

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
CVE-2023-44487: New HTTP/2 "Rapid Reset" Sets DDoS Record
In a pivotal coordinated disclosure, giants AWS, Cloudflare, and Google unveiled a groundbreaking DDoS attack stemming from a vulnerability in the HTTP/2 protocol, termed as the "HTTP/2 rapid reset" attack. Recorded in August and September 2023, these attacks shattered prior records of Layer 7 DDoS attacks. The most extensive incident hit Google with 398 million requests per second. At the core of this exploit is the HTTP/2 feature allowing multiplexing of multiple logical connections over one HTTP session.
WS_FTP Server Exploit with a Familiar Attack Chain
Sophos X-Ops on Mastodon has reported that Progress Software's WS_FTP Server software is currently facing active exploitation due to the .NET Deserialization vulnerability, CVE-2023-40044. This high-risk vulnerability, graded 10/10 by the vendor, was addressed with a hotfix in September 2023. Despite the fix, Sophos's analysis reveals attackers employing familiar patterns, leveraging the IIS component and delivering malicious payloads to deploy ransomware. Shockingly, the ransomware in question seems to be derived from the leaked Lockbit 3.0 source code.
"Stayin’ Alive" Campaign Targets Government & Telecom Organizations in Asia Since 2021
Check Point Research has been monitoring an ongoing cyber campaign named "Stayin' Alive", active since at least 2021. Primarily targeting telecommunications and government sectors in Asian countries like Vietnam, Uzbekistan, Kazakhstan, and Pakistan, the campaign employs basic tools with the primary goal of downloading and executing additional payloads. Spear-phishing emails delivering archive files are common initial attack vectors, even exploiting known vulnerabilities.
CISA Updates #StopRansomware Advisory for AvosLocker
The FBI and CISA, in a joint Cybersecurity Advisory, provide an updated deep dive into the operations of the AvosLocker ransomware gang, a Ransomware-as-a-Service entity active as of May 2023. AvoLockers targets multiple critical infrastructure sectors in the U.S., encompassing Windows, Linux, and VMware ESXi systems. They employ a plethora of legitimate software and open-source tools, ranging from remote administration to custom webshells. Known for their double-extortion tactics, AvosLocker uses tools like Cobalt Strike, Lazagne, Mimikatz, FileZilla, and more.
Ukraine Braces Defense on Power Grid Amist Winter Season
As winter looms, Ukraine is intensifying efforts to protect its already vulnerable energy infrastructure from further threats. Following the Russian invasion in 2022, the country witnessed extensive damage to its power stations, missile attacks, and an ever-present risk of cyberattacks. The Economist reports a significant 51% reduction in power-generating capacity in April 2023, compared to pre-invasion levels.
FBI Alerts Public of Increased 'phantom hacker' Scams
The FBI's recent public service announcement draws attention to the escalating "Phantom Hacker" scam, a refined version of tech support scams. Through a layered approach, impersonating tech support, bank agents, and government officials, attackers deceive victims into installing remote access software and transferring funds to scammer-controlled accounts.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)