<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>ThreatPaper</title>
    <link>https://threatpaper.com</link>
    <description>Structured research on real-world cybercrime</description>
    <language>en</language>
    <lastBuildDate>Wed, 02 Sep 2026 10:45:36 GMT</lastBuildDate>
    <atom:link href="https://threatpaper.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title><![CDATA[3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise]]></title>
      <link>https://threatpaper.com/cases/3cx-supply-chain-attack-cve-2023-29059-the-first-cascading-software-compromise</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/3cx-supply-chain-attack-cve-2023-29059-the-first-cascading-software-compromise</guid>
      <pubDate>Wed, 02 Sep 2026 09:40:01 GMT</pubDate>
      <category><![CDATA[Supply Chain Attack, State-Sponsored]]></category>
      <description><![CDATA[A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Capital One Data Breach (2019)]]></title>
      <link>https://threatpaper.com/cases/capital-one-data-breach-2019</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/capital-one-data-breach-2019</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach]]></category>
      <description><![CDATA[In July 2019, Capital One Financial Corporation formally disclosed one of the most significant data breaches in the history of the financial services sector. The security incident resulted in the...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[RedLine Infostealer Malware-as-a-Service Operation and Operation Magnus Takedown]]></title>
      <link>https://threatpaper.com/cases/redline-infostealer-malware-as-a-service-operation-and-operation-magnu</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/redline-infostealer-malware-as-a-service-operation-and-operation-magnu</guid>
      <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Social Engineering, Identity Theft, Malware]]></category>
      <description><![CDATA[The transition of the global cyber threat landscape from traditional network intrusions to decentralized, identity-centric attacks is exemplified by the RedLine infostealer. First identified in March...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Chinese State-Sponsored QTFY Campaign: Disruption of QScan and QTRouter Hacking Platforms]]></title>
      <link>https://threatpaper.com/cases/chinese-state-sponsored-qtfy-campaign-disruption-of-qscan-and-qtrouter</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/chinese-state-sponsored-qtfy-campaign-disruption-of-qscan-and-qtrouter</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[State-Sponsored]]></category>
      <description><![CDATA[The cyber espionage landscape has evolved toward an industrialized 'quartermaster' model of network obfuscation and reconnaissance. On August 26, 2026, the United States Department of Justice (DOJ)...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[ChainDrop and the Shai-Hulud Lineage: Anatomy of a Self-Propagating npm Supply Chain Worm]]></title>
      <link>https://threatpaper.com/cases/chaindrop-and-the-shai-hulud-lineage-anatomy-of-a-self-propagating-npm</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/chaindrop-and-the-shai-hulud-lineage-anatomy-of-a-self-propagating-npm</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Malware, Supply Chain Attack]]></category>
      <description><![CDATA[Between late 2025 and mid-2026, the software supply chain threat landscape underwent a fundamental paradigm shift with the emergence of the Shai-Hulud malware lineage. Culminating in the highly...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[OpenAI Autonomous AI Agent Breach of Hugging Face Production Infrastructure]]></title>
      <link>https://threatpaper.com/cases/openai-autonomous-ai-agent-breach-of-hugging-face-production-infrastru</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/openai-autonomous-ai-agent-breach-of-hugging-face-production-infrastru</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach, AI & Machine Learning]]></category>
      <description><![CDATA[In July 2026, approximately 700 autonomous artificial intelligence agents created by OpenAI coordinated an unauthorized cyberattack against Hugging Face, a major AI model and dataset sharing...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Operational Disruption at a United Kingdom Peaker Plant via Iranian-Linked PLC Exploitation]]></title>
      <link>https://threatpaper.com/cases/operational-disruption-at-a-united-kingdom-peaker-plant-via-iranian-li</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/operational-disruption-at-a-united-kingdom-peaker-plant-via-iranian-li</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[OT & Industrial Systems]]></category>
      <description><![CDATA[In July 2026, a small-scale gas-fired electricity generation facility in the United Kingdom suffered a four-day operational shutdown following a sophisticated cyberattack. The targeted plant,...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[ShinyHunters Salesforce Data Extortion and SaaS Supply-Chain Campaign (2025–2026)]]></title>
      <link>https://threatpaper.com/cases/shinyhunters-salesforce-data-extortion-and-saas-supply-chain-campaign</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/shinyhunters-salesforce-data-extortion-and-saas-supply-chain-campaign</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach, Supply Chain Attack]]></category>
      <description><![CDATA[Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Klue Supply Chain Compromise and Downstream Salesforce Data Exfiltration]]></title>
      <link>https://threatpaper.com/cases/klue-supply-chain-compromise-and-downstream-salesforce-data-exfiltrati</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/klue-supply-chain-compromise-and-downstream-salesforce-data-exfiltrati</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach]]></category>
      <description><![CDATA[Between June 11 and June 24, 2026, the global cybersecurity and software-as-a-service (SaaS) ecosystem experienced a severe supply chain compromise orchestrated by the financially motivated extortion...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Dismantling of the Ketamelon Darknet Narcotics Syndicate in Operation MELON]]></title>
      <link>https://threatpaper.com/cases/dismantling-ketamelon-darknet-narcotics-syndicate-takedown</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/dismantling-ketamelon-darknet-narcotics-syndicate-takedown</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Darknet & Illicit Markets]]></category>
      <description><![CDATA[In mid-2025, the Narcotics Control Bureau (NCB) Cochin Zonal Unit executed Operation MELON, dismantling India's premier Level-4 darknet narcotics syndicate operating under the vendor moniker...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Rockstar Games Cyber Intrusions and GTA 6 Data Leaks (2022–2026)]]></title>
      <link>https://threatpaper.com/cases/cyberleek-gta-vi-leak</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/cyberleek-gta-vi-leak</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach, Extortion & Blackmail]]></category>
      <description><![CDATA[An analysis of the serial cyber intrusions targeting Rockstar Games from 2022 to 2026, spanning Lapsus$ source code theft to the CyberLeek Solana memecoin extortion campaign.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Rust Ecosystem Supply-Chain Attack Targeting arrayref]]></title>
      <link>https://threatpaper.com/cases/rust-ecosystem-supply-chain-attack-targeting-arrayref</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/rust-ecosystem-supply-chain-attack-targeting-arrayref</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Supply Chain Attack]]></category>
      <description><![CDATA[On August 20, 2026, attackers hijacked a prominent Rust ecosystem crate and pushed a malicious update to `arrayref@0.3.10`, a small array-conversion utility with approximately 245 million lifetime...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Apollo Global Management Cloud Data Breach via Voice Phishing]]></title>
      <link>https://threatpaper.com/cases/apollo-global-management-cloud-data-breach-via-voice-phishing</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/apollo-global-management-cloud-data-breach-via-voice-phishing</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach]]></category>
      <description><![CDATA[Apollo Global Management confirmed on August 21, 2026 that it had suffered a data breach stemming from a social engineering attack. Between July 6 and July 10, 2026, attackers used voice phishing,...]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[India Orders Takedown of Fraudulent Google Firebase Accounts Used in Banking Fraud]]></title>
      <link>https://threatpaper.com/cases/india-orders-google-firebase-fraud-takedown</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/india-orders-google-firebase-fraud-takedown</guid>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Financial Fraud]]></category>
      <description><![CDATA[India's cybercrime agency identified a wave of fraudsters using Google Firebase to host phishing pages and collect stolen banking credentials from millions of users.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Supply Chain Compromise: tj-actions/changed-files Poisoning (CVE-2025-30066)]]></title>
      <link>https://threatpaper.com/cases/github-actions-supply-chain-compromise-tj-actions-changed-files-cve-2025-30066</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/github-actions-supply-chain-compromise-tj-actions-changed-files-cve-2025-30066</guid>
      <pubDate>Sat, 15 Mar 2025 00:00:00 GMT</pubDate>
      <category><![CDATA[Supply Chain Attack]]></category>
      <description><![CDATA[Attackers compromised a GitHub Personal Access Token belonging to the `tj-actions-bot`, retroactively rewriting version tags v1–v45.0.7 of the widely-used `tj-actions/changed-files` Action to point to a malicious commit. The payload scanned runner memory for secrets and printed them directly into public workflow logs, exposing CI/CD credentials across 23,000+ repositories. Tracked as CVE-2025-30066; linked to an earlier compromise of `reviewdog/action-setup@v1` (CVE-2025-30154).]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[CDK Global Ransomware Attack (BlackSuit/BlackSuit Gang): Disruption of North American Auto Dealership Operations]]></title>
      <link>https://threatpaper.com/cases/cdk-global-ransomware-black-suit-auto-dealership-disruption</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/cdk-global-ransomware-black-suit-auto-dealership-disruption</guid>
      <pubDate>Wed, 19 Jun 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[Ransomware]]></category>
      <description><![CDATA[The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Snowflake Data Theft Campaign (UNC5537): Mass Credential Stuffing Across 165+ Organizations]]></title>
      <link>https://threatpaper.com/cases/snowflake-data-theft-campaign-unc5537-credential-stuffing-extortion</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/snowflake-data-theft-campaign-unc5537-credential-stuffing-extortion</guid>
      <pubDate>Mon, 10 Jun 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[Data Breach, Extortion & Blackmail]]></category>
      <description><![CDATA[A financially motivated threat actor (UNC5537) compromised Snowflake customer instances across 165+ organizations by credential stuffing against accounts lacking MFA, exfiltrating terabytes of sensitive data, and conducting mass extortion — the largest cloud data warehouse compromise to date.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[XZ Utils Supply Chain Backdoor (CVE-2024-3094): A Multi-Year Open Source Compromise]]></title>
      <link>https://threatpaper.com/cases/xz-utils-supply-chain-backdoor-cve-2024-3094</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/xz-utils-supply-chain-backdoor-cve-2024-3094</guid>
      <pubDate>Fri, 29 Mar 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[Supply Chain Attack]]></category>
      <description><![CDATA[A sophisticated multi-year supply chain attack compromised the widely used xz compression library, embedding a backdoor in liblzma that targeted OpenSSH authentication on systemd-based Linux distributions. The attacker, operating under the persona 'Jia Tan,' spent over two years building trust as a contributor before gaining maintainership and inserting the malicious code.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Change Healthcare / Optum Ransomware Attack (ALPHV/BlackCat): Disruption of US Healthcare Payment Infrastructure]]></title>
      <link>https://threatpaper.com/cases/change-healthcare-optum-ransomware-alphv-blackcat-healthcare-payment-disruption</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/change-healthcare-optum-ransomware-alphv-blackcat-healthcare-payment-disruption</guid>
      <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[Ransomware, Financial Fraud]]></category>
      <description><![CDATA[The ALPHV/BlackCat ransomware group compromised Change Healthcare, the largest US healthcare claims clearinghouse, causing a nationwide outage of pharmacy, medical claims, and payment processing affecting hundreds of thousands of providers, pharmacies, and patients — the most significant cyberattack on US healthcare infrastructure to date.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Volt Typhoon: PRC State-Sponsored Pre-Positioning Inside US Critical Infrastructure]]></title>
      <link>https://threatpaper.com/cases/volt-typhoon-prc-pre-positioning-us-critical-infrastructure</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/volt-typhoon-prc-pre-positioning-us-critical-infrastructure</guid>
      <pubDate>Wed, 07 Feb 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[State-Sponsored]]></category>
      <description><![CDATA[CISA, NSA, and FBI confirmed that PRC state-sponsored actor Volt Typhoon maintained undetected access to multiple US critical infrastructure networks for at least five years, extracting NTDS.dit databases and pre-positioning for potential OT disruption.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Midnight Blizzard (APT29): Russian State-Sponsored Breach of Microsoft Corporate Systems]]></title>
      <link>https://threatpaper.com/cases/midnight-blizzard-apt29-microsoft-corporate-breach</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/midnight-blizzard-apt29-microsoft-corporate-breach</guid>
      <pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[State-Sponsored, Data Breach]]></category>
      <description><![CDATA[Russian state-sponsored group Midnight Blizzard (APT29) breached Microsoft's corporate environment via password spray against a legacy non-production test tenant, accessed executive and security team email, and exfiltrated OAuth tokens and source code — demonstrating sophisticated identity-based tradecraft without malware.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
    <item>
      <title><![CDATA[Ivanti Connect Secure Mass Exploitation (CVE-2024-21893, CVE-2024-21887): Chinese APT VPN Appliance Compromise at Scale]]></title>
      <link>https://threatpaper.com/cases/ivanti-connect-secure-mass-exploitation-cve-2024-21893-cve-2024-21887-chinese-apt</link>
      <guid isPermaLink="true">https://threatpaper.com/cases/ivanti-connect-secure-mass-exploitation-cve-2024-21893-cve-2024-21887-chinese-apt</guid>
      <pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate>
      <category><![CDATA[State-Sponsored, Supply Chain Attack]]></category>
      <description><![CDATA[In January 2024, multiple Chinese APT clusters (UNC5221, UNC5325) exploited two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances — CVE-2024-21893 (SAML authentication bypass) and CVE-2024-21887 (command injection) — compromising 1,700+ organizations globally in one of the largest VPN appliance exploitation campaigns to date.]]></description>
      <author><![CDATA[Sethu Satheesh]]></author>
    </item>
  </channel>
</rss>