gametheory
[GAME THEORY] The Recruiter Was Also the Quartermaster
A new joint advisory links recruiter malware and some DPRK IT workers. Here is where to join hiring, access, and payment decisions.
gametheory
A new joint advisory links recruiter malware and some DPRK IT workers. Here is where to join hiring, access, and payment decisions.
weekly
Edge patching may close the hole but not remove access; this issue tracks service-principal abuse and integrator routes into OT.
forecasts
A 58% disclosure forecast—and the ownership test that matters before the next campaign is named.
deep
New NIST guidance exposes a containment gap: the revocation command can succeed while an attacker’s access survives.
weekly
The engineer called it internal; the attacker found it internet-adjacent. Inventory and patch exposed GS1900 and Conductor gear, then hunt job changes and secret access.
forecasts
Two incidents appear to clear the bar. Govern AI credentials by replay value and blast radius before access becomes impact.
deep research
A practical operating model for package admission, runtime detection, and proving downstream impact before the trail goes cold.
weekly
Patch the control plane, then hunt leaked authority: new admins, fresh tokens, API use from new origins. Copied keys can outlive a green patch dashboard.
gametheory
The attacker needs sustained, useful output. Defenders can turn that dependency into friction across the access ecosystem.
gametheory
Shared intrusion logistics can be a better chokepoint than one APT—if defenders can prove real control-plane dependence.
weekly
A Teams message from “IT” can now be the first step in a domain takeover: remote-support session, silent install, then AD and WinRM movement.
forecasts
Our 45% forecast—and the public signals that would show private cyber effects have moved from authority to action.