What we are seeing in Nordic networks
Findings from live engagements, published so defenders can act before the next intrusion.
Akira affiliates abusing unpatched SSL VPN appliances
A single unpatched edge appliance gave affiliates domain-wide access in under four hours. We break down the initial access, the credential harvesting that followed, and the detections that would have caught it.
Threat brief · 6 min read
Read articleToken theft after MFA fatigue: what the logs actually show
MFA did its job — the user still clicked approve. We walk through the sign-in and audit logs that expose stolen session tokens and the conditional access gaps that let them travel.
Field notes · 9 min read
Read articleDetecting quiet persistence in Entra ID app registrations
Attackers no longer need a foothold on an endpoint. A rogue app registration with the right consent grant is a silent, reboot-proof backdoor. Here is how we hunt for them.
Research · 11 min read
Read articleWhen ransomware crosses into the plant floor
IT and OT convergence means an office-network intrusion can halt production. We cover the segmentation failures we see most and a pragmatic containment playbook for mixed environments.
Threat brief · 8 min read
Read articleBusiness email compromise in Nordic supply chains
Invoice fraud rarely starts with your inbox — it starts with a compromised supplier. We map the payment-diversion kill chain and the verification controls that actually stop it.
Field notes · 7 min read
Read articleLoader-as-a-service: the quiet economy behind the breach
Before the ransomware there is a loader, and behind the loader there is a marketplace. We profile the current commodity loaders seen in Nordic telemetry and their handoff to human operators.
Research · 10 min read
Read article