Product
high
threat
Toy Ghouls Deploying Custom GenieLocker Ransomware
1 rule 4 TTPs 1 IOCThe Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.
Windows +6
Toy Ghouls
ransomware
extortion
manufacturing
toy-ghouls
1r
4t
1i
high
advisory
Microsoft Security Updates — July 2026
10 CVEs 227 IOCsRoundup of Microsoft security advisories published in July 2026.
PoC
PowerShell +516
roundup
10c
227i
updated
medium
advisory
Suspicious Process Execution via Renamed PsExec Executable
2 rules 3 TTPsThe rule identifies suspicious PsExec activity where the psexec service is executed from a renamed executable, possibly to evade detection and enable lateral movement.
PsExec +1
lateral-movement
defense-evasion
windows
2r
3t