NSFOCUS Monthly APT Insights – March 2026

NSFOCUS Monthly APT Insights – March 2026

Regional APT Threat Situation In March 2026, the global threat hunting system of Fuying Lab detected a total of 31 APT attack activities. These activities were primarily concentrated in regions including South ...

30 Cybersecurity Search Engines Every Researcher Should Bookmark

A curated, categorised guide to 30 search engines that security researchers actually use: Shodan, Censys, Dehashed, ExploitDB, and the rest ...
Operation Saffron: Bitdefender Joins “First VPN” Takedown

Operation Saffron: Bitdefender Joins “First VPN” Takedown

An international law enforcement operation led by France and the Netherlands dismantled First VPN, a cybercriminal anonymization service used by ransomware actors, fraudsters, and data thieves across every major cybercrime investigation Europol ...
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer

SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer

Executive summary Financially motivated eCrime actors will likely continue to expand opportunistic campaigns by impersonating AI platforms. These campaigns generate direct supply chain risk for enterprises, as threat actors target software developer ...
Threat Detection and Response Platforms: A Modern Enterprise Guide to Faster, Smarter Cyber Defense

Threat Detection and Response Platforms: A Modern Enterprise Guide to Faster, Smarter Cyber Defense

Cyber threats are evolving faster than most organizations can respond. Modern enterprises face an increasingly complex threat landscape driven by ransomware, nation-state attacks, insider threats, cloud misconfigurations, supply chain risks, and AI-assisted ...
FamousSparrow APT Targets Azerbaijani Oil and Gas Industry

FamousSparrow APT Targets Azerbaijani Oil and Gas Industry

I'd like to thank my co-author, Martin Zugec, for his valuable contributions to this report ...
Footer-for-Blogs-3

Beyond the Perimeter: Detecting Suspicious Cloud Activity and Unauthorized External Communications 

As organizations continue accelerating digital transformation and cloud adoption, cyber threats are increasingly targeting users, cloud platforms, and outbound communications instead of traditional infrastructure alone. Modern attackers no longer rely solely on ...
Footer-for-Blogs-3

Global Cyber Threat Outlook 2026: Rising Infrastructure Attacks

Introduction The global cyber threat landscape continues to evolve as threat actors intensify attacks against critical infrastructure, telecommunications providers, defense organizations, and enterprise environments worldwide. Recent campaigns demonstrate how modern adversaries are ...
NSFOCUS Included in the Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies

NSFOCUS Included in the Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies

SANTA CLARA, Calif., May 13, 2026 – On May 4, 2026, Gartner® published the Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies report (hereinafter referred to as “the Report”). NSFOCUS was included in the ...