Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Mandiant Blog

18 articles

Mandiant Blog Campaigns Google Intel Nov 5

GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools

Executive Summary Based on recent analysis of the broader threat landscape, Google Threat Intelligence Group (GTIG) has identified a shift that occurred with...

Mandiant Blog →

Mandiant Blog General Nov 4

Preparing for Threats to Come: Cybersecurity Forecast 2026

Every November, we make it our mission to equip organizations with the knowledge needed to stay ahead of threats we anticipate in the coming year. The Cybers...

Mandiant Blog →

Mandiant Blog General Oct 28

Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring

Written by: Bhavesh Dhake, Will Silverstone, Matthew Hitchcock, Aaron Fletcher The Criticality of Privileged Access in Today's Threat Landscape Privileged ac...

Mandiant Blog →

Mandiant Blog Phishing Google Intel Oct 23

Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials

Google Threat Intelligence Group (GTIG) is tracking a cluster of financially motivated threat actors operating from Vietnam that leverages fake job postings ...

T1566 T1204

Mandiant Blog →

Mandiant Blog General Google Intel Oct 21

Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace

Written by: Alden Wahlstrom, David Mainor Introduction Google Threat Intelligence Group (GTIG) observed multiple instances of pro-Russia information operatio...

Mandiant Blog →

Mandiant Blog Malware Oct 20

To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER

Written by: Wesley Shields Introduction COLDRIVER, a Russian state-sponsored threat group known for targeting high profile individuals in NGOs, policy adviso...

Mandiant Blog →

Mandiant Blog Campaigns Google Intel Oct 16

DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains

Written by: Blas Kojusner, Robert Wallace, Joseph Dobson Google Threat Intelligence Group (GTIG) has observed the North Korea (DPRK) threat actor UNC5342 usi...

Mandiant Blog →

Mandiant Blog Campaigns Google Intel WordPress Oct 16

New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware

Written by: Mark Magee, Jose Hernandez, Bavi Sadayappan, Jessa Valdez Since late 2023, Mandiant Threat Defense and Google Threat Intelligence Group (GTIG) ha...

Mandiant Blog →

Mandiant Blog Zero-Day Google Oracle Intel Oct 9

Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign

Written by: Peter Ukhanov, Genevieve Stark, Zander Work, Ashley Pearson, Josh Murchie, Austin Larsen Update (Oct. 11): On Oct.

1 IOC

Mandiant Blog →

Mandiant Blog Advisory Salesforce Sep 30

Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations

Written by: Omar ElAhdan, Matthew McWhirt, Michael Rudden, Aswad Robinson, Bhavesh Dhake, Laith Al, Ravi Kumar Raja Update (Nov. 21): In response to the Sale...

Mandiant Blog →

Mandiant Blog Malware Google Intel Sep 24

Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors

Written by: Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen I...

Mandiant Blog →

Mandiant Blog Zero-Day Sep 3

ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690)

Written by: Rommel Joven, Josh Fleischer, Joseph Sciuto, Andi Slok, Choon Kiat Ng Update (September 3): This post was updated to include information about Go...

2 IOCs

Mandiant Blog →

Mandiant Blog General Salesforce Aug 26

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift

Written by: Austin Larsen, Matt Lin, Tyler McLellan, Omar ElAhdan Update (August 28) Based on new information identified by GTIG, the scope of this compromis...

T1041

Mandiant Blog →

Mandiant Blog Malware Aug 20

A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor

Written by: Marco Galli Welcome to the Frontline Bulletin Series Straight from Mandiant Threat Defense, the "Frontline Bulletin" series brings you the latest...

Mandiant Blog →

Mandiant Blog General VMware Broadcom Jul 23

Beyond Convenience: Exposing the Risks of VMware vSphere Active Directory Integration

Written by: Stuart Carrera, Brian Meyer Executive Summary Broadcom's VMware vSphere product continues to be a top choice for private cloud virtualization, un...

Mandiant Blog →

Mandiant Blog Campaigns Google VMware Intel Jul 23

From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC3944

Introduction In mid 2025, Google Threat Intelligence Group (GTIG) identified a sophisticated and aggressive cyber campaign targeting multiple industries, inc...

T1598

Mandiant Blog →

Mandiant Blog Campaigns Google SonicWall Intel Jul 16

Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor

Written by: Josh Goddard, Zander Work, Dimiter Andonov UPDATE (Sep 16): Clarified hunting guidance specifics surrounding ld.so.

Mandiant Blog →

Mandiant Blog Ransomware Jul 7

Isolated Recovery Environments: A Critical Layer in Modern Cyber Resilience

Written by: Jaysn Rye Executive Summary As adversaries grow faster, stealthier, and more destructive, traditional recovery strategies are increasingly insuff...

Mandiant Blog →

«Previous page 1 2
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA