https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026
Supply Chain Attacks Surge in March 2026 | ThreatLabz
March 2026 supply chain incidents hit Axios and LiteLLM, enabling RAT delivery and credential theft, lateral movement, and long-term persistence.
supply chain attacksmarch 2026surgethreatlabz
https://www.zscaler.com/es/blogs/security-research/spike-danabot-malware-activity
DanaBot Activity | ThreatLabz
Two large software supply chain attacks distributed the DanaBot malware. DanaBot is a malware-as-a-service platform that focuses credential theft.
danabotactivitythreatlabz
https://www.zscaler.com/br/blogs/security-research/ai-now-default-enterprise-accelerator-takeaways-threatlabz-2026-ai-security
AI is Now Default Enterprise Accelerator: Takeaways from ThreatLabz 2026 AI Security Report |...
Enterprise AI activity surged 83% in 2025. Get the key takeaways from Zscaler ThreatLabz research and analysis of nearly 1 trillion AI/ML transactions.
is nowenterprise accelerator
https://www.zscaler.com/de/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz
CVE-2024-38856 | ThreatLabz
CVE-2024-38856 targets the override view functionality, enabling attackers to gain unauthorized access to endpoints by utilizing a request crafted with special...
cve2024threatlabz
https://www.zscaler.com/blogs/security-research/operation-endgame-2-0-danabusted
Operation Endgame 2.0: DanaBusted | ThreatLabz
operation endgame2 0threatlabz
https://www.zscaler.com/fr/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/br/blogs/security-research/brief-history-smokeloader-part-1
SmokeLoader History | ThreatLabz
Part 1 | A technical analysis of SmokeLoader changes through the years.
smokeloaderhistorythreatlabz
https://www.zscaler.com/es/author/threatlabz
ThreatLabz | Zscaler Blog
Content authored by ThreatLabz on Zscaler's blog. Leading voices in cloud security and secure digital transformation.
threatlabzzscalerblog
https://www.zscaler.com/jp/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/blogs/security-research/technical-analysis-copybara
Technical Analysis of Copybara | ThreatLabz
technical analysisthreatlabz
https://www.zscaler.com/blogs/security-research/kimsuky-deploys-translatext-target-south-korean-academia
Kimsuky Deploys TRANSLATEXT Chrome Extension |ThreatLabz
ThreatLabz observed Kimsuky targeting South Korean entities with TRANSLATEXT to steal email addresses, passwords, cookies, and capturing browser activity.
chrome extensionkimsukydeploysthreatlabz
https://www.zscaler.com/blogs/security-research/steal-it-campaign
Steal-It Campaign | ThreatLabz
stealcampaignthreatlabz
https://www.zscaler.com/es/blogs/security-research/black-hat-seo-leveraged-distribute-malware
Black Hat SEO Leveraged to Distribute Malware | ThreatLabz
Learn how threat actors exploit search engine results and create fake sites on web hosting platforms to distribute malware.
black hat seoleverageddistributemalwarethreatlabz
https://www.zscaler.com/br/blogs/security-research/technical-analysis-xloader-versions-6-and-7-part-1
Technical Analysis of Xloader Versions 6 and 7 P1 | ThreatLabz
Technical analysis of Xloader versions 6 and 7 Part 1 | Labyrinthian obfuscation and encryption techniques to evade detection and hinder analysis
technical analysis6 andversions7p1
https://www.zscaler.com/blogs/security-research/unveiling-revc2-and-venom-loader
Unveiling RevC2 and Venom Loader | ThreatLabz
unveilingvenomloaderthreatlabz
https://www.zscaler.com/mx/blogs/security-research/onenote-growing-threat-malware-distribution
OneNote | ThreatLabz
Zscaler ThreatLabz team observed multiple OneNote malware campaign spreading RATs, Bankers, and Stealer category malware with multi-layer obfuscation.
onenotethreatlabz
https://www.zscaler.com/jp/blogs/security-research/operation-endgame-2-0-danabusted
Operation Endgame 2.0: DanaBusted | ThreatLabz
operation endgame2 0threatlabz
https://www.zscaler.com/jp/blogs/security-research/generative-ai-5-enterprise-predictions-ai-and-security-2023-2024-and-beyond
Generative AI Enterprise Predictions | ThreatLabz
Get insight into enterprise generative AI predictions for security and AI based on exclusive ThreatLabz research
generative ai enterprisepredictionsthreatlabz
https://www.zscaler.com/resources/2023-threatlabz-state-of-encrypted-attacks-report
ThreatLabz 2023 State of Encrypted Attacks Report - Zscaler
Discover the latest insights on encrypted threats with the Zscaler ThreatLabz 2023 State of Encrypted Attacks Report.
state ofthreatlabz2023encryptedattacks
https://www.zscaler.com/jp/blogs/security-research/react2shell-remote-code-execution-vulnerability-cve-2025-55182
React2Shell RCE Vulnerability (CVE-2025-55182) | ThreatLabz
CVE-2025-55182 is a critical React flaw that allows attackers to execute code remotely and without authentication using a malicious HTTP POST request.
rce vulnerabilityreact2shellcve2025threatlabz
https://www.zscaler.com/es/blogs/security-research/brief-history-smokeloader-part-1
SmokeLoader History | ThreatLabz
Part 1 | A technical analysis of SmokeLoader changes through the years.
smokeloaderhistorythreatlabz
https://www.zscaler.com/jp/blogs/security-research/black-hat-seo-leveraged-distribute-malware
Black Hat SEO Leveraged to Distribute Malware | ThreatLabz
Learn how threat actors exploit search engine results and create fake sites on web hosting platforms to distribute malware.
black hat seoleverageddistributemalwarethreatlabz
https://www.zscaler.com/br/blogs/security-research/generative-ai-5-enterprise-predictions-ai-and-security-2023-2024-and-beyond
Generative AI Enterprise Predictions | ThreatLabz
Get insight into enterprise generative AI predictions for security and AI based on exclusive ThreatLabz research
generative ai enterprisepredictionsthreatlabz
https://www.zscaler.com/blogs/security-research/dynamic-approaches-seen-avemaria-s-distribution-strategy
AveMaria's Distribution Strategy | ThreatLabz
Talks about 7 case studies that follow provide an in-depth analysis of the AveMaria infostealer attack chain and how it has been shifting over the past 6 months
distribution strategyavemariathreatlabz
https://www.zscaler.com/es/blogs/security-research/introducing-devopt-multifunctional-backdoor-arsenal
DevOpt | ThreatLabz
Zscaler ThreatLabz has recently unearthed a new backdoor 'Devopt'. It utilizes hard-coded names for persistence and offers several functionalities.
threatlabz
https://www.zscaler.com/fr/blogs/security-research/beyond-inbox-threatlabz-2025-phishing-report-reveals-how-phishing-evolving
2025 Phishing Report | ThreatLabz
Discover the latest phishing trends from Zscaler ThreatLabz. Learn what are the top phishing targets and how to protect your organization.
2025phishingreportthreatlabz
https://www.zscaler.com/es/blogs/security-research/phishing-typosquatting-and-brand-impersonation-trends-and-tactics
Typosquatting & Brand Impersonation | ThreatLabz
brand impersonationtyposquattingthreatlabz
https://www.zscaler.com/mx/blogs/security-research/cve-2025-24813-apache-tomcat-vulnerable-rce-attacks
CVE-2025-24813: Apache Tomcat Vulnerability | ThreatLabz
Learn about CVE-2025-24813, an Apache Tomcat vulnerability enabling remote code execution (RCE). Update to the latest version to prevent exploitation.
apache tomcat vulnerabilitycve2025threatlabz
https://www.zscaler.com/fr/blogs/security-research/react2shell-remote-code-execution-vulnerability-cve-2025-55182
React2Shell RCE Vulnerability (CVE-2025-55182) | ThreatLabz
CVE-2025-55182 is a critical React flaw that allows attackers to execute code remotely and without authentication using a malicious HTTP POST request.
rce vulnerabilityreact2shellcve2025threatlabz
https://www.zscaler.com/fr/author/threatlabz
ThreatLabz | Zscaler Blog
Content authored by ThreatLabz on Zscaler's blog. Leading voices in cloud security and secure digital transformation.
threatlabzzscalerblog
https://www.zscaler.com/de/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google
Anatsa Campaign Technical Analysis | ThreatLabz
Explore how Anatsa distributes Android malware by using PDF and QR code reader decoys to lure victims through the Google Play store.
technical analysisanatsacampaignthreatlabz
https://www.zscaler.com/it/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/fr/blogs/security-research/technical-analysis-xloader-versions-6-and-7-part-1
Technical Analysis of Xloader Versions 6 and 7 P1 | ThreatLabz
Technical analysis of Xloader versions 6 and 7 Part 1 | Labyrinthian obfuscation and encryption techniques to evade detection and hinder analysis
technical analysis6 andversions7p1
https://www.zscaler.com/de/blogs/security-research/beyond-inbox-threatlabz-2025-phishing-report-reveals-how-phishing-evolving
2025 Phishing Report | ThreatLabz
Discover the latest phishing trends from Zscaler ThreatLabz. Learn what are the top phishing targets and how to protect your organization.
2025phishingreportthreatlabz
https://www.zscaler.com/es/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/mx/blogs/security-research/unveiling-revc2-and-venom-loader
Unveiling RevC2 and Venom Loader | ThreatLabz
unveilingvenomloaderthreatlabz
https://www.zscaler.com/blogs/security-research/smokeloader-rises-ashes
Technical Analysis of SmokeLoader Version 2025 | ThreatLabz
Two new SmokeLoader versions have been identified that fix significant bugs as well as introduce additional measures to evade static and behavior based...
technical analysissmokeloaderversion2025threatlabz
https://www.zscaler.com/blogs/security-research/technical-analysis-latest-variant-valleyrat
New Updates to ValleyRAT | ThreatLabz
Technical analysis of a new ValleyRAT campaign | New updates include device fingerprinting and desktop screen capturing
new updatesthreatlabz
https://www.zscaler.com/de/blogs/security-research/black-hat-seo-leveraged-distribute-malware
Black Hat SEO Leveraged to Distribute Malware | ThreatLabz
Learn how threat actors exploit search engine results and create fake sites on web hosting platforms to distribute malware.
black hat seoleverageddistributemalwarethreatlabz
https://www.zscaler.com/br/blogs/security-research/phishing-typosquatting-and-brand-impersonation-trends-and-tactics
Typosquatting & Brand Impersonation | ThreatLabz
brand impersonationtyposquattingthreatlabz
https://www.zscaler.com/de/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/campaign/threatlabz-data-at-risk-report
Zscaler ThreatLabz 2025 Data@Risk Report
AI is a major source of data loss. Uncover key data loss trends and best practices across AI, SaaS, email, file-sharing tools, and more in this ThreatLabz...
data riskzscalerthreatlabz2025report
https://www.zscaler.com/blogs/security-research/unraveling-raspberry-robin-s-layers-analyzing-obfuscation-techniques-and
Raspberry Robin Analysis | ThreatLabz
raspberryrobinanalysisthreatlabz
https://www.zscaler.com/br/blogs/security-research/deepseek-lure-using-captchas-spread-malware
DeepSeek Lure Used To Spread Malware | ThreatLabz
Malicious actors are already creating fraudulent DeepSeek look-alike sites to spread malware using CAPTCHAs.
used todeepseeklurespreadmalware
https://www.zscaler.com/jp/resources/2023-threatlabz-state-of-encrypted-attacks-report
ThreatLabz 2023 State of Encrypted Attacks Report - Zscaler
Discover the latest insights on encrypted threats with the Zscaler ThreatLabz 2023 State of Encrypted Attacks Report.
state ofthreatlabz2023encryptedattacks
https://www.zscaler.com/jp/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz
CVE-2024-38856 | ThreatLabz
CVE-2024-38856 targets the override view functionality, enabling attackers to gain unauthorized access to endpoints by utilizing a request crafted with special...
cve2024threatlabz
https://www.zscaler.com/de/blogs/security-research/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-51467
CVE-2023-51467 | ThreatLabz
Critical CVE-2023-51467 found in Apache OFBiz reveals authentication bypass flaw with a CVSS score of 9.8 allowing for SSRF exploitation.
cve2023threatlabz
https://www.zscaler.com/it/blogs/security-research/threatlabz-ai-security-report-key-findings
AI in the Enterprise: Key Findings from the ThreatLabz 2025 AI Security Report | Zscaler
Get key findings from the ThreatLabz 2025 AI Security Report. Learn how enterprises can secure AI/ML adoption and stop AI-related threats.
ai inthe enterprisekey findings
https://www.zscaler.com/blogs/security-research/generative-ai-5-enterprise-predictions-ai-and-security-2023-2024-and-beyond
Generative AI Enterprise Predictions | ThreatLabz
Get insight into enterprise generative AI predictions for security and AI based on exclusive ThreatLabz research
generative ai enterprisepredictionsthreatlabz
https://www.zscaler.com/de/blogs/security-research/technical-analysis-hijackloader
HijackLoader | ThreatLabz
HijackLoader | Learn its tactics, evasion techniques, and modular architecture in our in-depth analysis.
threatlabz
https://www.zscaler.com/es/blogs/security-research/ransomware-redefined-redenergy-stealer-ransomware-attacks
RedEnergy Stealer | ThreatLabz
Zscaler has discovered a new malware variant, RedEnergy stealer that fits into the hybrid Stealer-as-a-Ransomware threat category.
stealerthreatlabz
https://www.zscaler.com/it/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google
Anatsa Campaign Technical Analysis | ThreatLabz
Explore how Anatsa distributes Android malware by using PDF and QR code reader decoys to lure victims through the Google Play store.
technical analysisanatsacampaignthreatlabz
https://www.zscaler.com/mx/author/threatlabz
ThreatLabz | Zscaler Blog
Content authored by ThreatLabz on Zscaler's blog. Leading voices in cloud security and secure digital transformation.
threatlabzzscalerblog
https://www.zscaler.com/br/blogs/security-research/black-hat-seo-leveraged-distribute-malware
Black Hat SEO Leveraged to Distribute Malware | ThreatLabz
Learn how threat actors exploit search engine results and create fake sites on web hosting platforms to distribute malware.
black hat seoleverageddistributemalwarethreatlabz
https://www.zscaler.com/br/blogs/security-research/shining-light-dark-angels-ransomware-group
Dark Angels Exposed | ThreatLabz
Exposing the Dark Angels ransomware group TTPs, including the use of 3rd-party ransomware families and data extortion to secure millions of dollars in payments.
dark angelsexposedthreatlabz
https://www.zscaler.com/blogs/security-research/multiple-vulnerabilities-found-connectwise-screenconnect
ScreenConnect Vulnerabilities | ThreatLabz
Attackers are exploiting multiple vulnerabilities to upload malicious payloads and execute remote code on select versions of ConnectWise ScreenConnect.
screenconnectvulnerabilitiesthreatlabz
https://www.zscaler.com/es/blogs/security-research/technical-analysis-hijackloader
HijackLoader | ThreatLabz
HijackLoader | Learn its tactics, evasion techniques, and modular architecture in our in-depth analysis.
threatlabz
https://www.zscaler.com/it/blogs/security-research/react2shell-remote-code-execution-vulnerability-cve-2025-55182
React2Shell RCE Vulnerability (CVE-2025-55182) | ThreatLabz
CVE-2025-55182 is a critical React flaw that allows attackers to execute code remotely and without authentication using a malicious HTTP POST request.
rce vulnerabilityreact2shellcve2025threatlabz
https://www.zscaler.com/blogs/security-research/bunnyloader-newest-malware-service
BunnyLoader | ThreatLabz
BunnyLoader features rapid iterations, anti-sandbox tactics, second-stage payload executions, keylogging, stealing capabilities, and remote execution.
threatlabz
https://www.zscaler.com/br/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz
CVE-2024-38856 | ThreatLabz
CVE-2024-38856 targets the override view functionality, enabling attackers to gain unauthorized access to endpoints by utilizing a request crafted with special...
cve2024threatlabz
https://www.zscaler.com/br/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/fr/blogs/security-research/black-hat-seo-leveraged-distribute-malware
Black Hat SEO Leveraged to Distribute Malware | ThreatLabz
Learn how threat actors exploit search engine results and create fake sites on web hosting platforms to distribute malware.
black hat seoleverageddistributemalwarethreatlabz
https://www.zscaler.com/blogs/security-research/malicious-npm-packages-deliver-nodecordrat
Malicious NPM Packages Deliver NodeCordRAT | ThreatLabz
ThreatLabz identified malicious NPM packages that deliver NodeCordRAT, which performs credential theft and steals cryptocurrency wallet data.
npm packagesmaliciousdeliverthreatlabz
https://www.zscaler.com/fr/blogs/security-research/onenote-growing-threat-malware-distribution
OneNote | ThreatLabz
Zscaler ThreatLabz team observed multiple OneNote malware campaign spreading RATs, Bankers, and Stealer category malware with multi-layer obfuscation.
onenotethreatlabz
https://www.zscaler.com/blogs/security-research/supply-chain-risk-python-termncolor-and-colorinal-explained
Termncolor and Colorinal Explained | ThreatLabz
ThreatLabz examines how termncolor and colorinal, malicious Python packages, expose supply chain risks via DLL sideloading, persistence, and covert C2...
explainedthreatlabz
https://www.zscaler.com/it/blogs/security-research/phishing-attacks-rise-58-year-ai-threatlabz-2024-phishing-report
Phishing Attacks Rise: ThreatLabz 2024 Phishing Report | Zscaler
Protect your organization against the latest phishing threats with insights and guidance from the Zscaler ThreatLabz 2024 Phishing Report.
phishing attacksrisethreatlabz2024report
https://www.zscaler.com/jp/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google
Anatsa Campaign Technical Analysis | ThreatLabz
Explore how Anatsa distributes Android malware by using PDF and QR code reader decoys to lure victims through the Google Play store.
technical analysisanatsacampaignthreatlabz
https://www.zscaler.com/de/blogs/security-research/react2shell-remote-code-execution-vulnerability-cve-2025-55182
React2Shell RCE Vulnerability (CVE-2025-55182) | ThreatLabz
CVE-2025-55182 is a critical React flaw that allows attackers to execute code remotely and without authentication using a malicious HTTP POST request.
rce vulnerabilityreact2shellcve2025threatlabz
https://www.zscaler.com/mx/blogs/security-research/latest-xloader-obfuscation-methods-and-network-protocol
Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz
Xloader version 8 continues to implement new code obfuscation techniques to hinder reverse engineering and defeat automated analysis tools.
latestobfuscationcodec2protocol
https://www.zscaler.com/it/blogs/security-research/ransomware-surges-extortion-escalates-threatlabz-2025-ransomware-report
Ransomware Surges, Extortion Escalates: ThreatLabz 2025 Ransomware Report | Zscaler
Ransomware is surging amid more data extortion, new groups, and evolving tactics. Get 5 key takeaways from the Zscaler ThreatLabz 2025 Ransomware Report.
ransomwaresurgesextortionthreatlabz2025
https://www.zscaler.com/blogs/security-research/2022-cloud-security-report
2022 Cloud (In)Security Report | ThreatLabz
Discover the latest insights and risks revealed by ThreatLabz on the current state of cloud security and learn how to reduce your risk.
in security2022cloudreportthreatlabz
https://www.zscaler.com/blogs/security-research/zloader-no-longer-silent-night
Zloader Analysis | ThreatLabz
Technical analysis of Zloader 2.1.7.0 | Updates include new obfuscation, RSA encryption, modifications to the DGA and a 64-bit loader module
analysisthreatlabz
https://www.zscaler.com/blogs/security-research/tropic-trooper-pivots-adaptixc2-and-custom-beacon-listener
Tropic Trooper: AdaptixC2 + Custom Beacon | ThreatLabz
ThreatLabz details Tropic Trooper using a trojanized SumatraPDF to deploy AdaptixC2 via GitHub C2, then pivoting to VS Code tunnels for remote access.
tropictroopercustombeaconthreatlabz
https://www.zscaler.com/it/blogs/security-research/new-vpn-risk-report-56-enterprises-attacked-vpn-vulnerabilities
Report del 2024 di Zscaler ThreatLabz sui rischi delle VPN
Report sui rischi VPN di Zscaler ThreatLabz 2024 con Cybersecurity Insiders.
reportdel2024dizscaler
https://www.zscaler.com/blogs/security-research/payouts-king-takes-aim-ransomware-throne
Payouts King Takes Aim at the Ransomware Throne | ThreatLabz
Former BlackBasta initial access brokers are conducting new attacks; stealing large amounts of data, and selectively deploying Payouts King ransomware.
at thepayoutskingtakesaim
https://www.zscaler.com/mx/blogs/security-research/introducing-devopt-multifunctional-backdoor-arsenal
DevOpt | ThreatLabz
Zscaler ThreatLabz has recently unearthed a new backdoor 'Devopt'. It utilizes hard-coded names for persistence and offers several functionalities.
threatlabz
https://www.zscaler.com/es/blogs/security-research/threatlabz-ai-security-report-key-findings
AI in the Enterprise: Key Findings from the ThreatLabz 2025 AI Security Report | Zscaler
Get key findings from the ThreatLabz 2025 AI Security Report. Learn how enterprises can secure AI/ML adoption and stop AI-related threats.
ai inthe enterprisekey findings
https://www.zscaler.com/es/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google
Anatsa Campaign Technical Analysis | ThreatLabz
Explore how Anatsa distributes Android malware by using PDF and QR code reader decoys to lure victims through the Google Play store.
technical analysisanatsacampaignthreatlabz
https://www.zscaler.com/es/blogs/security-research/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-51467
CVE-2023-51467 | ThreatLabz
Critical CVE-2023-51467 found in Apache OFBiz reveals authentication bypass flaw with a CVSS score of 9.8 allowing for SSRF exploitation.
cve2023threatlabz
https://www.zscaler.com/fr/blogs/security-research/agniane-stealer-dark-web-s-crypto-threat
Agniane Stealer | ThreatLabz
Unearth the malevolent Agniane Stealer: a dark web malware targeting sensitive data and crypto intel. Explore its threats in our report.
stealerthreatlabz
https://www.zscaler.com/blogs/security-research/coverage-advisory-cve-2023-47246-sysaid-zero-day-vulnerability
CVE-2023-47246 | ThreatLabz
ThreatLabz weighs in on CVE-2023-47246 SysAid Zero-Day Vulnerability, and provides recommendations and best practices
cve2023threatlabz
https://www.zscaler.com/it/blogs/security-research/hibernating-qakbot-comprehensive-study-and-depth-campaign-analysis
Hibernating Qakbot | ThreatLabz
Throughout this article, we delve into the intricacies of Qakbot's attack chains, encryption methods, and its wide geographical reach.
hibernatingqakbotthreatlabz
https://www.zscaler.com/mx/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz
CVE-2024-38856 | ThreatLabz
CVE-2024-38856 targets the override view functionality, enabling attackers to gain unauthorized access to endpoints by utilizing a request crafted with special...
cve2024threatlabz
https://www.zscaler.com/mx/blogs/security-research/black-hat-seo-leveraged-distribute-malware
Black Hat SEO Leveraged to Distribute Malware | ThreatLabz
Learn how threat actors exploit search engine results and create fake sites on web hosting platforms to distribute malware.
black hat seoleverageddistributemalwarethreatlabz
https://www.zscaler.com/es/blogs/security-research/cve-2024-38856-pre-auth-rce-vulnerability-apache-ofbiz
CVE-2024-38856 | ThreatLabz
CVE-2024-38856 targets the override view functionality, enabling attackers to gain unauthorized access to endpoints by utilizing a request crafted with special...
cve2024threatlabz
https://www.zscaler.com/blogs/security-research/threatlabz-discovers-117-vulnerabilities-microsoft-365-apps-sketchup-3d-part-2
Vulnerabilities in Microsoft 365 Apps | ThreatLabz
Explore the hidden vulnerabilities lurking in Microsoft 365 Apps due to the SketchUp 3D file format in Part 2 of this two-part series.
microsoft 365vulnerabilitiesappsthreatlabz
https://www.zscaler.com/fr/resources/2023-threatlabz-state-of-encrypted-attacks-report
ThreatLabz 2023 State of Encrypted Attacks Report - Zscaler
Discover the latest insights on encrypted threats with the Zscaler ThreatLabz 2023 State of Encrypted Attacks Report.
state ofthreatlabz2023encryptedattacks
https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37
APT37 | ThreatLabz
An operational security failure by the North Korean threat actor - APT37, led to the discovery of many previously unknown tools and techniques used by them
threatlabz
https://www.zscaler.com/blogs/security-research/tweaks-stealer-targets-roblox-users-through-youtube-and-discord
Roblox Users Targeted with Tweaks Malware | ThreatLabz
Threat actors target Roblox gamers with Tweaks malware lures on YouTube and Discord
robloxuserstargetedtweaksmalware
https://www.zscaler.com/mx/blogs/security-research/hibernating-qakbot-comprehensive-study-and-depth-campaign-analysis
Hibernating Qakbot | ThreatLabz
Throughout this article, we delve into the intricacies of Qakbot's attack chains, encryption methods, and its wide geographical reach.
hibernatingqakbotthreatlabz
https://www.zscaler.com/jp/blogs/security-research/steal-it-campaign
Steal-It Campaign | ThreatLabz
stealcampaignthreatlabz
https://www.zscaler.com/br/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google
Anatsa Campaign Technical Analysis | ThreatLabz
Explore how Anatsa distributes Android malware by using PDF and QR code reader decoys to lure victims through the Google Play store.
technical analysisanatsacampaignthreatlabz
https://www.zscaler.com/fr/blogs/security-research/exploring-encrypted-attacks-amidst-ai-revolution
2023 Encrypted Attacks Report | ThreatLabz
Explore how encrypted attacks are evolving during the AI revolution | Safeguard your digital landscape with ThreatLabz insights and best practices
2023encryptedattacksreportthreatlabz
https://www.zscaler.com/mx/blogs/security-research/generative-ai-5-enterprise-predictions-ai-and-security-2023-2024-and-beyond
Generative AI Enterprise Predictions | ThreatLabz
Get insight into enterprise generative AI predictions for security and AI based on exclusive ThreatLabz research
generative ai enterprisepredictionsthreatlabz
https://www.zscaler.com/es/blogs/security-research/steal-it-campaign
Steal-It Campaign | ThreatLabz
stealcampaignthreatlabz
https://www.zscaler.com/fr/blogs/security-research/introducing-devopt-multifunctional-backdoor-arsenal
DevOpt | ThreatLabz
Zscaler ThreatLabz has recently unearthed a new backdoor 'Devopt'. It utilizes hard-coded names for persistence and offers several functionalities.
threatlabz
https://github.com/ThreatLabz/ransomware_notes
GitHub - ThreatLabz/ransomware_notes: An Archive of Ransomware Notes Past and Present Collected by...
An Archive of Ransomware Notes Past and Present Collected by Zscaler ThreatLabz - ThreatLabz/ransomware_notes
past and present
https://www.zscaler.com/blogs/security-research/inside-zloader-s-latest-trick-dns-tunneling
Technical Analysis of Zloader 2.9.4.0 | ThreatLabz
Discover how Zloader 2.9.4.0 implemented a custom DNS tunneling protocol combined with TLS encryption to evade network detection.
technical analysis2 94 0threatlabz
https://www.zscaler.com/it/blogs/security-research/nevada-ransomware-yet-another-nokoyawa-variant
Nevada Ransomware, Nokoyawa Variant | ThreatLabz
There are significant code similarities between Nevada and Nokoyawa ransomware including debug strings, command-line arguments and encryption algorithms
nevadaransomwarenokoyawavariantthreatlabz
https://www.zscaler.com/jp/blogs/security-research/introducing-devopt-multifunctional-backdoor-arsenal
DevOpt | ThreatLabz
Zscaler ThreatLabz has recently unearthed a new backdoor 'Devopt'. It utilizes hard-coded names for persistence and offers several functionalities.
threatlabz