Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro
tags: report:trend_micro, report:unit42
tags: report:trend_micro, report:unit42
tags: report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. Thi
The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Unive
How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems
Deduped connector weight from graph context.