Dysphoria IoT Botnet Adopts Blockchain C2 After Law Enforcement Disruption
The Dysphoria IoT botnet has re-architected its command-and-control infrastructure using Ethereum and Solana blockchain name services and victim-relay mesh networks, directly responding to the March 2026 JackSkid disruption. Researchers report over 200,000 active bots sustaining near-daily DDoS campaigns against ISPs and communications infrastructure.
Flash Briefings
All briefings →Dysphoria IoT Botnet Adopts Blockchain C2 After Law Enforcement Disruption
The Dysphoria IoT botnet has re-architected its command-and-control infrastructure using Ethereum and Solana blockchain name services and victim-relay mesh networks, directly responding to the March 2026 JackSkid disruption. Researchers report over 200,000 active bots sustaining near-daily DDoS campaigns against ISPs and communications infrastructure.
PolinRider: North Korea Floods npm, Go and Chrome With 108 Malicious Packages
A North Korean supply chain campaign tracked as PolinRider has distributed 162 malicious release artifacts across 108 packages in npm, Packagist, Go modules, and Chrome extensions, using VS Code auto-run tasks and blockchain-based command-and-control to deliver credential-stealing malware.
CISA Updates Iranian PLC Advisory: Scope Expands to Schneider and Siemens
CISA advisory AA26-097a, updated July 22, now confirms Iranian-affiliated actors are targeting PLCs from Schneider Electric and Siemens alongside Rockwell Automation across US water, energy, and government sectors.
Craneware Breach: Hackers Steal Data from UK Billing Software Firm Serving Thousands of US Hospitals
UK healthcare billing software company Craneware has confirmed attackers exfiltrated a 'significant volume' of data including employee records, customer data, and partner information. Craneware's software is used by thousands of clinics, hospitals, and pharmacies across the United States.
Deep Analysis
All analysis →GodDamn / Hyadina -- The Beast Rebrand That Ships With a Microsoft-Signed EDR Killer
The threat actor Symantec tracks as Hyadina has run three successive ransomware families since 2022. The latest, GodDamn, arrives paired with PoisonX -- a kernel driver that carries a valid Microsoft signature and kills endpoint defences before encryption starts. This is not a BYOVD attack. The driver was built for this purpose, and then it got a legitimate certificate.
Star Blizzard: The FSB's Spearphishing Arm Targeting Civil Society and Government
Star Blizzard — also known as Callisto Group, COLDRIVER, and TA446 — is the FSB's persistent long-term access operation against politicians, journalists, academics, and NGOs. A deep dive into their TTPs, target profile, infrastructure, and defensive implications.
Linen Typhoon: APT27's SharePoint Zero-Days and the Return to North American Networks
Microsoft tracks APT27 as Linen Typhoon. In July 2026, the group is exploiting two SharePoint vulnerabilities — CVE-2025-49706 and CVE-2025-49704 — against North American telecommunications and government targets. Active since 2010, this group's tools, patience, and institutional knowledge make it one of the most capable Chinese-attributed actors operating against Western targets.
Commentary
All commentary →Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality
Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.
The Agentic Attack Surface: Your AI Assistant Is the New Endpoint
Enterprise AI assistants now hold privileged access to code repositories, cloud credentials, internal APIs, and production systems. Security teams are not monitoring them. This is a structural blind spot with material consequences — and it's arriving faster than most organisations realise.
The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting
Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.