- [2026.07.23]Crimeware Has an Attack Surface. We Catalogue It.
Standard threat-intelligence indexes malware by hash and family. Our Cyber Arsenal indexes the other thing — the vulnerabilities of the malware itself: the pre-auth RCE, the broken cookie validation, and the backdoors that the tools' own distributors wired into them. Over 40% of the commodity webshells and grabbers we catalogued are harvesting the operators who deploy them.
- [2026.06.24]FortiBleed from the Target Side: What Stops Them [Part 3/3]
Half the FortiBleed sprayer IPs — including several that successfully validated the admin account — carry a threat score of zero and appear on no abuse feed at all. The only rule that catches 100% of them is a management-interface allowlist. This is Part 3 of three: the defenses that work, why standard SOC rules miss this spray, the ASN-level indicators, and the timeline gap that is the real lesson. With a companion Detection Brief.
- [2026.06.24]FortiBleed Credential-Validation Spray: Detection Brief
SOC-ready companion to FortiBleed from the Target Side. The highest-signal detections for the credential-validation phase: off-allowlist admin auth, one source testing many usernames at a steady 24/7 cadence, a single success after a run of failures, and FortiGate service/cloud accounts appearing at the login prompt. TLP:CLEAR.