Blog

Threat Intel Weekly

One analyst write-up a week on the DDoS, ransomware, or application-security story that mattered most, with severity context and what it means for defenders.

Aug 10 – Aug 16, 2026
Medium DDoS

RBL Leviathan Ghost is racking up government targets across India and Indonesia. Its own proof mostly disagrees.

A pro-Palestine hacktivist collective is claiming defacements and DDoS hits against Indian and Indonesian government sites, and stitching together alliances with other named crews to look bigger while it does it. Its own check-host screenshots tell a quieter story.

Jul 28 – Aug 3, 2026
Critical Vulnerabilities

N-able patched an N-central bug, attackers found a second way in, and this time it's already active

N-able's fix for an N-central auth-bypass bug closed one path but left another open. The follow-on flaw, CVE-2026-18577, is now being used to seize admin control of the RMM platform MSPs use to manage their customers' entire fleets.

Jul 21 – 27, 2026
Critical Ransomware

Inside JadePuffer: the first ransomware operation run end-to-end by an AI agent

A large language model agent — not a human operator — ran the entire intrusion: recon, credential theft, lateral movement, privilege escalation, and encryption. Here's what changes for defenders when the attacker on the other end doesn't sleep.

Apr 6 – Apr 12, 2026
High DDoS

The DOJ dismantled the botnet behind the largest DDoS on record. A new one was already for sale on Telegram.

A real win: US, Canadian, and German authorities took down four IoT botnets responsible for over 300,000 DDoS attacks. A month later, a stealthier DDoS-for-hire botnet targeting the same device pool was already advertising on Telegram — the vacancy didn't stay open long.

Jan 26 – Feb 1, 2026
Critical DDoS

Inside the 31.4 Tbps attack: how 2 million hijacked Android TV boxes became the largest DDoS on record

Cloudflare disclosed the technical anatomy of the largest publicly recorded DDoS attack — 31.4 Tbps for 35 seconds, generated by a botnet built almost entirely from compromised, off-brand Android TV boxes. The record has already been climbing for months.