Data Provider
- Indexed articles, last 90 days
- 12
- Latest publication
- Sep 28, 2026
- Outlet visibility, for Circleid
- Top 5M sites
- Earliest in this view
- Jul 6, 2026
Latest articles
Jewelbug Targets the Middle East and Asia via Cyber Espionage and Crypto Fraud Campaigns (opens the original)
Read excerpt
Security.com recently published an analysis of a China-based hackers-for-hire group Jewelbug espionage con crypto fraud campaign that trailed their sights on victims across the Middle East and Asia. The attackers administered both campaigns from a single control panel. And as of publishing, the group’s victim database recorded 1 million+ implant check-ins and 580K+ stolen browser cookies in less than three months of active operations. The researchers publicized 27 network IoCs comprising 10 subd
DNS Footprinting: SourTrade Distributes Unfinished Malware through Malvertising (opens the original)
Read excerpt
Confiant recently reported on a campaign where threat actors distributed unfinished malware through SourTrade malvertisements in a bid to defeat file fingerprinting, the most widely used security detection technique today. Active since late 2024, SourTrade has become known for mimicking TradingView, Solana, and Luno to go after retail traders and crypto investors. The researchers listed 96 network IoCs—all domain names— connected to the threat. We analyzed them all after learning that none were
DNS Spotlight: 2026’s 5 Most Notorious Ransomware (opens the original)
Read excerpt
The Swiss Cyber Institute named the most notorious ransomware as of April 2026. We zoomed into five of them—LockBit, Cl0p, Akira, Medusa, and Qilin—in a bid to know more about their network IoCs and identify new artifacts. Since the report did not go into detail about the malware’s IoCs, we obtained them from the sources enumerated below instead. We collated a total of 85 network IoCs from the five sources above. After extracting domains from the subdomain IoCs and filtering out those that belon
A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign (opens the original)
Read excerpt
ReversingLabs uncovered a device code phishing campaign that abused Microsoft 365’s legitimate OAuth 2.0 Device Authorization Grant flow to access victims’ accounts. Instead of stealing passwords using a counterfeit login page, the attackers persuaded victims to complete a legitimate authentication process that authorized an attacker-controlled device. The researchers listed hundreds of URLs as network IoCs for the attack. We cleaned up the list of IoCs aided by the WhoisXML API MCP Server by ex
5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive (opens the original)
Read excerpt
CRN recently named the biggest cyber attacks and breaches the world has seen so far in 2026, and we zoomed in on five of them. We specifically tackled the attacks below. We collated network IoCs comprising subdomains, domains, and IP addresses from the sources identified above. Note that we extracted some domains from the subdomain IoCs then filtered out those that were owned by legitimate companies aided by the WhoisXML API MCP Server and one that was on the Tor network. After that, we ended up
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
Top 5M sites
For Circleid, the outlet · Measured Aug 1, 2026
Website popularity band, not a count of readers or article views.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.