From the field

Research & analysis.

Practical write-ups on breaches, vulnerabilities, and defensive security.

Law Firms Are Being Targeted Through Social Engineering and Data Extortion

A Google Cloud Mandiant report details an ongoing campaign against U.S. law firms and professional services organizations by a financially motivated group tracked as UNC3753 (also known as Luna Moth, Chatty Spider, and Silent Ransom Group). The attackers rely on invoice-themed emails, phone calls impersonating IT, screen sharing, and legitimate remote access tools to steal data and extort victims, sometimes in under a single business day.

Read article

Miasma Reaches Azure: A Warning Shot for Modern Software Supply Chains

The Miasma malware campaign reached Microsoft-linked GitHub repositories, including Azure-related projects, before GitHub disabled dozens of them. What stands out is the technique: instead of only abusing package installation, Miasma weaponized repository-level configuration files used by developer tools and AI coding assistants, a reminder that project configuration should be treated as executable code.

Read article

A Stock Exchange Espionage Campaign Shows Why Executive Mailboxes Are Prime Targets

A Symantec/Broadcom threat-intelligence report details a five-month espionage campaign against a senior executive at a major global stock exchange. Attackers maintained access from October 2025 to March 2026, exfiltrating mailbox data in small batches through personal cloud services while hiding malware inside legitimate-looking Adobe, OneDrive, and Lenovo software components.

Read article