Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research, report:microsoft_mstic, report:trend_micro
tags: report:checkpoint_research, report:securityweek
tags: report:checkpoint_research, report:securityweek
tags: report:securityweek, report:talos
tags: report:securityweek, report:trend_micro
tags: report:checkpoint_research, report:securityweek
tags: report:checkpoint_research, report:securityweek
tags: report:talos, report:trend_micro
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Meet HoloTab by HCompany. Your AI browser companion. Meet HoloTab by HCompany. Your AI browser companion. Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Log In Sign Up Back to Articles Meet HoloTab by HCompany. Your AI browser companion. Team Article Pub
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from t
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, w
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives
Deduped connector weight from graph context.