Threat Intelligence & Security News

Threat Intelligence & Security News

CyberDesserts covers the threat landscape as it happens, ransomware campaigns, vulnerability disclosures, and emerging attack techniques. Written for security practitioners who need to understand what's happening, why it matters, and what to do about it. No vendor noise. No recycled press releases. Just analysis grounded in 20+ years of defending real organisations.
09
Jul
The Vulnerabilities That Never Get a CVE

The Vulnerabilities That Never Get a CVE

July 2026 Most vulnerability programmes run on a simple assumption: if a flaw matters, it gets a CVE, and if
9 min read
05
Jul
External Attack Surface Management: Seeing What Attackers Already See

External Attack Surface Management: Seeing What Attackers Already See

July 2026 For years, security ran on a simple mental model: build the walls high, dig the moat deep, and
13 min read
03
Jul
Your AI Coding Assistant's Config Folder Is a Persistence Surface

Your AI Coding Assistant's Config Folder Is a Persistence Surface

Supply-chain malware started writing into the config files your coding agent reads on every run. Nothing in the usual toolchain is watching that surface.
10 min read
23
Jun
What Is Scanning My Server? An Internet Scanner Reference

What Is Scanning My Server? An Internet Scanner Reference

You found a line in your logs you do not recognise. CensysInspect, Shodan-Pull/1.0, visionheight.com/scan, a
8 min read
24
May
What is a JA3 Fingerprint? How TLS Client Fingerprinting Works

What is a JA3 Fingerprint? How TLS Client Fingerprinting Works

Recognise the software behind any encrypted connection from its TLS handshake alone. How JA3 fingerprinting works, how to read one, and what a single hash reveals about shared attacker tooling.
7 min read
23
May
AndroxGh0st and the limits of TLS fingerprinting

AndroxGh0st and the limits of TLS fingerprinting

May 2026 The same scanner toolkit AWS attributed to Interlock ransomware in March 2026 also runs AndroxGh0st credential theft and
11 min read
14
May
Inside the Scanners Hunting Exposed AI Infrastructure: 72 Hours of Findings

Inside the Scanners Hunting Exposed AI Infrastructure: 72 Hours of Findings

460 source IPs, 11,643 requests, 72 hours. The AI-aware operators in the data enumerated; the exploitation observed targeted credentials, not AI capabilities.
19 min read
14
Apr
A glasswing butterfly resting on a green leaf, its transparent wings revealing the leaf surface beneath

Fable 5 Is Frozen and Glasswing Still Leaves Two Problems Open

Last updated: 30 June 2026 | What's changed: both models were suspended on 12 June under a US export
8 min read
08
Apr
Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next

Scattered Spider: The Attack Chain, Hard Lessons, and What Comes Next

April 2026 Scattered Spider is a financially motivated cybercrime collective responsible for some of the most disruptive attacks in recent
18 min read
07
Apr
Developer desk with a "No Bad Days" sign, keyboard, coffee mug and monitor taken before the axios npm supply chain attack made March 31 2026 a very bad day

Axios NPM Supply Chain Attack (2026): What Happened and What to Do

On March 31, 2026, two malicious versions of the axios npm package were published using a compromised maintainer account. The
8 min read