From One Vendor to Hundreds of Organizations: What a Turkish HR Provider Breach Reveals About Supply Chain Cyber Risk

Blog Executive Summary Baltas Eksen Seçme Değerlendirme Eğitim ve Org. Tic. A.Ş. (“Baltas”), a Turkish HR and executive assessment provider, officially disclosed a personal data breach to Türkiye’s Personal Data Protection Authority (KVKK). Shortly after, a threat actor surfaced on an underground forum claiming responsibility for the breach and asserting that data belonging to more […]
TeamPCP: How a Cloud Exploitation Group Evolved Into a Supply Chain Threat

Blog When TeamPCP emerged in late 2025, few recognized the threat actor that would eventually compromise over 1,000 organizations. What distinguishes this financially motivated cybercrime group isn’t cutting-edge technology but strategic evolution a calculated shift from opportunistic cloud exploitation to coordinated supply chain attacks that fundamentally challenged conventional security assumptions. From Cloud Mining to Supply […]
From Threat Intelligence to Action: ThreatMon and Binalyze Partner to Operationalize Cyber Threat Intelligence

Blog Threat intelligence creates value only when it helps security teams detect, investigate, and respond to threats faster. Organizations today consume large volumes of cyber threat intelligence, yet many still struggle to transform that intelligence into actionable detection and hunting content. Security teams often export indicators of compromise (IOCs), manually convert them into detection rules, […]
Inside wp2shell: How Two WordPress Core Bugs Became a Critical RCE Chain

Blog Analyzing CVE-2026-63030 and CVE-2026-60137 When WordPress quietly pushed emergency security updates on July 17, 2026, it wasn’t addressing just another isolated vulnerability. Instead, the patches closed two separate flaws that, when chained together, created something far more serious than either issue on its own. Researchers quickly began referring to the attack chain as wp2shell a […]
The Middle East’s Cyber Threat Picture in 2026: What 170 Incidents Tell Us

Blog If you only looked at the headline number, 2026 in the Middle East would seem like a fairly typical ransomware year. 170 ransomware and extortion incidents across 17 countries, most of them hitting manufacturing, healthcare, finance, and government. Criminals chasing money, in other words. Business as usual. But spend some time inside the data […]
What Was a 45-GPU Cracking Farm Built For?

Blog Most credential leaks are messy. Someone dumps a pile of raw data, half of it stale, and walks away. What ThreatMon’s research team pulled apart in June 2026 was the opposite: a clean, sorted, validated inventory of network access, put together by an operator who clearly knew what they were doing right up until […]
Why Would an Adversary Collect 74,000 FortiGate

Blog ThreatMon Analysis of a Global FortiGate Access Collection Operation Executive Summary In June 2026, security researcher Volodymyr “Bob” Diachenko disclosed the existence of a large dataset associated with internet-facing FortiGate deployments worldwide. The disclosure immediately attracted attention due to the scale of the exposed information and the number of organizations represented within the records. […]
Oil & Gas Under Siege: What the 2026 Cyber Threat Landscape Actually Looks Like

The pipelines keep running. The rigs keep drilling. But somewhere in the background, threat actors are quietly doing their own kind of work stealing credentials, probing control systems, and waiting for the right moment to pull the trigger on a ransomware payload. The 2026 threat intelligence picture for the oil and gas sector is not pretty, and if you’re involved in energy security, it deserves your full attention.
GitHub’s Source Code Is for Sale And They’ve Confirmed It

Blog GitHub’s Source Code Is for Sale And They’ve Confirmed It On May 19, 2026, a threat actor going by the handle TeamPCP posted a sale listing on the Breached cybercrime forum offering roughly 4,000 private GitHub repositories including the company’s core Rails application for a starting price of $50,000. By the time researchers caught […]
Seedworm Expands Operations with Stealth-Focused Espionage Campaign

Blog Seedworm Expands Operations with Stealth-Focused Espionage Campaign ThreatMon researchers identified a new espionage campaign linked to Seedworm, the Iran-aligned threat actor also known as MuddyWater and Static Kitten. The activity affected organizations across multiple industries, including manufacturing, finance, government, aviation, and education. The campaign shows a clear shift toward stealth and operational security. Instead […]