Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
Critical Infrastructure in Israel Under Siege from Cyberattacks
Israel is experiencing a surge in cyberattacks targeting critical infrastructure, including water systems, airlines, and transportation. On April 9, 2023, cyberattacks caused malfunctions in water monitors and disrupted irrigation systems. Pro-Palestinian hacktivist group GhostSec is suspected, but involvement remains unconfirmed. Authorities are working to restore affected systems amid ongoing threats.
FTC: Warns of Family Scams Enabled by AI-Enhancements
The FTC warns consumers about AI-enhanced family scams using voice cloning to mimic distressed family members in emergency situations. Victims are deceived into giving up money based on the convincing AI-generated voices. The FTC advises verifying the story by contacting the family member directly or corroborating with others.
Beware of RCE Vulnerability in MSMQ SERVICE
A critical RCE vulnerability (CVE-2023-21554), dubbed QueueJumper, in Microsoft MSMQ service has been patched. Check Point Research found it can be exploited with one packet to port 1801/tcp, affecting over 360,000 IPs. Administrators should verify if MSMQ is installed and apply the necessary patches immediately.
Lazarus Group Unleashed 'DeathNote' Campaign on Defense Industry and Cryptocurrency Targets
The Lazarus Group's DeathNote campaign targets defense and cryptocurrency sectors with sophisticated malware. Utilizing weaponized documents and Trojanized applications, the campaign executes malware downloaders, conducts reconnaissance, and exfiltrates valuable data. The campaign has been active since 2020, expanding its techniques and target profile over time.
A Flaw in Azure's Shared Key Authorization Poses Risk to Cloud Security
Orca Security researchers discovered a 'by-design flaw' in Azure's Shared Key authorization, posing significant cloud security risks. The flaw enables attackers to manipulate storage accounts, steal access tokens, and execute remote code, compromising critical business assets. Despite acknowledging the issue, Microsoft has opted for updates instead of redesigning the system.
A Destructive Pairing with MuddyWater and DEV-1084
A collaboration between Iranian threat actor, MERCURY (aka MuddyWater) and threat actor Microsoft tracks as DEV-1084 has been observed. According to a report from the Microsoft Threat Intelligence team the two groups worked in tandem to compromise an on-premises and cloud environment.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
Trusted by leading teams at

.png)


