Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs

September 09, 2026 | Serhii Melnyk and Timmy Lister

Hunter

Stay Informed

Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.

Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader

August 28, 2026 | Serhii Melnyk

This is a collaborative follow-up to our original post, developed jointly with ...

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

August 25, 2026 | Nikita Kazymirskyi

A cyber incident affecting a small UK electricity generator in July 2026 ...

Release the RAVEN: Destruction and Discipline

August 18, 2026 | Karl Biron

In Part 4, we stole every document from every index, planted a rogue superuser ...

Release the RAVEN: Data Heist and Persistence

August 14, 2026 | Karl Biron

We have access through port 9200. We have code execution through port 5601. ...

Release the RAVEN: Kibana Under Siege

August 13, 2026 | Karl Biron

In Parts 1 and 2, every command targeted port 9200. Every exploit, every ...

Beyond ‘Fake Updates’: From Application Store-Themed Phishing to Large-Scale Distribution of ScreenConnect

August 07, 2026 | King Orande and Cris Tomboc

The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign ...

Release the RAVEN: Exploiting the Cracks

August 06, 2026 | Karl Biron

In Part 1, we went from a single open port to a complete map of the target. ...

Release the RAVEN: First Contact

August 05, 2026 | Karl Biron

You are mid-engagement. Nmap finishes its sweep and port 9200 lights up on a ...

Release the RAVEN: An Offensive Reconnaissance and Attack Tool on Vulnerable Elasticsearch Nodes

July 29, 2026 | Karl Biron

You have almost certainly interacted with Elasticsearch today. The search bar ...

LegacyHive: Hunting Windows Profile Initialization Abuse Through Offline Registry Manipulation

July 27, 2026 | Serhii Melnyk and Timmy Lister

Following GreenPlasma, YellowKey and MiniPlasma, as well as RoguePlanet and ...

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop

July 21, 2026 | Serhii Melnyk

Coordinated vulnerability disclosures operate on a straightforward premise: the ...

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

July 20, 2026 | Pauline Bolaños

Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and ...

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

July 16, 2026 | Rodel Mendrez

You're browsing a legitimate small business website. Before the page loads, a ...

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

July 09, 2026 | Nathaniel Morales

The LevelBlue Managed Threat Research team investigated a security alert in a ...

LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

June 24, 2026 | Dawid Nesterowicz

In Norse mythology, Loki, the god of mischief, has powerful and deceptive ...

Operation FlutterBridge: The FlutterShell macOS Backdoor

June 18, 2026 | Maor Gabay

Identified through macOS endpoint monitoring, the CL-CRI-1089 cluster, ...

Reversing NVIDIA’s CVE-2026-24190: How a Kernel Flaw Put Enterprise AI Clusters and Workstations at Risk

June 15, 2026 | Alon Bancic

Executive Summary: Bypassing Boundaries in Enterprise AI Infrastructure The ...

The Device Code Phishing Tsunami: What We’re Seeing in the Wild

June 09, 2026 | John Kevin Adriano

With contributions from Cris Tomboc.

macOS ClickFix Social Engineering Campaigns

June 04, 2026 | Maor Gabay

Overview The "ClickFix" threat landscape has undergone a significant ...

The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP

June 03, 2026 | Jose Martin

In Brazil, Nota Fiscal eletrônica (NF-e) is the everyday name for an official ...

Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign

May 28, 2026 | Maor Gabay

We recently observed a multi-stage macOS intrusion campaign conducted by the ...

From WinRE to SYSTEM: Hunting CVE-2026-45585 Exploitation and the MiniPlasma Attack Chain

May 22, 2026 | Serhii Melnyk

Since April 2026, LevelBlue SpiderLabs’ Cyber Threat Intelligence team has ...

YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled

May 19, 2026 | James Ballantyne

Two novel Windows zero-day vulnerabilities dubbed YellowKey, which bypasses ...

Inside Vect Ransomware-as-a-Service

April 30, 2026 | SpiderLabs Researcher

Vect ransomware, a new group that emerged in January 2026, has recently begun ...

Hacking Hotels via Smart Stationary Bikes: How Unsecured Gym Equipment Can Lead to RCE

April 29, 2026 | John Lopez

Internet of Things (IoT) systems in hospitality environments are often ...

Go With the Flow: Abusing OAuth Device Code Flow

April 20, 2026 | Jakub Wiewiorski

In early 2026, phishing attacks are still among the top contributors to the ...

RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait

April 17, 2026

A newly disclosed zero-day vulnerability, dubbed RedSun, is raising fresh ...