Public Sector and Government
The Flashpoint Threat Intelligence Brief: Middle East
Flashpoint’s weekly analysis tracks shifting kinetic and cyber threat radiuses, geopolitical disruptions, and provides critical operational forecasts for the ongoing Middle East conflict.
Cyber Threat Intelligence
CastleStealer: An Emerging Infostealer Growing More Sophisticated
In this post, we analyze the evolution of CastleStealer, including the sensitive data it targets, new techniques for bypassing browser protections, remote command capabilities, and an approach to exfiltration designed to help stolen data blend into network traffic.
Cyber Threat Intelligence
AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communities
A monthly analysis of how artificial intelligence is used in illicit communities, based on Flashpoint proprietary intelligence and direct visibility into real threat actor environments.
Featured
Process Parameter Poisoning: Inside a Novel EDR Evasion Technique
In this post, Flashpoint analysts examine Process Parameter Poisoning—a novel EDR evasion technique we validated in Rust—and detail how abusing undocumented process parameters allows attackers to inject code and bypass standard security products.
Cyber Threat Intelligence
The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact
In this post we examine how modern hacktivism has evolved into a tool of global hybrid warfare, analyzing crowdsourced attack tactics, media-driven propaganda, and real-world impacts across Ukraine, the Middle East, European Union, and NATO nations.
Insider Threats
Insider Threat Report: Dark Web Recruitment & Access Trends
Flashpoint’s monthly analysis of insider threat recruitment, illicit access advertising, and threat actor activity targeting enterprise environments.
Corporate & Physical Security
Data Center Physical Security: Mitigating FPV Drone Threats
In this post, we explore how shifting online sentiment and low-cost First-Person View (FPV) technology are creating an unprecedented airborne threat vector for critical data center infrastructure.
Illicit Communities
Understanding Illicit Ecosystems: Inside Rehub’s Rise as a Primary Ransomware Marketplace
Flashpoint intelligence tracks Rehub, breaking down its migration, infrastructure, and the various RaaS groups sponsoring and partnering with it.
Ransomware
Inside Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer
In this post we analyze Qilin ransomware’s new custom Rust loader, break down the inner workings of its sophisticated kernel-level EDR killer, and explore how organizations can defend against these aggressive defense evasion tactics. Flashpoint customers can access the full intelligence report—complete with deeper technical analysis and all associated IOCs—directly within Flashpoint Ignite.
Cyber Threat Intelligence
Understanding Illicit Ecosystems: How Dark Web Forums Structure Cybercrime
In this post, we analyze how dark web forums operate, breaking down Flashpoint's tiered classification system and examining how specialized, hybrid platforms function together as an interconnected cybercrime supply chain.
Infostealer
Remus Stealer: A New, Not-So-New Infostealer
In this post, we explore the emergence of Remus Stealer, analyzing its structural and behavioral similarities to the infamous Lumma malware.
Corporate and Physical Security
America250 Fourth of July Threat Assessment
In this post we break down the intersecting cyber risks, physical security strains, and operational challenges shaping the security landscape for the historic Semiquincentennial celebrations.
