Triaging the Week 103

AI-coded malware, weaponized extensions, social engineering the help desk, and exploiting zero-days across critical infrastructure. All in this week's edition of triaging the week.

AI-coded malware, weaponized extensions, social engineering the help desk, and exploiting zero-days across critical infrastructure. All in this week's edition of triaging the week.

Learn how data engineering for CTI can transform your threat intelligence team from reactive to proactive. A complete guide with actions.

Quishing and Browser-in-the-Browser attacks steal credentials, exploitation of LLM services and automation platforms, a massive leak of BreachForums accounts, and urgent patches for Cisco and Fortinet in triaging the week 102.

State-sponsored espionage, active exploitation of critical vulnerabilities in legacy hardware and popular software, and new malware campaigns targeting cloud services and user credentials in triaging the week 101.

State-sponsored espionage using Windows Group Policy, new malware (SantaStealer, PyStoreRAT, DocSwap) distributed through phishing, fake GitHub repos, and compromised app stores in triaging the week 100.

Learn how FlowViz transforms threat reports into visual attack flows in seconds. Turn 40-page PDFs into MITRE ATT&CK-mapped diagrams with AI automation.

Active exploitation of the critical "React2Shell" vulnerability, malicious VSCode extensions target developers, and urgent security warnings for Fortinet, Ivanti, and Docker Hub users in triaging the week 099.

Critical supply chain vulnerabilities, compromised browser extensions, maximum-severity RCE flaws in React frameworks, and the rise of malicious AI models in triaging the week 098.
Discover why the Unified Kill Chain is the framework CTI analysts need. Learn how it fixes the Cyber Kill Chain's flaws and complements MITRE ATT&CK.

WhatsApp metadata exposure affecting 3.5 billion accounts, a critical Grafana admin takeover vulnerability, a foiled insider threat at CrowdStrike, and a third-party breach impacting OpenAI in triaging the week 097.
Learn what detection engineering is, why it's the hottest cyber security career in 2025, and how to transition from SOC analyst to detection engineer.

Automated AI cyberattacks, law enforcement actions against bulletproof hosting services, evolving threats from North Korean hackers, and new supply chain vulnerabilities in triaging the week 096.

Stop saying “fake news!” Learn how to classify information disorder professionally. A CTI analyst's guide to misinformation, disinformation, and malinformation.

Glassworm malware returns, critical container escape flaws in runC, a side-channel attack on encrypted AI chats called 'WhisperLeak', and malicious NuGet packages with "time bomb" payloads in triaging the week 095.

This CTI analyst roadmap turns chaos into clarity. It outlines the CTI learning resources, from SOC skills to strategic writing, to help you build your career.