Threat intelligence

What we are seeing in Nordic networks

Findings from live engagements, published so defenders can act before the next intrusion.

Subscribe to briefings
Ransomware

Akira affiliates abusing unpatched SSL VPN appliances

A single unpatched edge appliance gave affiliates domain-wide access in under four hours. We break down the initial access, the credential harvesting that followed, and the detections that would have caught it.

Threat brief · 6 min read

Read article
Identity

Token theft after MFA fatigue: what the logs actually show

MFA did its job — the user still clicked approve. We walk through the sign-in and audit logs that expose stolen session tokens and the conditional access gaps that let them travel.

Field notes · 9 min read

Read article
Cloud

Detecting quiet persistence in Entra ID app registrations

Attackers no longer need a foothold on an endpoint. A rogue app registration with the right consent grant is a silent, reboot-proof backdoor. Here is how we hunt for them.

Research · 11 min read

Read article
OT / ICS

When ransomware crosses into the plant floor

IT and OT convergence means an office-network intrusion can halt production. We cover the segmentation failures we see most and a pragmatic containment playbook for mixed environments.

Threat brief · 8 min read

Read article
Email

Business email compromise in Nordic supply chains

Invoice fraud rarely starts with your inbox — it starts with a compromised supplier. We map the payment-diversion kill chain and the verification controls that actually stop it.

Field notes · 7 min read

Read article
Malware

Loader-as-a-service: the quiet economy behind the breach

Before the ransomware there is a loader, and behind the loader there is a marketplace. We profile the current commodity loaders seen in Nordic telemetry and their handoff to human operators.

Research · 10 min read

Read article