-

4 Years. 1 Mission. And a whole lot of "Welcome123" passwords later…
January 4, 2026 Industry NewsIt’s hard to believe it has been four years since I first looked at the Vatican’s digital infrastructure and realized that while the Swiss Guard.
-

Meeting Intelligence Heist: Browser Extensions Target Zoom, Teams, WebEx & More
December 31, 2025 Malware & TTPsThreat Profile: DarkSpectre (The "Zoom Stealer" Campaign) DarkSpectre is a sophisticated, China-linked threat actor that has been quietly operating a massive corporate espionage campaign now.
-

New Strain: COOSEAGROUP (Beast Variant)
December 26, 2025 Malware & TTPsCOOSEAGROUP is a sophisticated ransomware strain newly identified by CYFIRMA and Trend Micro in late December 2025. Technical analysis confirms that this group is not.
-

Ransomware Operation: Interlock
December 24, 2025 Malware & TTPsDate: December 24, 2025 Source: CISA/FBI Joint Advisory (AA25-203A) Threat Level: Critical A new joint advisory from CISA and the FBI has shed light on.
-

New Threat Actor: LongNosedGoblin
December 23, 2025 Threat Actor AnalysisLongNosedGoblin is a newly documented Advanced Persistent Threat (APT) group aligned with Chinese state interests. First detailed by ESET research in December 2025, the group.
-

Threat Actor: Infy (Prince of Persia)
December 21, 2025 Threat Actor AnalysisInfy (also known as Prince of Persia) is a persistent Iranian nation-state threat actor active since at least 2007. After a period of apparent dormancy.
-

ShinyHunters & The "Com" Network (Mixpanel Supply Chain Attack)
December 20, 2025 Industry NewsOverview ShinyHunters, a notorious data-extortion group, has been confirmed as the threat actor behind the recent massive breaches of Pornhub and SoundCloud. This campaign was.
-

RAAS: VolkLocker (CyberVolk 2.x)
December 20, 2025 Malware & TTPsThreat Profile: VolkLocker VolkLocker (also tracked as CyberVolk 2.x) is a Golang-based Ransomware-as-a-Service (RaaS) platform operated by the pro-Russian/Indian hacktivist collective CyberVolk. While the group.
-

Threat Actor: Morpheus
December 20, 2025 Threat Actor AnalysisMorpheus is a newly identified ransomware group that launched its operations in late 2024, with activity surging in December 2025. Technical analysis confirms a definitive.
-

Threat Actor: Weaxor (aka Mallox Rebrand)
December 20, 2025 Threat Actor AnalysisWeaxor is the direct successor to the Mallox (TargetCompany/FARGO) ransomware operation. This rebranding represents a shift in TTPs, moving away from opportunistic MSSQL brute-forcing toward.

Shenouda.nl is the personal website of Joe Shenouda, a seasoned cybersecurity expert and CISO, dedicated to providing strategic insights into the global cyber threat landscape through threat intelligence analysis. The site features blog posts on current cyber incidents, such as data breaches, hacktivist activities, and geopolitical cyber conflicts, often mapping threats to frameworks like MITRE ATT&CK and offering defense recommendations. It serves as a resource for professionals in the field, combining Joe’s extensive experience in cyber defense with timely analyses of emerging threats.

