Blog
Threat Intel Weekly
One analyst write-up a week on the DDoS, ransomware, or application-security story that mattered most, with severity context and what it means for defenders.
Featured this week
NoName057(16) got hit by an international takedown in 2025. It came back 80% louder.
NoName057(16) is the most persistent pro-Russian DDoS operation running against NATO and Ukraine-aligned states — crowdsourced through Telegram, paid in crypto, and still expanding more than a year after Europol seized its servers. The data shows why a takedown alone didn't work.
Read the write-up ↗Archive
RBL Leviathan Ghost is racking up government targets across India and Indonesia. Its own proof mostly disagrees.
A pro-Palestine hacktivist collective is claiming defacements and DDoS hits against Indian and Indonesian government sites, and stitching together alliances with other named crews to look bigger while it does it. Its own check-host screenshots tell a quieter story.
N-able patched an N-central bug, attackers found a second way in, and this time it's already active
N-able's fix for an N-central auth-bypass bug closed one path but left another open. The follow-on flaw, CVE-2026-18577, is now being used to seize admin control of the RMM platform MSPs use to manage their customers' entire fleets.
Inside JadePuffer: the first ransomware operation run end-to-end by an AI agent
A large language model agent — not a human operator — ran the entire intrusion: recon, credential theft, lateral movement, privilege escalation, and encryption. Here's what changes for defenders when the attacker on the other end doesn't sleep.
The DOJ dismantled the botnet behind the largest DDoS on record. A new one was already for sale on Telegram.
A real win: US, Canadian, and German authorities took down four IoT botnets responsible for over 300,000 DDoS attacks. A month later, a stealthier DDoS-for-hire botnet targeting the same device pool was already advertising on Telegram — the vacancy didn't stay open long.
Inside the 31.4 Tbps attack: how 2 million hijacked Android TV boxes became the largest DDoS on record
Cloudflare disclosed the technical anatomy of the largest publicly recorded DDoS attack — 31.4 Tbps for 35 seconds, generated by a botnet built almost entirely from compromised, off-brand Android TV boxes. The record has already been climbing for months.