28-1313-4380-bdb4-b3fbfe07a490",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "uses",
"source_ref": "threat-actor--23532327-1fb0-44d5-9abd-363bfb924874",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7ee4d53e-9e2c-47bb-9e44-0bacb52f3c32",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"target_ref": "threat-actor--23532327-1fb0-44d5-9abd-363bfb924874",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--87627ab4-4fa7-47a2-98df-5398ca88fc1b",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"target_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--f564068c-ff66-422b-add0-55876d8934e0",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "targets",
"source_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8eb154c5-6e40-4374-835d-e99350e9d30c",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "drops",
"source_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"target_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--aa7bd7b7-fd21-4a1d-b445-6f52b968e38e",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "targets",
"source_ref": "malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"target_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3c0be556-f5af-4668-b090-858b9556a259",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "identity--438e87ff-8de4-4243-bbe3-fcb5a59b8fe4",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5748d798-706d-48cb-a045-e6408cb3389e",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "targets",
"source_ref": "malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"target_ref": "identity--2e53c328-2ca3-45f0-83f3-fa57d820b563",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4abe7d34-ec73-490c-ab5e-9a3a07b6bdb3",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"target_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--255248f7-a611-4144-b648-b57d6583b1f6",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "targets",
"source_ref": "malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"target_ref": "vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--77cf90d1-ebf5-43d4-a2e8-0314ac133e1c",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "vulnerability--44b6cfb1-604e-4443-b372-93df0a88bdbe",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--dae3027b-68fa-4d39-b1c2-04837c6c4294",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "uses",
"source_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"target_ref": "malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' The Good | Courts Sentence Karakurt Ransomware Negotiator & Two DPRK IT Worker Scheme Facilitators \\n Federal authorities have successfully secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national extradited to the U.S. for his critical role in the Karakurt extortion syndicate . \\n Operating as a specialized “cold case” negotiator, Zolotarjovs ( aka Sforza_cesarini) systematically targeted victims who had previously stopped communications with the extortion group to avoid paying the ransom . To coerce the ransom payments, he focused on analyzing stolen personal data and information about the target companies to exert intense psychological pressure on the victims. In some cases, Zolotarjovs resorted to leveraging sensitive health information, including children’s medical records, to force the victim to complete the ransom payment. \\n Source: Dayton247now \\n The broader Karakurt operation has extorted an estimated $56 million from dozens of compromised organizations. As the first Karakurt member to face federal prosecution, Zolotarjovs’s sentencing is a hard-won milestone in ongoing efforts to dismantle international cyber-extortion rings. \\n In a separate victory, U.S. prosecutors sentenced two American nationals to 18 months in prison each for operating extensive laptop farms that actively facilitated North Korean cyber infiltration . \\n Matthew Knoot and Erick Prince were prosecuted for helping DPRK-based IT workers secure remote employment at almost 70 U.S. companies by exploiting stolen identities . The pair received company-issued laptops and deployed unauthorized remote desktop software, allowing the North Korean workers to seamlessly masquerade as legitimate domestic employees. \\n The FBI continues to warn about the thousands of North Korean IT workers working to infiltrate U.S. firms to steal intellectual property, implant malware, and siphon funds to the heavily sanctioned regime. \\n The Bad | PCPJack Worm Evicts TeamPCP, Steals Cloud Credentials at Scale \\n SentinelLABS researchers this week exposed PCPJack , a sophisticated credential theft framework and cloud worm that targets public infrastructure to harvest sensitive data . \\n Unlike other known cloud hacktools, the toolset actively hunts, evicts, and systematically deletes artifacts associated with TeamPCP , a threat group responsible for multiple high-profile supply chain intrusions earlier this year. \\n The multi-stage infection chain begins with a shell script called bootstrap.sh , which establishes persistence and selectively downloads specialized Python modules from an attacker-controlled Amazon S3 bucket. The malware extracts a massive array of sensitive credentials , including cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise productivity application tokens, and cryptocurrency wallets. Unlike typical cloud-focused threat campaigns, PCPJack does not deploy cryptomining payloads on victims. \\n Beginning of bootstrap.sh, the dropper script \\n To achieve lateral movement , the framework exploits a number of web vulnerabilities, including severe Next.js and WordPress flaws, while aggressively scanning for poorly secured Docker, Redis, RayML, and MongoDB instances. Stolen data is then encrypted before being exfiltrated via attacker-controlled Telegram channels. \\n Security teams are advised to strictly enforce multi-factor authentication on service accounts, restrict Kubernetes access scopes, use an enterprise-wide vault, and thoroughly secure all exposed cloud management interfaces. \\n The Ugly | Palo Alto Warns of Critical Flaw in PAN-OS Enabling Remote Code Execution \\n Palo Alto Networks customers were issued an urgent warning this week regarding a critical-level, unpatched zero-day vulnerability currently being exploited in the wild . \\n Tracked as CVE-2026-0300 , the buffer overflow flaw directly impacts the PAN-OS User-ID Authentication Portal ( aka the Captive Portal), enabling unauthenticated attackers to execute arbitrary code with root privileges using specially-crafted packets. \\n With a CVSS score of 9.3, the vulnerability presents an immediate risk to enterprise networks. Threat watchdog Shadowserver has currently identified over 5,000 vulnerable firewalls exposed online, primarily concentrated across Asia and North America. \\n Source: ShadowServers (current as of this writing) \\n This actively exploited vulnerability adds to the growing pattern of targeting edge infrastructure . PAN-OS has a well-documented history of severe zero-days, and with 90% of Fortune 10 companies and many major U.S. banks depending on it, the exposure is significant. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, setting mandatory remediation deadlines for federal civilian agencies. \\n With a patch not expected until mid-May, Palo Alto is urging administrators to secure affected environments immediate",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--94817487-b376-49c6-bfd1-c14d51522291",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "vulnerability--3def0baa-88d9-4bec-85e7-2c5cecf77a3e",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' \\n\\t \\n\\t\\t In this article \\n\\t\\t \\n\\n\\t\\t \\n\\t\\t\\t \\n\\t\\t \\n\\t \\n\\t \\n\\t\\t \\n\\t\\t\\t A representative case study: Semantic Kernel CVE-2026-26030: In-Memory Vector Store CVE-2026-25592: Arbitrary file write through SessionsPythonPlugin The vulnerability Attack chain overview Defending the agentic edge Not bugs, but developed by design CTF challenge: Attack your own agent Learn more \\t\\t \\n\\t \\n\\t \\n \\n\\n\\n\\n AI agents have fundamentally changed the threat model of AI model-based applications. By equipping these models with plugins (also called tools), your agents no longer just generate text; they now read files, search connected databases, run scripts, and perform other tasks to actively operate on your network. \\n\\n\\n\\n Because of this, vulnerabilities in the AI layer are no longer just a content issue and are an execution risk. If an attacker can control the parameters passed into these plugins via prompt injection, the agent may be driven to perform actions beyond its intended use. \\n\\n\\n\\n The AI model itself isn’t the issue as it’s behaving exactly as designed by parsing language into tool schemas. The vulnerability lies in how the framework and tools trust the parsed data. \\n\\n\\n\\n To build powerful applications, developers rely heavily on frameworks like Semantic Kernel, LangChain, and CrewAI. These frameworks act as the operating system for AI agents, abstracting away complex model orchestration. But this convenience comes with a hidden cost: because these frameworks act as a ubiquitous foundational layer, a single vulnerability in how they map AI model outputs to system tools carries systemic risk. \\n\\n\\n\\n As part of our mission to make AI systems more secure and eliminate new class of vulnerabilities, we’re launching a research series focused on identifying vulnerabilities in popular AI agent frameworks. Through responsible disclosure, we work with maintainers to ensure issues are addressed before sharing our findings with the community. \\n\\n\\n\\n In this post, we share details on the vulnerabilities we discovered in Microsoft’s Semantic Kernel, along with the steps we took to address them and interactive way to try it yourself. Stay tuned for upcoming blogs where we’ll dive into similar vulnerabilities found in frameworks beyond the Microsoft ecosystem. \\n\\n\\n\\n Background \\n\\n\\n\\n We discovered a vulnerable path in Microsoft Semantic Kernel that could turn prompt injection into host-level remote code execution (RCE). \\n\\n\\n\\n A single prompt was enough to launch calc.exe on the device running our AI agent, with no browser exploit, malicious attachment, or memory corruption bug needed. The agent simply did what it was designed to do: interpret natural language, choose a tool, and pass parameters into code. \\n\\n\\n Figure 1. Illustration of CVE-2026-26030 exploitation using a local model. \\n\\n\\n\\n This scenario is the real security story behind modern AI agents. Once an AI model is wired to tools, prompt injection draws a thin line between being just a content security problem and becoming a code execution primitive. In this post in our research series on AI agent framework security, we show how two vulnerabilities in Semantic Kernel could allow attackers to cross that line, and what customers should do to assess exposure, patch affected agents, and investigate whether exploitation may already have occurred. \\n\\n\\n\\n A representative case study: Semantic Kernel \\n\\n\\n\\n Semantic Kernel is Microsoft’s open-source framework for building AI agents and integrating AI models into applications. With over 27,000 stars on GitHub, it provides essential abstractions for orchestrating AI models, managing plugins, and chaining workflows. \\n\\n\\n\\n During our security research into the Semantic Kernel framework, we identified and disclosed two critical vulnerabilities: CVE-2026-25592 and CVE-2026-26030. These flaws, which have since been fixed, could allow an attacker to achieve unauthorized code execution by leveraging injection attacks specifically targeted at agents built within the framework. \\n\\n\\n\\n In the following sections, we break down the mechanics of these vulnerabilities in detail and provide actionable guidance on how to harden your agents against similar exploitation. \\n\\n\\n\\n CVE-2026-26030: In-Memory Vector Store \\n\\n\\n\\n Exploitation of this vulnerability requires two conditions: \\n\\n\\n\\n \\n The attacker must have a prompt injection vector, allowing influence over the agent’s inputs \\n\\n\\n\\n The targeted agent must have the Search Plugin backed by In-Memory Vector Store functionality using the default configuration \\n \\n\\n\\n\\n When both these two conditions are met, the vulnerability enables an attacker to achieve RCE from a prompt. \\n\\n\\n\\n To demonstrate how this vulnerability could be exploited, we built a “hotel finder” agent using Semantic Kernel. First, we created an In Memory Vector collection to store the hotels’",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--2d0d573f-7b16-4cd6-9d90-19152163c480",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "related-to",
"source_ref": "vulnerability--e3e71ecc-fec4-4862-a001-4c33159df6be",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 85,
"description": "{'type': 'text/html', 'language': None, 'base': '', 'value': ' \\n\\t \\n\\t\\t In this article \\n\\t\\t \\n\\n\\t\\t \\n\\t\\t\\t \\n\\t\\t \\n\\t \\n\\t \\n\\t\\t \\n\\t\\t\\t A representative case study: Semantic Kernel CVE-2026-26030: In-Memory Vector Store CVE-2026-25592: Arbitrary file write through SessionsPythonPlugin The vulnerability Attack chain overview Defending the agentic edge Not bugs, but developed by design CTF challenge: Attack your own agent Learn more \\t\\t \\n\\t \\n\\t \\n \\n\\n\\n\\n AI agents have fundamentally changed the threat model of AI model-based applications. By equipping these models with plugins (also called tools), your agents no longer just generate text; they now read files, search connected databases, run scripts, and perform other tasks to actively operate on your network. \\n\\n\\n\\n Because of this, vulnerabilities in the AI layer are no longer just a content issue and are an execution risk. If an attacker can control the parameters passed into these plugins via prompt injection, the agent may be driven to perform actions beyond its intended use. \\n\\n\\n\\n The AI model itself isn’t the issue as it’s behaving exactly as designed by parsing language into tool schemas. The vulnerability lies in how the framework and tools trust the parsed data. \\n\\n\\n\\n To build powerful applications, developers rely heavily on frameworks like Semantic Kernel, LangChain, and CrewAI. These frameworks act as the operating system for AI agents, abstracting away complex model orchestration. But this convenience comes with a hidden cost: because these frameworks act as a ubiquitous foundational layer, a single vulnerability in how they map AI model outputs to system tools carries systemic risk. \\n\\n\\n\\n As part of our mission to make AI systems more secure and eliminate new class of vulnerabilities, we’re launching a research series focused on identifying vulnerabilities in popular AI agent frameworks. Through responsible disclosure, we work with maintainers to ensure issues are addressed before sharing our findings with the community. \\n\\n\\n\\n In this post, we share details on the vulnerabilities we discovered in Microsoft’s Semantic Kernel, along with the steps we took to address them and interactive way to try it yourself. Stay tuned for upcoming blogs where we’ll dive into similar vulnerabilities found in frameworks beyond the Microsoft ecosystem. \\n\\n\\n\\n Background \\n\\n\\n\\n We discovered a vulnerable path in Microsoft Semantic Kernel that could turn prompt injection into host-level remote code execution (RCE). \\n\\n\\n\\n A single prompt was enough to launch calc.exe on the device running our AI agent, with no browser exploit, malicious attachment, or memory corruption bug needed. The agent simply did what it was designed to do: interpret natural language, choose a tool, and pass parameters into code. \\n\\n\\n Figure 1. Illustration of CVE-2026-26030 exploitation using a local model. \\n\\n\\n\\n This scenario is the real security story behind modern AI agents. Once an AI model is wired to tools, prompt injection draws a thin line between being just a content security problem and becoming a code execution primitive. In this post in our research series on AI agent framework security, we show how two vulnerabilities in Semantic Kernel could allow attackers to cross that line, and what customers should do to assess exposure, patch affected agents, and investigate whether exploitation may already have occurred. \\n\\n\\n\\n A representative case study: Semantic Kernel \\n\\n\\n\\n Semantic Kernel is Microsoft’s open-source framework for building AI agents and integrating AI models into applications. With over 27,000 stars on GitHub, it provides essential abstractions for orchestrating AI models, managing plugins, and chaining workflows. \\n\\n\\n\\n During our security research into the Semantic Kernel framework, we identified and disclosed two critical vulnerabilities: CVE-2026-25592 and CVE-2026-26030. These flaws, which have since been fixed, could allow an attacker to achieve unauthorized code execution by leveraging injection attacks specifically targeted at agents built within the framework. \\n\\n\\n\\n In the following sections, we break down the mechanics of these vulnerabilities in detail and provide actionable guidance on how to harden your agents against similar exploitation. \\n\\n\\n\\n CVE-2026-26030: In-Memory Vector Store \\n\\n\\n\\n Exploitation of this vulnerability requires two conditions: \\n\\n\\n\\n \\n The attacker must have a prompt injection vector, allowing influence over the agent’s inputs \\n\\n\\n\\n The targeted agent must have the Search Plugin backed by In-Memory Vector Store functionality using the default configuration \\n \\n\\n\\n\\n When both these two conditions are met, the vulnerability enables an attacker to achieve RCE from a prompt. \\n\\n\\n\\n To demonstrate how this vulnerability could be exploited, we built a “hotel finder” agent using Semantic Kernel. First, we created an In Memory Vector collection to store the hotels’",
"x_validation_method": "three-llm-consensus"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ad0ac28a-9557-4e95-84a3-de1da11739cb",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "uses",
"source_ref": "threat-actor--23532327-1fb0-44d5-9abd-363bfb924874",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 75,
"description": "Article co-occurrence: Courts Sentence Karakurt and Vulnerabilities (T1588.006)",
"x_validation_method": "mitre-article-cooccurrence"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8309b882-49c7-4f20-815d-01aab312d61a",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "uses",
"source_ref": "threat-actor--ab656e4c-50e9-406b-af1d-c8bac482476f",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 75,
"description": "Article co-occurrence: TeamPCP and Vulnerabilities (T1588.006)",
"x_validation_method": "mitre-article-cooccurrence"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b93a5ed3-1d73-44e8-8e25-81d7a7b8146d",
"created": "2026-05-08T14:57:20.281Z",
"modified": "2026-05-08T14:57:20.281Z",
"relationship_type": "uses",
"source_ref": "malware--ec398fe2-550f-4e05-aa8b-067dc494bb4c",
"target_ref": "attack-pattern--0b9d5f9a-d372-4a5d-8f9f-e62f6d5e8719",
"confidence": 70,
"description": "Article co-occurrence: Karakurt Ransomware and Vulnerabilities (T1588.006)",
"x_validation_method": "mitre-article-cooccurrence"
},
{
"type": "ipv4-addr",
"spec_version": "2.1",
"id": "ipv4-addr--fcf9628c-46ee-4edd-8552-8e890e71f271",
"value": "12.7.0.1"
},
{
"type": "ipv4-addr",
"spec_version": "2.1",
"id": "ipv4-addr--398631a3-2e68-4b99-9fda-54f70ba0e582",
"value": "12.8.0.1"
},
{
"type": "ipv4-addr",
"spec_version": "2.1",
"id": "ipv4-addr--67b1fe8b-a3a1-478c-9a36-4e6d2c2a5556",
"value": "12.6.1.1"
},
{
"type": "ipv4-addr",
"spec_version": "2.1",
"id": "ipv4-addr--a5d4b3ba-ab5d-4c86-8046-30480c7daded",
"value": "12.8.0.0"
},
{
"type": "file",
"value": "0305e89110744077d8db8618827351a03bce5b11ef5815a72c64eea009304a34",
"hashes": {
"SHA-256": "0305e89110744077d8db8618827351a03bce5b11ef5815a72c64eea009304a34"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--99b57e02-f77b-489f-a871-74fce6113ee6"
},
{
"type": "file",
"value": "11ae897d79548b6b44da75f7ab335a0585f47886ce22b371f6d340968dbed9ae",
"hashes": {
"SHA-256": "11ae897d79548b6b44da75f7ab335a0585f47886ce22b371f6d340968dbed9ae"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--0b34e0d6-ec1c-4f31-9803-109aad01dce9"
},
{
"type": "file",
"value": "166791aac8b056af8029ab6bdeec5a2626ca3f3961fdf0337d24451cfccfc05d",
"hashes": {
"SHA-256": "166791aac8b056af8029ab6bdeec5a2626ca3f3961fdf0337d24451cfccfc05d"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--ed611eba-6db4-4557-899e-5b979f8c6594"
},
{
"type": "file",
"value": "6aba7b5a9b4f7ad4203f26f3fb539911369aeef502d43af23aa3646d91280ad9",
"hashes": {
"SHA-256": "6aba7b5a9b4f7ad4203f26f3fb539911369aeef502d43af23aa3646d91280ad9"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--cdd07d77-85b3-4ab8-9895-4b25771c7e8f"
},
{
"type": "file",
"value": "7e851b73bd59088d60101109c9ebf7ef300971090c991b57393e4c793f5e2d33",
"hashes": {
"SHA-256": "7e851b73bd59088d60101109c9ebf7ef300971090c991b57393e4c793f5e2d33"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--99af8978-ff6d-4350-9560-7e35a39ce833"
},
{
"type": "file",
"value": "852a80470536cb1fdab1a04d831923616bf00c77320a6b4656e80fc3cc722a66",
"hashes": {
"SHA-256": "852a80470536cb1fdab1a04d831923616bf00c77320a6b4656e80fc3cc722a66"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--82931dde-1bfe-41e8-96ed-0adbd7371ee5"
},
{
"type": "file",
"value": "a42ad963c53f2e0794e7cd0c3632cc75b98f131c3ffceb8f2f740241c097214a",
"hashes": {
"SHA-256": "a42ad963c53f2e0794e7cd0c3632cc75b98f131c3ffceb8f2f740241c097214a"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--ce952501-f160-4d19-aeba-e052a9275351"
},
{
"type": "file",
"value": "aa7a3e8b59b5495f6eebc19f0654b93bb01fd2fa2932458179a8ae85fb4b8ec1",
"hashes": {
"SHA-256": "aa7a3e8b59b5495f6eebc19f0654b93bb01fd2fa2932458179a8ae85fb4b8ec1"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--bf0c4613-58fb-4693-8c03-2c5760c29aeb"
},
{
"type": "file",
"value": "ab72813444207dba5429cf498c6ffbc69e1bd665d8007561d0973246fa7f8175",
"hashes": {
"SHA-256": "ab72813444207dba5429cf498c6ffbc69e1bd665d8007561d0973246fa7f8175"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--c7dc8c85-8223-40b0-bafc-e565545c0804"
},
{
"type": "file",
"value": "adf676107a6c2354d1a484c2a08c36c33d276e355a65f77770ae1ae7b7c36143",
"hashes": {
"SHA-256": "adf676107a6c2354d1a484c2a08c36c33d276e355a65f77770ae1ae7b7c36143"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--e6e80c7a-3ef5-4113-98b6-7b35923fff66"
},
{
"type": "file",
"value": "b480092d8e5f7ca6aebdeaae676ea09281d07fc8ccf2318da2fa1c01471b818d",
"hashes": {
"SHA-256": "b480092d8e5f7ca6aebdeaae676ea09281d07fc8ccf2318da2fa1c01471b818d"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--fa972639-2121-4b38-b07e-9f611571de4b"
},
{
"type": "file",
"value": "bdc5417ffba758b6d0a359b252ba047b59aacf1d217a8b664554256b5adb071d",
"hashes": {
"SHA-256": "bdc5417ffba758b6d0a359b252ba047b59aacf1d217a8b664554256b5adb071d"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--4c15829b-c9f7-4705-a136-54df96f3e81c"
},
{
"type": "file",
"value": "c2d983d3812b5b6d592b149d627b118db2debd33069efe4de4e57306ba42b5dc",
"hashes": {
"SHA-256": "c2d983d3812b5b6d592b149d627b118db2debd33069efe4de4e57306ba42b5dc"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--78093583-ed9c-4a78-a408-78540711dad5"
},
{
"type": "file",
"value": "d49761cdbea170dd17255a958214db392dc7621198f95d5eb5749859c603100a",
"hashes": {
"SHA-256": "d49761cdbea170dd17255a958214db392dc7621198f95d5eb5749859c603100a"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--1bef0928-f61c-4de3-9583-d549a0a61340"
},
{
"type": "file",
"value": "d8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964",
"hashes": {
"SHA-256": "d8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--7f6b73e1-71a5-4928-ba7e-a7d424da5261"
},
{
"type": "file",
"value": "edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809",
"hashes": {
"SHA-256": "edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--8e3c53c8-0f35-4917-8be6-25e54a773733"
},
{
"type": "file",
"value": "f279e462253f130878ffac820f5a0f9ac92dd14ad2f1e4bd21062bab7b99b839",
"hashes": {
"SHA-256": "f279e462253f130878ffac820f5a0f9ac92dd14ad2f1e4bd21062bab7b99b839"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--84fe9cd3-b640-40d1-84f1-4993d16e4a8d"
},
{
"type": "file",
"value": "fd11f419e4ac992e89cca48369e7d774b7b2e0d28d0b6a34f7ee0bc1d943c056",
"hashes": {
"SHA-256": "fd11f419e4ac992e89cca48369e7d774b7b2e0d28d0b6a34f7ee0bc1d943c056"
},
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "file--1376cd0f-6cfd-4b5c-8d39-e019c9921b12"
},
{
"type": "domain-name",
"value": "powerscrews.com",
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "domain-name--30fe8fb8-23b8-497a-9afd-0769b5c73565"
},
{
"type": "domain-name",
"value": "d.2fcc7078.digimg.store",
"source": "OTX-Subscribed",
"pulse_name": "New Lua-based malware LucidRook observed in targeted attacks against Taiwanese organizations",
"id": "domain-name--0294587c-f38c-42fa-b687-8371012afd2f"
},
{
"type": "file",
"value": "0b95524e5b00688f7f5efe56a74b93985feb2152d9336d44ca7a8dd9ca25d2d5",
"hashes": {
"SHA-256": "0b95524e5b00688f7f5efe56a74b93985feb2152d9336d44ca7a8dd9ca25d2d5"
},
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "file--36d8f279-8ff1-49a2-a74f-ceddb59de59a"
},
{
"type": "file",
"value": "87074c1bfd071fc47410a52af863e9ca62b2b85950c4cf643a220f0ea5717952",
"hashes": {
"SHA-256": "87074c1bfd071fc47410a52af863e9ca62b2b85950c4cf643a220f0ea5717952"
},
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "file--1c8cd1e3-13ba-4560-af1a-68b94ae4d208"
},
{
"type": "file",
"value": "f792d82e4472c001852998a3575e492907f38daa8d58ecdb3b3604b38d7b8a07",
"hashes": {
"SHA-256": "f792d82e4472c001852998a3575e492907f38daa8d58ecdb3b3604b38d7b8a07"
},
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "file--fc159c6a-cbbc-48b6-b9c5-b9d11dc308dc"
},
{
"type": "url",
"value": "http://84.54.33.192:8040/Bin/ScreenConnect.ClientSetup.msi",
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "url--007a390b-ae5c-41ea-8d83-75475c8863b4"
},
{
"type": "url",
"value": "https://anythinghere.woremix.icu/Viewfiles/download.php",
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "url--0c8a0b99-5259-4856-a05d-fc0d8fdf3130"
},
{
"type": "url",
"value": "https://lenwillfilenetwork.com/downloads/Network%20Solutions%20Agreement.msi",
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "url--7e3e8791-000a-4d83-b1bc-2d2ef77ef361"
},
{
"type": "domain-name",
"value": "lenwillfilenetwork.com",
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "domain-name--efc14d82-8b97-4e0a-9883-58a8a94159d8"
},
{
"type": "domain-name",
"value": "anythinghere.woremix.icu",
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "domain-name--ddfc1d32-6440-4540-8187-f0f6e0ac6ac3"
},
{
"type": "domain-name",
"value": "shankar.woremix.icu",
"source": "OTX-Subscribed",
"pulse_name": "Threat Actors Weaponize Tiflux RMMs in Malspam Attacks",
"id": "domain-name--ffb0d50c-d04b-428f-81e5-2e6089155d07"
},
{
"type": "file",
"value": "e41c635e4c3514e266d143d544ad1abde5db3dcfe6cccdf9bb7a218003f8ab6a",
"hashes": {
"SHA-256": "e41c635e4c3514e266d143d544ad1abde5db3dcfe6cccdf9bb7a218003f8ab6a"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--7925dd7f-fffa-4046-b14e-aad2c769e80c"
},
{
"type": "domain-name",
"value": "lastpass-login-help.com",
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "domain-name--b31b3aed-28d4-4323-a196-a30173214292"
},
{
"type": "file",
"value": "b8e7288656eca9750a5490aa96d3594b",
"hashes": {
"MD5": "b8e7288656eca9750a5490aa96d3594b"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--8bac32f8-d87e-45e4-aed5-4ce1edf54766"
},
{
"type": "file",
"value": "005587975a483876c1fa26b64b418931019be38f",
"hashes": {
"SHA-1": "005587975a483876c1fa26b64b418931019be38f"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--333175c3-f421-4596-87d8-88a35151ba3e"
},
{
"type": "file",
"value": "01cebc48016395e284ac76afc1816f143ee3e7b6",
"hashes": {
"SHA-1": "01cebc48016395e284ac76afc1816f143ee3e7b6"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--94ffe6cb-fa37-4cba-bb6e-22f15fcc0f07"
},
{
"type": "file",
"value": "0b86434ca5145636d745222f7e49c903ce6ef538",
"hashes": {
"SHA-1": "0b86434ca5145636d745222f7e49c903ce6ef538"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--79f80763-776e-418d-ae7e-04750d99709a"
},
{
"type": "file",
"value": "2cd2c5268e41cdece1b0506bcda3b9eba2998119",
"hashes": {
"SHA-1": "2cd2c5268e41cdece1b0506bcda3b9eba2998119"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--4322174b-e54a-43d9-bea2-f789964dae65"
},
{
"type": "file",
"value": "2fab324eb0d927846c8744dc0e217beea65138e0",
"hashes": {
"SHA-1": "2fab324eb0d927846c8744dc0e217beea65138e0"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--9119ab3e-b456-4773-94ca-6d5807456a17"
},
{
"type": "file",
"value": "339cbf61c80f757085c5afb7304d69f323bdf87a",
"hashes": {
"SHA-1": "339cbf61c80f757085c5afb7304d69f323bdf87a"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--012569f1-63f2-4b87-8454-9430e3918960"
},
{
"type": "file",
"value": "6060da100b5cd587131a1c11a20d6e0108604744",
"hashes": {
"SHA-1": "6060da100b5cd587131a1c11a20d6e0108604744"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--bcac6dff-8d37-4d25-b8a4-de5f312aca1a"
},
{
"type": "file",
"value": "848ef1f638807826586802428a7ebafdc710915c",
"hashes": {
"SHA-1": "848ef1f638807826586802428a7ebafdc710915c"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--4e241c1a-39d5-4517-9e6d-bd8c64c9c290"
},
{
"type": "file",
"value": "9c7ab48c9fdbbeecdad8433529bdab38584f0e25",
"hashes": {
"SHA-1": "9c7ab48c9fdbbeecdad8433529bdab38584f0e25"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--4801bd56-5685-4fd4-8708-7b8d0066ba6d"
},
{
"type": "file",
"value": "a20a9924d92c2b06d82b79c0fe87451c650cabec",
"hashes": {
"SHA-1": "a20a9924d92c2b06d82b79c0fe87451c650cabec"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--069808d1-aa93-48b0-8772-d7fa42df6a1a"
},
{
"type": "file",
"value": "c2dd8051d89c4efa71bd67d2df7d9b4bc3e67810",
"hashes": {
"SHA-1": "c2dd8051d89c4efa71bd67d2df7d9b4bc3e67810"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--3460d037-0755-42a2-b9c1-d30cdbf42d89"
},
{
"type": "file",
"value": "fed52a4bbac7b5b6ae4f76cab3eadd67e79227e3",
"hashes": {
"SHA-1": "fed52a4bbac7b5b6ae4f76cab3eadd67e79227e3"
},
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "file--c9ac9738-5dc0-402e-bcb5-6e8b9c893d98"
},
{
"type": "url",
"value": "https://cdn.cloudfront-js.com:8443/u",
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "url--19b8373f-8afa-4c1b-921c-f33833daabf2"
},
{
"type": "domain-name",
"value": "cdn.cloudfront-js.com",
"source": "OTX-Subscribed",
"pulse_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
"id": "domain-name--5b2fadde-50a0-43b1-82cc-ac906b7d7596"
},
{
"type": "domain-name",
"value": "dns-providersa2.com",
"source": "OTX-Subscribed",
"pulse_name": "5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer",
"id": "domain-name--0c4e404a-a048-4ca7-b9ad-90b7edf3fc60"
},
{
"type": "url",
"value": "https://dns-providersa2.com/upload",
"source": "OTX-Subscribed",
"pulse_name": "5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer",
"id": "url--10c79a48-c78f-4ff5-992d-db190386eab4"
},
{
"type": "url",
"value": "https://dns-providersa2.com/check",
"source": "OTX-Subscribed",
"pulse_name": "5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer",
"id": "url--538bb72d-ee7d-411e-bd70-cf8032f6a99d"
},
{
"type": "domain-name",
"value": "git.justdotrip.com",
"source": "OTX-Subscribed",
"pulse_name": "5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer",
"id": "domain-name--62adba55-6e03-405b-8965-e47a6445ede3"
},
{
"type": "domain-name",
"value": "checkbot8634938602.duckdns.org",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--6b507e8a-ab34-47ec-8a60-7b2863948bcb"
},
{
"type": "domain-name",
"value": "indianstreetbets.ddns.net",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--df828e3e-85a8-4ee0-826f-deb316e746fa"
},
{
"type": "domain-name",
"value": "billpaycanada.online",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--74be08f3-bd23-45e6-8d59-84492a4780a4"
},
{
"type": "domain-name",
"value": "poorinfo.tk",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--28e9d7c8-0b79-4e22-b594-da2291b0c3af"
},
{
"type": "domain-name",
"value": "9twelve-srvcs.zapto.org",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--b308d0ef-e8bc-4be4-b03a-661339743bf5"
},
{
"type": "domain-name",
"value": "peak.serveftp.net",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--bb4bbf8f-8930-4e91-879d-2d505c5175f1"
},
{
"type": "domain-name",
"value": "www.hoanglonggroup.com",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--80ffe91c-3a3c-450a-8cf7-6dd47fcd7072"
},
{
"type": "domain-name",
"value": "www.account-next.com",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--d55c2760-6f63-4228-9d33-987a519fda0a"
},
{
"type": "domain-name",
"value": "jjuangco.ddns.net",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--2f57b158-e2c7-4db9-9f40-b80afafd2d62"
},
{
"type": "domain-name",
"value": "uyhb4rz7vcph6j.com",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--391ac3cf-a457-45da-b2ce-42b96918eabc"
},
{
"type": "domain-name",
"value": "www.mohimjo.com",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--9ba644e6-8d5b-44de-8410-0ee596bbe47b"
},
{
"type": "domain-name",
"value": "www.shimmeringlight.ir",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--976696e7-8a15-405c-8174-3339573aa204"
},
{
"type": "domain-name",
"value": "mi.cuenta.amazon.es.dsgaradcollegemohol.online",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--418ce282-95bf-4b4b-bfe2-6bb15a40d24c"
},
{
"type": "domain-name",
"value": "seeking0support.ddns.net",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--9f1fc006-128c-4a35-aff9-1189f46f3a6e"
},
{
"type": "domain-name",
"value": "www.dsgaradcollegemohol.online",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--2d0ca9fe-8b44-4d7d-9f4d-6982043163c2"
},
{
"type": "domain-name",
"value": "freeworldlike.tk",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--27e6fd86-874b-4daf-b94e-88fb39f40a47"
},
{
"type": "domain-name",
"value": "www.oksurls.info",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--8206c595-f663-4051-b7ef-f6239a1c0636"
},
{
"type": "domain-name",
"value": "www.vbzurls.info",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--d0c82521-7ef2-4948-bfcb-4b1df6d7e798"
},
{
"type": "domain-name",
"value": "www.suncbi.com",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--45c5ea35-0cc1-44ca-ab7a-9f8b22a66250"
},
{
"type": "domain-name",
"value": "facaziki2.xyz",
"source": "OTX",
"malware_families": [
"Chaos ransomware"
],
"pulse_names": [
"Malware - Malware Domain Feed V2 - November 03 2020"
],
"id": "domain-name--a571934d-b012-49a0-bc9b-3cc31e010e59"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3737f004-0f2b-41e0-89fd-b49cd9f3791d",
"created": "2026-05-08T14:53:24.016Z",
"modified": "2026-05-08T14:53:24.016Z",
"name": "Malicious ipv4-addr indicator",
"description": "Malicious ipv4-addr identified in threat intelligence",
"pattern": "[ipv4-addr:value = '12.7.0.1']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:24.016Z",
"labels": [
"malicious-activity"
],
"confidence": 95
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b279757d-daf3-44c0-8697-158e88eab854",
"created": "2026-05-08T14:53:24.016Z",
"modified": "2026-05-08T14:53:24.016Z",
"relationship_type": "based-on",
"source_ref": "indicator--3737f004-0f2b-41e0-89fd-b49cd9f3791d",
"target_ref": "ipv4-addr--fcf9628c-46ee-4edd-8552-8e890e71f271"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--222fb629-adc4-4ad2-84c2-513e4aaae7eb",
"created": "2026-05-08T14:53:24.023Z",
"modified": "2026-05-08T14:53:24.023Z",
"name": "Malicious ipv4-addr indicator",
"description": "Malicious ipv4-addr identified in threat intelligence",
"pattern": "[ipv4-addr:value = '12.8.0.1']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:24.023Z",
"labels": [
"malicious-activity"
],
"confidence": 95
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6dbe468f-6be1-40b1-9dac-446593eb3a2d",
"created": "2026-05-08T14:53:24.023Z",
"modified": "2026-05-08T14:53:24.023Z",
"relationship_type": "based-on",
"source_ref": "indicator--222fb629-adc4-4ad2-84c2-513e4aaae7eb",
"target_ref": "ipv4-addr--398631a3-2e68-4b99-9fda-54f70ba0e582"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c9370069-b197-4cc2-8627-dc88ee96f4ab",
"created": "2026-05-08T14:53:24.029Z",
"modified": "2026-05-08T14:53:24.029Z",
"name": "Malicious ipv4-addr indicator",
"description": "Malicious ipv4-addr identified in threat intelligence",
"pattern": "[ipv4-addr:value = '12.6.1.1']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:24.029Z",
"labels": [
"malicious-activity"
],
"confidence": 95
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a0b3e41d-7d3e-437e-b6b5-7dd3eb4fbfdd",
"created": "2026-05-08T14:53:24.029Z",
"modified": "2026-05-08T14:53:24.029Z",
"relationship_type": "based-on",
"source_ref": "indicator--c9370069-b197-4cc2-8627-dc88ee96f4ab",
"target_ref": "ipv4-addr--67b1fe8b-a3a1-478c-9a36-4e6d2c2a5556"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7996bfe4-3d91-495f-843d-fc32cc8c9d3d",
"created": "2026-05-08T14:53:24.035Z",
"modified": "2026-05-08T14:53:24.035Z",
"name": "Malicious ipv4-addr indicator",
"description": "Malicious ipv4-addr identified in threat intelligence",
"pattern": "[ipv4-addr:value = '12.8.0.0']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:24.035Z",
"labels": [
"malicious-activity"
],
"confidence": 95
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--52923c5b-dc35-42b8-9d72-f5025df4a5e0",
"created": "2026-05-08T14:53:24.035Z",
"modified": "2026-05-08T14:53:24.035Z",
"relationship_type": "based-on",
"source_ref": "indicator--7996bfe4-3d91-495f-843d-fc32cc8c9d3d",
"target_ref": "ipv4-addr--a5d4b3ba-ab5d-4c86-8046-30480c7daded"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--46f4d47e-a42c-4531-a4e9-7b6defc9ffab",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '0305e89110744077d8db8618827351a03bce5b11ef5815a72c64eea009304a34']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5805ce93-d1a2-490a-9f4e-9abcd2ff92ba",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--46f4d47e-a42c-4531-a4e9-7b6defc9ffab",
"target_ref": "file--99b57e02-f77b-489f-a871-74fce6113ee6"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0d14a12b-6921-47a6-bc93-1dc87192a060",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '11ae897d79548b6b44da75f7ab335a0585f47886ce22b371f6d340968dbed9ae']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ded5768e-927c-487a-8444-7bb5dc26ead1",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--0d14a12b-6921-47a6-bc93-1dc87192a060",
"target_ref": "file--0b34e0d6-ec1c-4f31-9803-109aad01dce9"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--1fffda73-7b0a-4033-83ae-bdaf2f2dd788",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '166791aac8b056af8029ab6bdeec5a2626ca3f3961fdf0337d24451cfccfc05d']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7269624e-a880-4f19-9d12-28a9987195f7",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--1fffda73-7b0a-4033-83ae-bdaf2f2dd788",
"target_ref": "file--ed611eba-6db4-4557-899e-5b979f8c6594"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--a49cc7de-6154-411c-88ea-c9b3eb194dcc",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '6aba7b5a9b4f7ad4203f26f3fb539911369aeef502d43af23aa3646d91280ad9']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--94c725ea-0e36-419e-8669-83a87f9f4e0d",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--a49cc7de-6154-411c-88ea-c9b3eb194dcc",
"target_ref": "file--cdd07d77-85b3-4ab8-9895-4b25771c7e8f"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--74c946b6-0004-42e8-bf8e-489e5bf9cbaa",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '7e851b73bd59088d60101109c9ebf7ef300971090c991b57393e4c793f5e2d33']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4416a98c-e048-420d-9c37-56bf147dde00",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--74c946b6-0004-42e8-bf8e-489e5bf9cbaa",
"target_ref": "file--99af8978-ff6d-4350-9560-7e35a39ce833"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--d038a601-abfb-49f1-a600-78b9fd77cb07",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '852a80470536cb1fdab1a04d831923616bf00c77320a6b4656e80fc3cc722a66']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--95226818-ee24-47a0-b2a2-62123742382a",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--d038a601-abfb-49f1-a600-78b9fd77cb07",
"target_ref": "file--82931dde-1bfe-41e8-96ed-0adbd7371ee5"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--cfa5cc77-7f4f-4dff-994f-e2e0897fdb85",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'a42ad963c53f2e0794e7cd0c3632cc75b98f131c3ffceb8f2f740241c097214a']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ed446572-5c85-4f27-99ae-c56380d9bbb7",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--cfa5cc77-7f4f-4dff-994f-e2e0897fdb85",
"target_ref": "file--ce952501-f160-4d19-aeba-e052a9275351"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--999b2cfb-e4ca-40d5-9719-cbe28bda117a",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'aa7a3e8b59b5495f6eebc19f0654b93bb01fd2fa2932458179a8ae85fb4b8ec1']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--40c1281a-ff34-429d-8354-030d481d04b0",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--999b2cfb-e4ca-40d5-9719-cbe28bda117a",
"target_ref": "file--bf0c4613-58fb-4693-8c03-2c5760c29aeb"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--87755302-fafd-4ae3-9a73-8fc351f09768",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'ab72813444207dba5429cf498c6ffbc69e1bd665d8007561d0973246fa7f8175']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--eab88738-408f-4cd6-9ec5-01696e16a4ac",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--87755302-fafd-4ae3-9a73-8fc351f09768",
"target_ref": "file--c7dc8c85-8223-40b0-bafc-e565545c0804"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--4724a470-d53f-49c1-aa0a-2992d369112a",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'adf676107a6c2354d1a484c2a08c36c33d276e355a65f77770ae1ae7b7c36143']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a629e544-9b5f-4209-9871-1915dbe784a8",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--4724a470-d53f-49c1-aa0a-2992d369112a",
"target_ref": "file--e6e80c7a-3ef5-4113-98b6-7b35923fff66"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--25891cad-bf27-45e7-8b05-11348825d00c",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'b480092d8e5f7ca6aebdeaae676ea09281d07fc8ccf2318da2fa1c01471b818d']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1247286b-7d48-4ea0-ae32-2320bc1cfdf7",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--25891cad-bf27-45e7-8b05-11348825d00c",
"target_ref": "file--fa972639-2121-4b38-b07e-9f611571de4b"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--13dd4672-0a1d-48b9-9e90-8bc0ba6e796d",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'bdc5417ffba758b6d0a359b252ba047b59aacf1d217a8b664554256b5adb071d']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ff8ea414-b64a-40a6-9d6f-42cc213f18f0",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--13dd4672-0a1d-48b9-9e90-8bc0ba6e796d",
"target_ref": "file--4c15829b-c9f7-4705-a136-54df96f3e81c"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ab06cb65-46de-4149-85ea-69eb7f394826",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'c2d983d3812b5b6d592b149d627b118db2debd33069efe4de4e57306ba42b5dc']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--bb47a588-536d-45db-a7f5-8d2004d89f2c",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--ab06cb65-46de-4149-85ea-69eb7f394826",
"target_ref": "file--78093583-ed9c-4a78-a408-78540711dad5"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--793ac21b-491d-4fbd-966c-91e220776790",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'd49761cdbea170dd17255a958214db392dc7621198f95d5eb5749859c603100a']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6668ab45-82f7-48b4-bbe1-4e954c0c41ce",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--793ac21b-491d-4fbd-966c-91e220776790",
"target_ref": "file--1bef0928-f61c-4de3-9583-d549a0a61340"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--730d36c8-c593-45a4-b417-afc0fcb16a64",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'd8bc6047fb3fd4f47b15b4058fa482690b5b72a5e3b3d324c21d7da4435c9964']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--93740008-f911-4122-9c05-bbc01e9b3b10",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--730d36c8-c593-45a4-b417-afc0fcb16a64",
"target_ref": "file--7f6b73e1-71a5-4928-ba7e-a7d424da5261"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--fb0591cd-f547-4081-af7c-c6084a29a480",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'edb25fed9df8e9a517188f609b9d1a030682c701c01c0d1b5ce79cba9f7ac809']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--04816d97-cd7e-49c2-aa34-8c8172b6e451",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--fb0591cd-f547-4081-af7c-c6084a29a480",
"target_ref": "file--8e3c53c8-0f35-4917-8be6-25e54a773733"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6a020350-6536-45a7-b163-8cfbbfce8c65",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'f279e462253f130878ffac820f5a0f9ac92dd14ad2f1e4bd21062bab7b99b839']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8e7ca3a7-1c2a-40c5-908d-2748fb37ca5b",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--6a020350-6536-45a7-b163-8cfbbfce8c65",
"target_ref": "file--84fe9cd3-b640-40d1-84f1-4993d16e4a8d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c0c08ed1-8e4b-4a96-8b2b-8c01196cf52e",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'fd11f419e4ac992e89cca48369e7d774b7b2e0d28d0b6a34f7ee0bc1d943c056']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.249Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b4246c74-8fb9-4eab-8875-ad9b21dd9bf5",
"created": "2026-05-08T14:53:38.249Z",
"modified": "2026-05-08T14:53:38.249Z",
"relationship_type": "based-on",
"source_ref": "indicator--c0c08ed1-8e4b-4a96-8b2b-8c01196cf52e",
"target_ref": "file--1376cd0f-6cfd-4b5c-8d39-e019c9921b12"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0638421d-0ea0-40c9-9c01-ba1956f7ceb5",
"created": "2026-05-08T14:53:38.264Z",
"modified": "2026-05-08T14:53:38.264Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'powerscrews.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.264Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--091131d5-f2bf-4d35-b94b-9b798aee5959",
"created": "2026-05-08T14:53:38.264Z",
"modified": "2026-05-08T14:53:38.264Z",
"relationship_type": "based-on",
"source_ref": "indicator--0638421d-0ea0-40c9-9c01-ba1956f7ceb5",
"target_ref": "domain-name--30fe8fb8-23b8-497a-9afd-0769b5c73565"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--56a0fee6-9cf2-42c1-93e3-ba7c4a8dc640",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'd.2fcc7078.digimg.store']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.279Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--0325d5bd-98be-4c0e-8431-db8de0d06823",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"relationship_type": "based-on",
"source_ref": "indicator--56a0fee6-9cf2-42c1-93e3-ba7c4a8dc640",
"target_ref": "domain-name--0294587c-f38c-42fa-b687-8371012afd2f"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--1ef63244-3232-4c1f-a9a7-afc46789b06e",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '0b95524e5b00688f7f5efe56a74b93985feb2152d9336d44ca7a8dd9ca25d2d5']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.279Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5cc47bf7-d37f-4f39-ada4-edda32c3c1f7",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"relationship_type": "based-on",
"source_ref": "indicator--1ef63244-3232-4c1f-a9a7-afc46789b06e",
"target_ref": "file--36d8f279-8ff1-49a2-a74f-ceddb59de59a"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b31b89c8-9cf5-443d-a2e4-16836da9099a",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = '87074c1bfd071fc47410a52af863e9ca62b2b85950c4cf643a220f0ea5717952']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.279Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7eff61fb-a1ca-413c-a0f8-c2c487093832",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"relationship_type": "based-on",
"source_ref": "indicator--b31b89c8-9cf5-443d-a2e4-16836da9099a",
"target_ref": "file--1c8cd1e3-13ba-4560-af1a-68b94ae4d208"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9897a661-c77e-4c4e-a3cd-f2d79a684f89",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'f792d82e4472c001852998a3575e492907f38daa8d58ecdb3b3604b38d7b8a07']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.279Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--545fc567-a68c-4408-9eaa-c69a8a0cefb3",
"created": "2026-05-08T14:53:38.279Z",
"modified": "2026-05-08T14:53:38.279Z",
"relationship_type": "based-on",
"source_ref": "indicator--9897a661-c77e-4c4e-a3cd-f2d79a684f89",
"target_ref": "file--fc159c6a-cbbc-48b6-b9c5-b9d11dc308dc"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--abf6326c-ebe0-415d-869b-556efe0c400c",
"created": "2026-05-08T14:53:38.294Z",
"modified": "2026-05-08T14:53:38.294Z",
"name": "Malicious url indicator",
"description": "Malicious url identified in threat intelligence",
"pattern": "[url:value = 'http://84.54.33.192:8040/Bin/ScreenConnect.ClientSetup.msi']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.294Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5cfd0e4b-b2b6-447c-86d8-4309f3efebd7",
"created": "2026-05-08T14:53:38.294Z",
"modified": "2026-05-08T14:53:38.294Z",
"relationship_type": "based-on",
"source_ref": "indicator--abf6326c-ebe0-415d-869b-556efe0c400c",
"target_ref": "url--007a390b-ae5c-41ea-8d83-75475c8863b4"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3deeef52-fe28-4cf5-a3e3-c6cd6765a6e6",
"created": "2026-05-08T14:53:38.309Z",
"modified": "2026-05-08T14:53:38.309Z",
"name": "Malicious url indicator",
"description": "Malicious url identified in threat intelligence",
"pattern": "[url:value = 'https://anythinghere.woremix.icu/Viewfiles/download.php']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.309Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--efe47c35-eff1-4d87-a2ec-08a1e70ec6a3",
"created": "2026-05-08T14:53:38.309Z",
"modified": "2026-05-08T14:53:38.309Z",
"relationship_type": "based-on",
"source_ref": "indicator--3deeef52-fe28-4cf5-a3e3-c6cd6765a6e6",
"target_ref": "url--0c8a0b99-5259-4856-a05d-fc0d8fdf3130"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9b72bc53-c523-43e0-905a-059a5ff0a0fb",
"created": "2026-05-08T14:53:38.324Z",
"modified": "2026-05-08T14:53:38.324Z",
"name": "Malicious url indicator",
"description": "Malicious url identified in threat intelligence",
"pattern": "[url:value = 'https://lenwillfilenetwork.com/downloads/Network%20Solutions%20Agreement.msi']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.324Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e71f29e6-d674-4450-9b77-8f748e298a20",
"created": "2026-05-08T14:53:38.324Z",
"modified": "2026-05-08T14:53:38.324Z",
"relationship_type": "based-on",
"source_ref": "indicator--9b72bc53-c523-43e0-905a-059a5ff0a0fb",
"target_ref": "url--7e3e8791-000a-4d83-b1bc-2d2ef77ef361"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--d598d739-4f88-4cc4-bd75-9ee929f11ec4",
"created": "2026-05-08T14:53:38.341Z",
"modified": "2026-05-08T14:53:38.341Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'lenwillfilenetwork.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.341Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--76ba4ee0-bf1c-4896-a13b-17aef6ae522d",
"created": "2026-05-08T14:53:38.341Z",
"modified": "2026-05-08T14:53:38.341Z",
"relationship_type": "based-on",
"source_ref": "indicator--d598d739-4f88-4cc4-bd75-9ee929f11ec4",
"target_ref": "domain-name--efc14d82-8b97-4e0a-9883-58a8a94159d8"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--12dbd412-bc93-489b-b6fe-7b01c1041dc3",
"created": "2026-05-08T14:53:38.355Z",
"modified": "2026-05-08T14:53:38.355Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'anythinghere.woremix.icu']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.355Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1f7fe038-c95d-4687-8842-a90bb83d0951",
"created": "2026-05-08T14:53:38.355Z",
"modified": "2026-05-08T14:53:38.355Z",
"relationship_type": "based-on",
"source_ref": "indicator--12dbd412-bc93-489b-b6fe-7b01c1041dc3",
"target_ref": "domain-name--ddfc1d32-6440-4540-8187-f0f6e0ac6ac3"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--2a7de07e-5a66-4299-aea3-e2373960d96c",
"created": "2026-05-08T14:53:38.370Z",
"modified": "2026-05-08T14:53:38.370Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'shankar.woremix.icu']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.370Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a7eb95dd-49c1-43a8-804c-811741735335",
"created": "2026-05-08T14:53:38.370Z",
"modified": "2026-05-08T14:53:38.370Z",
"relationship_type": "based-on",
"source_ref": "indicator--2a7de07e-5a66-4299-aea3-e2373960d96c",
"target_ref": "domain-name--ffb0d50c-d04b-428f-81e5-2e6089155d07"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e4b924a8-36ee-486d-8e81-75ee2fa45455",
"created": "2026-05-08T14:53:38.370Z",
"modified": "2026-05-08T14:53:38.370Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-256' = 'e41c635e4c3514e266d143d544ad1abde5db3dcfe6cccdf9bb7a218003f8ab6a']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.370Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--81192100-2de1-4ad4-9f19-42d7fa0a9b02",
"created": "2026-05-08T14:53:38.370Z",
"modified": "2026-05-08T14:53:38.370Z",
"relationship_type": "based-on",
"source_ref": "indicator--e4b924a8-36ee-486d-8e81-75ee2fa45455",
"target_ref": "file--7925dd7f-fffa-4046-b14e-aad2c769e80c"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e2bb4aae-e13a-4e80-9fe0-56969946b999",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'lastpass-login-help.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--83203b02-545a-447d-a5f5-9274b99fb057",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--e2bb4aae-e13a-4e80-9fe0-56969946b999",
"target_ref": "domain-name--b31b3aed-28d4-4323-a196-a30173214292"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f6759fb4-83dc-442d-96a5-b067ff866182",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'MD5' = 'b8e7288656eca9750a5490aa96d3594b']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--49a0c1e9-d9e9-4683-909d-e7caa1ebc09f",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--f6759fb4-83dc-442d-96a5-b067ff866182",
"target_ref": "file--8bac32f8-d87e-45e4-aed5-4ce1edf54766"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f01dff36-a09e-4302-b53a-0a7f9a8de800",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '005587975a483876c1fa26b64b418931019be38f']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--57f7e749-9a87-4576-9915-86cd5ea69df7",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--f01dff36-a09e-4302-b53a-0a7f9a8de800",
"target_ref": "file--333175c3-f421-4596-87d8-88a35151ba3e"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--1573198e-ac23-4f09-8706-cd66f3e35253",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '01cebc48016395e284ac76afc1816f143ee3e7b6']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--742ae493-808b-4779-b6ee-bd2a71f531fa",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--1573198e-ac23-4f09-8706-cd66f3e35253",
"target_ref": "file--94ffe6cb-fa37-4cba-bb6e-22f15fcc0f07"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--aff4b601-5c3c-49e9-9032-aa53343b3e72",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '0b86434ca5145636d745222f7e49c903ce6ef538']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3807e6f1-2c43-4583-9210-298c64827b23",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--aff4b601-5c3c-49e9-9032-aa53343b3e72",
"target_ref": "file--79f80763-776e-418d-ae7e-04750d99709a"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7130cd0b-cffd-43d7-9373-43c03e79ec75",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '2cd2c5268e41cdece1b0506bcda3b9eba2998119']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--bcb0220a-46d6-4126-8c88-079623e72961",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--7130cd0b-cffd-43d7-9373-43c03e79ec75",
"target_ref": "file--4322174b-e54a-43d9-bea2-f789964dae65"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--dcd31d31-e328-428f-b7e3-851b1fe9de52",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '2fab324eb0d927846c8744dc0e217beea65138e0']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--d7f7b681-fd0e-48a6-a3bc-594181b45e71",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--dcd31d31-e328-428f-b7e3-851b1fe9de52",
"target_ref": "file--9119ab3e-b456-4773-94ca-6d5807456a17"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--15d7a563-d657-402f-b00a-7d7e016d2dd9",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '339cbf61c80f757085c5afb7304d69f323bdf87a']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--525152fb-0580-4862-bef1-c8e6a41855f7",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--15d7a563-d657-402f-b00a-7d7e016d2dd9",
"target_ref": "file--012569f1-63f2-4b87-8454-9430e3918960"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--36abf4a1-0626-48ce-88a7-ac4731ab9d2c",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '6060da100b5cd587131a1c11a20d6e0108604744']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--a844c4bc-d87f-4ee2-a2a8-362a40d6c4c1",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--36abf4a1-0626-48ce-88a7-ac4731ab9d2c",
"target_ref": "file--bcac6dff-8d37-4d25-b8a4-de5f312aca1a"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--deb86168-e00b-41c6-8f7a-cf774bbff169",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '848ef1f638807826586802428a7ebafdc710915c']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--42b6a511-70d4-4342-be74-45d2d505d958",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--deb86168-e00b-41c6-8f7a-cf774bbff169",
"target_ref": "file--4e241c1a-39d5-4517-9e6d-bd8c64c9c290"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--7ffe8762-9d18-4848-8b86-05362e1f789a",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = '9c7ab48c9fdbbeecdad8433529bdab38584f0e25']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--f7eeccdd-b09c-4114-93cc-12a534c6ac45",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--7ffe8762-9d18-4848-8b86-05362e1f789a",
"target_ref": "file--4801bd56-5685-4fd4-8708-7b8d0066ba6d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5a20f3f5-cec5-4aba-a5c3-c3cddec2a787",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = 'a20a9924d92c2b06d82b79c0fe87451c650cabec']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--51e93463-294d-43fc-b484-aec46ba9109e",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--5a20f3f5-cec5-4aba-a5c3-c3cddec2a787",
"target_ref": "file--069808d1-aa93-48b0-8772-d7fa42df6a1a"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5cb65448-a86a-4ec2-bb3e-5a0ce7a38cda",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = 'c2dd8051d89c4efa71bd67d2df7d9b4bc3e67810']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c6308b85-526b-4061-80ac-5ec641dacbce",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--5cb65448-a86a-4ec2-bb3e-5a0ce7a38cda",
"target_ref": "file--3460d037-0755-42a2-b9c1-d30cdbf42d89"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--8abd1692-d843-40dd-9156-1a77e3a2dcad",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"name": "Malicious file indicator",
"description": "Malicious file identified in threat intelligence",
"pattern": "[file:hashes.'SHA-1' = 'fed52a4bbac7b5b6ae4f76cab3eadd67e79227e3']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.384Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--07223623-a0ca-45b1-9dc7-994df0e13219",
"created": "2026-05-08T14:53:38.384Z",
"modified": "2026-05-08T14:53:38.384Z",
"relationship_type": "based-on",
"source_ref": "indicator--8abd1692-d843-40dd-9156-1a77e3a2dcad",
"target_ref": "file--c9ac9738-5dc0-402e-bcb5-6e8b9c893d98"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0ddebffe-8ebf-46d5-84bb-340ced6f8cbf",
"created": "2026-05-08T14:53:38.400Z",
"modified": "2026-05-08T14:53:38.400Z",
"name": "Malicious url indicator",
"description": "Malicious url identified in threat intelligence",
"pattern": "[url:value = 'https://cdn.cloudfront-js.com:8443/u']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.400Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e2e397b7-1348-4867-a713-23a1abf5710c",
"created": "2026-05-08T14:53:38.400Z",
"modified": "2026-05-08T14:53:38.400Z",
"relationship_type": "based-on",
"source_ref": "indicator--0ddebffe-8ebf-46d5-84bb-340ced6f8cbf",
"target_ref": "url--19b8373f-8afa-4c1b-921c-f33833daabf2"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3fd9a3d6-704e-4be1-918f-d43c6b36285a",
"created": "2026-05-08T14:53:38.419Z",
"modified": "2026-05-08T14:53:38.419Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'cdn.cloudfront-js.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.419Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--93da6b60-9360-43e4-b1fb-2242cd4ad605",
"created": "2026-05-08T14:53:38.419Z",
"modified": "2026-05-08T14:53:38.419Z",
"relationship_type": "based-on",
"source_ref": "indicator--3fd9a3d6-704e-4be1-918f-d43c6b36285a",
"target_ref": "domain-name--5b2fadde-50a0-43b1-82cc-ac906b7d7596"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--a5bafdcb-b820-4a86-8828-785c1b560ecd",
"created": "2026-05-08T14:53:38.438Z",
"modified": "2026-05-08T14:53:38.438Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'dns-providersa2.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.438Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8e9285b8-b873-4ccb-97cd-043dc3c381bf",
"created": "2026-05-08T14:53:38.438Z",
"modified": "2026-05-08T14:53:38.438Z",
"relationship_type": "based-on",
"source_ref": "indicator--a5bafdcb-b820-4a86-8828-785c1b560ecd",
"target_ref": "domain-name--0c4e404a-a048-4ca7-b9ad-90b7edf3fc60"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--54ea5c64-cd37-48d8-b792-61b9df2964b4",
"created": "2026-05-08T14:53:38.457Z",
"modified": "2026-05-08T14:53:38.457Z",
"name": "Malicious url indicator",
"description": "Malicious url identified in threat intelligence",
"pattern": "[url:value = 'https://dns-providersa2.com/upload']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.457Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--62c50bb3-3d83-4667-b3c9-b858ad6b4f0d",
"created": "2026-05-08T14:53:38.457Z",
"modified": "2026-05-08T14:53:38.457Z",
"relationship_type": "based-on",
"source_ref": "indicator--54ea5c64-cd37-48d8-b792-61b9df2964b4",
"target_ref": "url--10c79a48-c78f-4ff5-992d-db190386eab4"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c1599584-b529-4b8f-9b74-8a439c47a6d9",
"created": "2026-05-08T14:53:38.474Z",
"modified": "2026-05-08T14:53:38.474Z",
"name": "Malicious url indicator",
"description": "Malicious url identified in threat intelligence",
"pattern": "[url:value = 'https://dns-providersa2.com/check']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.474Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--34acd7e6-7968-49db-b7e8-3fa6c4458bd5",
"created": "2026-05-08T14:53:38.474Z",
"modified": "2026-05-08T14:53:38.474Z",
"relationship_type": "based-on",
"source_ref": "indicator--c1599584-b529-4b8f-9b74-8a439c47a6d9",
"target_ref": "url--538bb72d-ee7d-411e-bd70-cf8032f6a99d"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c9e3aee3-bc2b-4fcf-8cf3-59c7e35c8c66",
"created": "2026-05-08T14:53:38.490Z",
"modified": "2026-05-08T14:53:38.490Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'git.justdotrip.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:53:38.490Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--7c6bf2f8-4e9e-458a-a256-17e33e3926f5",
"created": "2026-05-08T14:53:38.490Z",
"modified": "2026-05-08T14:53:38.490Z",
"relationship_type": "based-on",
"source_ref": "indicator--c9e3aee3-bc2b-4fcf-8cf3-59c7e35c8c66",
"target_ref": "domain-name--62adba55-6e03-405b-8965-e47a6445ede3"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0aabb538-8f14-483a-b01c-c22d84d59f29",
"created": "2026-05-08T14:55:23.547Z",
"modified": "2026-05-08T14:55:23.547Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'checkbot8634938602.duckdns.org']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.547Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--bbfe67e0-a90a-41d3-aacb-9be05a5ab4ed",
"created": "2026-05-08T14:55:23.547Z",
"modified": "2026-05-08T14:55:23.547Z",
"relationship_type": "based-on",
"source_ref": "indicator--0aabb538-8f14-483a-b01c-c22d84d59f29",
"target_ref": "domain-name--6b507e8a-ab34-47ec-8a60-7b2863948bcb"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e7608f70-1278-4214-82fa-9b1f5aa81e3a",
"created": "2026-05-08T14:55:23.616Z",
"modified": "2026-05-08T14:55:23.616Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'indianstreetbets.ddns.net']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.616Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--403174e9-078b-4eca-a0d5-3603e5a6c248",
"created": "2026-05-08T14:55:23.616Z",
"modified": "2026-05-08T14:55:23.616Z",
"relationship_type": "based-on",
"source_ref": "indicator--e7608f70-1278-4214-82fa-9b1f5aa81e3a",
"target_ref": "domain-name--df828e3e-85a8-4ee0-826f-deb316e746fa"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f0da10b8-8aa2-4b32-b7bb-6b3e8b3e60ae",
"created": "2026-05-08T14:55:23.637Z",
"modified": "2026-05-08T14:55:23.637Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'billpaycanada.online']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.637Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--24c7e63d-f345-4918-81a3-cf51a2ec1aa6",
"created": "2026-05-08T14:55:23.637Z",
"modified": "2026-05-08T14:55:23.637Z",
"relationship_type": "based-on",
"source_ref": "indicator--f0da10b8-8aa2-4b32-b7bb-6b3e8b3e60ae",
"target_ref": "domain-name--74be08f3-bd23-45e6-8d59-84492a4780a4"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--96fe08c8-9261-41ab-bbfb-70b55be19e7d",
"created": "2026-05-08T14:55:23.656Z",
"modified": "2026-05-08T14:55:23.656Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'poorinfo.tk']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.656Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--3e09c8fb-1f88-4ffb-8894-49ba613e2689",
"created": "2026-05-08T14:55:23.656Z",
"modified": "2026-05-08T14:55:23.656Z",
"relationship_type": "based-on",
"source_ref": "indicator--96fe08c8-9261-41ab-bbfb-70b55be19e7d",
"target_ref": "domain-name--28e9d7c8-0b79-4e22-b594-da2291b0c3af"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--37e78efa-aff9-4ecb-ad1e-e65c08e2266b",
"created": "2026-05-08T14:55:23.674Z",
"modified": "2026-05-08T14:55:23.674Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = '9twelve-srvcs.zapto.org']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.674Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5539cf9d-1220-480e-bbf5-7b23505e8e47",
"created": "2026-05-08T14:55:23.674Z",
"modified": "2026-05-08T14:55:23.674Z",
"relationship_type": "based-on",
"source_ref": "indicator--37e78efa-aff9-4ecb-ad1e-e65c08e2266b",
"target_ref": "domain-name--b308d0ef-e8bc-4be4-b03a-661339743bf5"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--6807be85-c2c0-4018-9f40-57e414618ffc",
"created": "2026-05-08T14:55:23.707Z",
"modified": "2026-05-08T14:55:23.707Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'peak.serveftp.net']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.707Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--30fc30ee-45fb-4742-9357-6490a9a7095d",
"created": "2026-05-08T14:55:23.707Z",
"modified": "2026-05-08T14:55:23.707Z",
"relationship_type": "based-on",
"source_ref": "indicator--6807be85-c2c0-4018-9f40-57e414618ffc",
"target_ref": "domain-name--bb4bbf8f-8930-4e91-879d-2d505c5175f1"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--4758589f-65fd-4c8a-a89f-ca6e25040980",
"created": "2026-05-08T14:55:23.723Z",
"modified": "2026-05-08T14:55:23.723Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.hoanglonggroup.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.723Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--62caa360-3c23-4bbe-974b-62e3feb09793",
"created": "2026-05-08T14:55:23.723Z",
"modified": "2026-05-08T14:55:23.723Z",
"relationship_type": "based-on",
"source_ref": "indicator--4758589f-65fd-4c8a-a89f-ca6e25040980",
"target_ref": "domain-name--80ffe91c-3a3c-450a-8cf7-6dd47fcd7072"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--89183394-9a69-46be-999f-118521070062",
"created": "2026-05-08T14:55:23.741Z",
"modified": "2026-05-08T14:55:23.741Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.account-next.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.741Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--cfb738f0-e0a2-4c5f-8682-40b11a4b2d2a",
"created": "2026-05-08T14:55:23.741Z",
"modified": "2026-05-08T14:55:23.741Z",
"relationship_type": "based-on",
"source_ref": "indicator--89183394-9a69-46be-999f-118521070062",
"target_ref": "domain-name--d55c2760-6f63-4228-9d33-987a519fda0a"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--186178b1-0251-467a-b185-218db858fc28",
"created": "2026-05-08T14:55:23.759Z",
"modified": "2026-05-08T14:55:23.759Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'jjuangco.ddns.net']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.759Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--9ca024be-b1fc-4a7a-a12d-80d2a5a208c2",
"created": "2026-05-08T14:55:23.759Z",
"modified": "2026-05-08T14:55:23.759Z",
"relationship_type": "based-on",
"source_ref": "indicator--186178b1-0251-467a-b185-218db858fc28",
"target_ref": "domain-name--2f57b158-e2c7-4db9-9f40-b80afafd2d62"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--2d5953de-e767-4555-be85-efd552896be8",
"created": "2026-05-08T14:55:23.777Z",
"modified": "2026-05-08T14:55:23.778Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'uyhb4rz7vcph6j.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.778Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--b08a5303-a212-44fb-a95a-938f80b47caa",
"created": "2026-05-08T14:55:23.778Z",
"modified": "2026-05-08T14:55:23.778Z",
"relationship_type": "based-on",
"source_ref": "indicator--2d5953de-e767-4555-be85-efd552896be8",
"target_ref": "domain-name--391ac3cf-a457-45da-b2ce-42b96918eabc"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c320b2fd-1972-4746-9959-032903ccf1f8",
"created": "2026-05-08T14:55:23.797Z",
"modified": "2026-05-08T14:55:23.797Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.mohimjo.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.797Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--73773b7f-04e2-45b1-819e-89cbc0bbcdc3",
"created": "2026-05-08T14:55:23.797Z",
"modified": "2026-05-08T14:55:23.797Z",
"relationship_type": "based-on",
"source_ref": "indicator--c320b2fd-1972-4746-9959-032903ccf1f8",
"target_ref": "domain-name--9ba644e6-8d5b-44de-8410-0ee596bbe47b"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--930c6000-68ca-41f6-8ffb-a9450d2a661f",
"created": "2026-05-08T14:55:23.813Z",
"modified": "2026-05-08T14:55:23.813Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.shimmeringlight.ir']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.813Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--8d8b3d20-e976-461b-b0b7-b695f1cb2572",
"created": "2026-05-08T14:55:23.813Z",
"modified": "2026-05-08T14:55:23.813Z",
"relationship_type": "based-on",
"source_ref": "indicator--930c6000-68ca-41f6-8ffb-a9450d2a661f",
"target_ref": "domain-name--976696e7-8a15-405c-8174-3339573aa204"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--31aadb97-e8c8-4a7e-8a8c-74017b8dd1dd",
"created": "2026-05-08T14:55:23.829Z",
"modified": "2026-05-08T14:55:23.829Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'mi.cuenta.amazon.es.dsgaradcollegemohol.online']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.829Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--95552b18-461f-4ed5-a515-6704e0809b70",
"created": "2026-05-08T14:55:23.829Z",
"modified": "2026-05-08T14:55:23.829Z",
"relationship_type": "based-on",
"source_ref": "indicator--31aadb97-e8c8-4a7e-8a8c-74017b8dd1dd",
"target_ref": "domain-name--418ce282-95bf-4b4b-bfe2-6bb15a40d24c"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--0af750d9-370a-4045-8e93-1f03bb62583b",
"created": "2026-05-08T14:55:23.844Z",
"modified": "2026-05-08T14:55:23.844Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'seeking0support.ddns.net']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.844Z",
"labels": [
"malicious-activity"
],
"confidence": 80
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--99116855-694e-4585-bdd8-7628932e80c2",
"created": "2026-05-08T14:55:23.844Z",
"modified": "2026-05-08T14:55:23.844Z",
"relationship_type": "based-on",
"source_ref": "indicator--0af750d9-370a-4045-8e93-1f03bb62583b",
"target_ref": "domain-name--9f1fc006-128c-4a35-aff9-1189f46f3a6e"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3f41a446-df69-4d61-944f-753010cbee01",
"created": "2026-05-08T14:55:23.862Z",
"modified": "2026-05-08T14:55:23.862Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.dsgaradcollegemohol.online']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.862Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--68e9a820-33fc-46bb-bada-998ac016e66f",
"created": "2026-05-08T14:55:23.862Z",
"modified": "2026-05-08T14:55:23.862Z",
"relationship_type": "based-on",
"source_ref": "indicator--3f41a446-df69-4d61-944f-753010cbee01",
"target_ref": "domain-name--2d0ca9fe-8b44-4d7d-9f4d-6982043163c2"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--2c2f5b19-ea28-4578-b447-aa7968d94bca",
"created": "2026-05-08T14:55:23.879Z",
"modified": "2026-05-08T14:55:23.879Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'freeworldlike.tk']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.879Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--fccf5b4e-cc93-40fe-85e6-79c0d6423e69",
"created": "2026-05-08T14:55:23.879Z",
"modified": "2026-05-08T14:55:23.879Z",
"relationship_type": "based-on",
"source_ref": "indicator--2c2f5b19-ea28-4578-b447-aa7968d94bca",
"target_ref": "domain-name--27e6fd86-874b-4daf-b94e-88fb39f40a47"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e1815691-2274-4ff2-8bef-37478d267c47",
"created": "2026-05-08T14:55:23.894Z",
"modified": "2026-05-08T14:55:23.894Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.oksurls.info']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.894Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ddaebeb0-c877-44ab-b184-7e90addc0c15",
"created": "2026-05-08T14:55:23.894Z",
"modified": "2026-05-08T14:55:23.894Z",
"relationship_type": "based-on",
"source_ref": "indicator--e1815691-2274-4ff2-8bef-37478d267c47",
"target_ref": "domain-name--8206c595-f663-4051-b7ef-f6239a1c0636"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ee1b0ec0-f921-40db-8c67-b45b94f06fba",
"created": "2026-05-08T14:55:23.910Z",
"modified": "2026-05-08T14:55:23.910Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.vbzurls.info']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.910Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ecc67cda-e976-4b83-83e4-9125457dcfc6",
"created": "2026-05-08T14:55:23.910Z",
"modified": "2026-05-08T14:55:23.910Z",
"relationship_type": "based-on",
"source_ref": "indicator--ee1b0ec0-f921-40db-8c67-b45b94f06fba",
"target_ref": "domain-name--d0c82521-7ef2-4948-bfcb-4b1df6d7e798"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--71287744-8540-45b7-8507-910dd65a5358",
"created": "2026-05-08T14:55:23.925Z",
"modified": "2026-05-08T14:55:23.925Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'www.suncbi.com']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.925Z",
"labels": [
"malicious-activity"
],
"confidence": 70
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--2ae2adb9-0c9f-4213-a986-7fd443b8de3e",
"created": "2026-05-08T14:55:23.925Z",
"modified": "2026-05-08T14:55:23.925Z",
"relationship_type": "based-on",
"source_ref": "indicator--71287744-8540-45b7-8507-910dd65a5358",
"target_ref": "domain-name--45c5ea35-0cc1-44ca-ab7a-9f8b22a66250"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b47badd0-1be0-4d56-aa16-02cf0f545b8c",
"created": "2026-05-08T14:55:23.939Z",
"modified": "2026-05-08T14:55:23.939Z",
"name": "Malicious domain-name indicator",
"description": "Malicious domain-name identified in threat intelligence",
"pattern": "[domain-name:value = 'facaziki2.xyz']",
"pattern_type": "stix",
"valid_from": "2026-05-08T14:55:23.939Z",
"labels": [
"malicious-activity"
],
"confidence": 75
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ebf5e693-7ed0-43a1-bc34-e525db0f0201",
"created": "2026-05-08T14:55:23.939Z",
"modified": "2026-05-08T14:55:23.939Z",
"relationship_type": "based-on",
"source_ref": "indicator--b47badd0-1be0-4d56-aa16-02cf0f545b8c",
"target_ref": "domain-name--a571934d-b012-49a0-bc9b-3cc31e010e59"
}
]
}