Security insights andplatform updates
Product updates, security research, and launch announcements from the team.

Building certgrep.sh: a free certificate transparency search engine
The engineering story behind certgrep.sh. An occurrence-only index over certificate transparency, a finite state transducer engine that ran in production for three months, the regex-latency wall that ended it, and the trigram pivot that made the whole thing cheap enough to give away.

From fake interview to signed ClickOnce: inside a three-payload Windows chain
A fake Web3 interview delivered a signed ClickOnce stager on Windows that unpacked two credential stealers and a persistent Go RAT.

Announcing Site Canaries
Site Canaries detect cloned and phishing copies of a production page with a small embedded script, then report flagged hostnames alongside domain findings.

From typosquatting to macOS backdoor via ClickFix and blockchain C2
A macOS ClickFix campaign used typosquatting, clipboard-driven Terminal execution, persistent AppleScript, and a Polygon smart contract as a mutable C2 pointer for backdoor, stealer, RAT, and Ledger replacement modules.

When one RMM tool won't get the job done: inside a phishing operation's infrastructure
A packed carrier-onboarding dropper pulls NetSupport Manager from commodity VPS infrastructure. The same operator box also runs SimpleHelp and ScreenConnect, rotates fresh builds daily, and pivots lures from US carriers to European freight within 24 hours.

Announcing Email Intelligence for Microsoft 365
Email Intelligence ingests domain threat signals from Microsoft 365 mail into Have I Been Squatted lookups. Watchdog adds sender domain blocks in the tenant.

When a trusted trucking email delivers remote access
Attackers used what appears to be a compromised Microsoft 365 account at a US freight carrier, sent Bill of Lading phishing to business contacts, and used a PDF link to an S3-hosted EXE that silently installed a pre-configured N-able RMM agent.

Have I Been Squatted now integrates with Tines
Have I Been Squatted now integrates with Tines, so typosquat permutations, domain analysis data can run directly inside investigation stories.

Typosquatted domains were early signals in the Trivy and LiteLLM attacks
In the TeamPCP supply chain campaign, lookalike domains were registered and certified days before malicious commits shipped—public signals defenders can monitor for.

Diesel Vortex: Inside the Russian cybercrime group targeting US & EU freight
Diesel Vortex is a Russian phishing-as-a-service group targeting freight and logistics companies across the US and Europe. This report details the group's infrastructure, tactics, and the 1,600+ credentials stolen from DAT Truckstop, Penske, EFS and Timocom.

Announcing certgrep
Today we officially launch certgrep, our second free public tool for the security community.