Product
Suspicious Activity: Multiple Remote Management Tool Vendors on Same Host
1 TTPThis brief describes a behavioral detection for Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tools from different vendors are observed starting processes within an eight-minute window, indicating potential compromise, shadow IT, or attacker staging of redundant access.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
MuddyWater Disguises Cyber-Espionage as Chaos Ransomware Attack
2 rules 5 TTPsThe MuddyWater group is disguising its cyber-espionage operations as Chaos ransomware attacks, using Microsoft Teams social engineering for initial access and establishing persistence, likely to complicate attribution and mask their true objectives.
Supply Chain Compromises via Npm, PyPI Packages and Teams Phishing Campaigns
3 rules 3 TTPsThe April 2026 Red Canary Intelligence Insights highlights the axios npm compromise, TeamPCP's LiteLLM compromise via PyPI, and a surge in Microsoft Teams phishing, leading to RAT deployment, credential harvesting, ransomware deployment, or data theft.