Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs
September 09, 2026 | Serhii Melnyk and Timmy Lister
Stay Informed
Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.
Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader
August 28, 2026 | Serhii Melnyk
This is a collaborative follow-up to our original post, developed jointly with ...
Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat
August 25, 2026 | Nikita Kazymirskyi
A cyber incident affecting a small UK electricity generator in July 2026 ...
Release the RAVEN: Destruction and Discipline
August 18, 2026 | Karl Biron
In Part 4, we stole every document from every index, planted a rogue superuser ...
Release the RAVEN: Data Heist and Persistence
August 14, 2026 | Karl Biron
We have access through port 9200. We have code execution through port 5601. ...
Release the RAVEN: Kibana Under Siege
August 13, 2026 | Karl Biron
In Parts 1 and 2, every command targeted port 9200. Every exploit, every ...
Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect
August 07, 2026 | King Orande and Cris Tomboc
The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...
Release the RAVEN: Exploiting the Cracks
August 06, 2026 | Karl Biron
In Part 1, we went from a single open port to a complete map of the target. ...
Release the RAVEN: First Contact
August 05, 2026 | Karl Biron
You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...
Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes
July 29, 2026 | Karl Biron
You have almost certainly interacted with Elasticsearch today. The search bar ...
LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation
July 27, 2026 | Serhii Melnyk and Timmy Lister
Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and ...
Exploitarium: Inside the Archive Behind the Mass 0-Day Drop
July 21, 2026 | Serhii Melnyk
Coordinated vulnerability disclosures operate on a straightforward premise: the ...
LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC
July 20, 2026 | Pauline Bolaños
Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 | Rodel Mendrez
You're browsing a legitimate small business website. Before the page loads, a ...
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
July 09, 2026 | Nathaniel Morales
The LevelBlue Managed Threat Research team investigated a security alert in a ...
LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign
June 24, 2026 | Dawid Nesterowicz
In Norse mythology, Loki, the god of mischief, has powerful and deceptive ...
Operation FlutterBridge: The FlutterShell macOS Backdoor
June 18, 2026 | Maor Gabay
Identified through macOS endpoint monitoring, the CL-CRI-1089 cluster, ...
Reversing NVIDIA’s CVE-2026-24190: How a Kernel Flaw Put Enterprise AI Clusters and Workstations at Risk
June 15, 2026 | Alon Bancic
Executive Summary: Bypassing Boundaries in Enterprise AI Infrastructure The ...
The Device Code Phishing Tsunami: What We’re Seeing in the Wild
June 09, 2026 | John Kevin Adriano
With contributions from Cris Tomboc.
macOS ClickFix Social Engineering Campaigns
June 04, 2026 | Maor Gabay
Overview The "ClickFix" threat landscape has undergone a significant ...
The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP
June 03, 2026 | Jose Martin
In Brazil, Nota Fiscal eletrônica (NF-e) is the everyday name for an official ...
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
May 28, 2026 | Maor Gabay
We recently observed a multi-stage macOS intrusion campaign conducted by the ...
From WinRE to SYSTEM: Hunting CVE-2026-45585 Exploitation and the MiniPlasma Attack Chain
May 22, 2026 | Serhii Melnyk
Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has ...
YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled
May 19, 2026 | James Ballantyne
Two novel Windows zero-day vulnerabilities dubbed YellowKey, which bypasses ...
Inside Vect Ransomware-as-a-Service
April 30, 2026 | SpiderLabs Researcher
Vect ransomware, a new group that emerged in January 2026, has recently begun ...
Hacking Hotels via Smart Stationary Bikes: How Unsecured Gym Equipment Can Lead to RCE
April 29, 2026 | John Lopez
Internet of Things (IoT) systems in hospitality environments are often ...
Go With the Flow: Abusing OAuth Device Code Flow
April 20, 2026 | Jakub Wiewiorski
In early 2026, phishing attacks are still among the top contributors to the ...
RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait
April 17, 2026
A newly disclosed zero-day vulnerability, dubbed RedSun, is raising fresh ...