

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
Heightened Threat from Iranian State-Sponsored Hackers
A subgroup of the Iranian state-sponsored Magic Hound, tracked by Microsoft, is escalating data theft campaigns against high-value targets. These hackers rapidly weaponize new vulnerabilities and conduct sophisticated attacks using PowerShell scripts, Impacket, and custom implants. Their activities align with Iran's national priorities, targeting sectors like defense, energy, and government.
Critical Infrastructure in Israel Under Siege from Cyberattacks
Israel is experiencing a surge in cyberattacks targeting critical infrastructure, including water systems, airlines, and transportation. On April 9, 2023, cyberattacks caused malfunctions in water monitors and disrupted irrigation systems. Pro-Palestinian hacktivist group GhostSec is suspected, but involvement remains unconfirmed. Authorities are working to restore affected systems amid ongoing threats.
FTC: Warns of Family Scams Enabled by AI-Enhancements
The FTC warns consumers about AI-enhanced family scams using voice cloning to mimic distressed family members in emergency situations. Victims are deceived into giving up money based on the convincing AI-generated voices. The FTC advises verifying the story by contacting the family member directly or corroborating with others.
Beware of RCE Vulnerability in MSMQ SERVICE
A critical RCE vulnerability (CVE-2023-21554), dubbed QueueJumper, in Microsoft MSMQ service has been patched. Check Point Research found it can be exploited with one packet to port 1801/tcp, affecting over 360,000 IPs. Administrators should verify if MSMQ is installed and apply the necessary patches immediately.
Lazarus Group Unleashed 'DeathNote' Campaign on Defense Industry and Cryptocurrency Targets
The Lazarus Group's DeathNote campaign targets defense and cryptocurrency sectors with sophisticated malware. Utilizing weaponized documents and Trojanized applications, the campaign executes malware downloaders, conducts reconnaissance, and exfiltrates valuable data. The campaign has been active since 2020, expanding its techniques and target profile over time.
A Flaw in Azure's Shared Key Authorization Poses Risk to Cloud Security
Orca Security researchers discovered a 'by-design flaw' in Azure's Shared Key authorization, posing significant cloud security risks. The flaw enables attackers to manipulate storage accounts, steal access tokens, and execute remote code, compromising critical business assets. Despite acknowledging the issue, Microsoft has opted for updates instead of redesigning the system.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)