Threat Intelligence Blog
Research, insights, and updates from the isMalicious team.
CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server
A deserialization flaw in the agent polling protocol gives attackers TeamCity server privileges without credentials. JetBrains patched in 2025.11.7 and 2026.1.3 — CISA KEV and a 3-day federal deadline mean hunt now, not after the next release train.
CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes
A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.
isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack
Talos reputation is excellent and it lives inside Cisco products. If your stack is not Cisco, or you need an API rather than a web form, that is where the comparison starts.
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.
Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data
A Cl0p affiliate is chaining a FlexPLM information disclosure with an unauthenticated RCE in PTC Windchill to plant JSP web shells and run double-extortion data theft. Here are the detection signals and the triage workflow.
SSO Vishing And SaaS Data Theft: Domain Monitoring Before The Helpdesk Call
ShinyHunters-style SSO vishing shows how fake login domains, MFA enrollment abuse, and SaaS access can become data theft. Domain monitoring gives defenders early warning.
Mobile Smishing Defense: URL Scanners And Domain Reputation For July 2026
Mobile phishing keeps gaining operational relevance. Security teams need URL scanning, domain reputation checks, DNS pivots, and employee reporting workflows built for SMS and chat.
Shadow AI Data Leak Defense: Monitor Domains, URLs, And Unsanctioned AI Apps
Shadow AI has become a governance and data leakage issue. Security teams need discovery, DNS visibility, sanctioned app controls, and domain monitoring around AI tool usage.
Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows
Anthropic mapped AI-enabled cyber activity to MITRE ATT&CK and found gaps around autonomous orchestration. SOC teams need AI summaries tied to evidence, not unsupported verdicts.

Shadow AI Governance: How Security Teams Can Detect Risk Without Blocking Innovation
Shadow AI is the new shadow IT: fast adoption, weak visibility, and serious data leakage risk. Security teams need discovery, domain intelligence, policy, training, and monitoring.

MCP Security Risks: Tool Poisoning, Prompt Injection, and the New AI Agent Attack Surface
Model Context Protocol integrations give agents access to tools, files, and services. That power creates new risks: tool poisoning, prompt injection, overbroad permissions, and untrusted server abuse.

Security LLM and Agent Workflows: When (and How) to Check Malicious Domains, IPs, and URLs Before Acting
AI assistants in SOAR, IDEs, and browser extensions can exfiltrate data or run malicious code if they fetch the wrong link. This guide gives guardrails: schema for tool calls, policy tiers, and where threat intelligence checks belong in the loop.

Brand Impersonation and Lookalike Domains: A Practical Monitoring Playbook for Security, Legal, and Fraud Teams
Typosquats and homoglyphs are cheap to register and expensive to ignore. Learn how to discover, prioritize, and remove lookalike infrastructure before it harvests credentials or poisons your customers’ trust in search and email.

EPSS Explained: Using the Exploit Prediction Scoring System to Prioritize Patches in 2026
A practical guide to the Exploit Prediction Scoring System (EPSS)—how it works, how it complements CVSS and KEV, and how security teams can use EPSS probabilities to prioritize vulnerability management at scale.

IP and Domain Intelligence: Building a Proactive Cyber Threat Defense
Reactive security leaves organizations perpetually one step behind attackers. Learn how combining IP and domain intelligence transforms your security posture from reactive incident response to proactive threat prevention that stops attacks before they start.

Domain Lookup: How to Identify Malicious Websites Before They Strike
Malicious websites are the launchpad for phishing, malware distribution, and credential theft. Learn how domain lookup tools use reputation data, WHOIS analysis, and threat feeds to identify dangerous domains before your users click.

Steganography: Hiding Secrets in Plain Sight
Steganography hides data within innocent-looking files like images or audio. Learn how hackers use digital steganography to smuggle malware and steal data.

Botnets Explained: Is Your Computer Part of a Zombie Army?
Botnets are networks of infected devices controlled by cybercriminals. Find out how they work, what they do, and how to check if your IP is involved.

How Hackers Use "Typosquatting" to Trick You (and How to Spot It)
Typosquatting relies on your fingers slipping. Learn how attackers register look-alike domains to steal your data and how to check URLs before you click.

Is Your Email Leaking Data? How to Check Email Reputation
Learn why email reputation matters for security and deliverability, and how to check if an email address is compromised or malicious.

Why Your SaaS Needs to Block Disposable Email Addresses Immediately
Disposable and temporary email addresses can enable fraud, spam, and abuse. Learn how disposable-domain detection supports account controls and sender reputation.

Biometric Spoofing: Defeating Authentication in an AI World
Are fingerprints and facial recognition truly secure? We explore the techniques attackers use to spoof biometric sensors, from 3D-printed faces to synthetic voice cloning.

AbuseIPDB Alternative: IP Reputation, Domain, and URL Coverage
AbuseIPDB is strong for IP reputation, but it does not cover domains and URLs. Compare AbuseIPDB and isMalicious across coverage, API features, pricing, enrichment, and monitoring.
Expert Threat Intelligence Analysis
Our blog features in-depth analysis from our threat research team. Each article is backed by real data from our analysis of millions of malicious domains, IPs, and URLs across the global threat landscape. Topics include ransomware campaigns, phishing techniques, malware distribution networks, and emerging threat trends. We publish specific intelligence that security teams can immediately use to improve their defenses.
Practical Security Guidance
Beyond threat analysis, we share practical guidance for security practitioners. Our tutorials cover API integration, SIEM configuration, threat hunting techniques, and building effective threat intelligence programs. Whether you're a SOC analyst, security engineer, or CISO, you'll find content tailored to your role and experience level.
Stay Ahead of Emerging Threats
The threat landscape evolves constantly. Our blog keeps you informed about the latest attack techniques, newly discovered vulnerabilities, and emerging threat actors. Subscribe to our newsletter for weekly digests of the most important developments in cybersecurity.
Subscribe to Our Newsletter
Weekly threat intelligence insights delivered to your inbox.