Home

Red Sky® Alliance has been serving information security professionals for over twelve years. We invite businesses and organizations, from enterprises to small businesses, to learn more about cyber threats and how to avoid them. We provide TLP White and Green cyber threat reporting for targeted industry segments, international reports, and malware/bot analyses.

A privately held USA-owned cyber threat intelligence firm that delivers proprietary cyber threat intelligence datasets and services. Our company provides insightful, actionable intelligence in formats best suited to your strategic, operational, and tactical needs.

 

Let us better prepare you and your team for new cyber threats.

Redskyalliance.org offers free access to all, and no salesperson will call.

31266423053?profile=RESIZE_400x An eight-month operation targeting West African organized crime groups has led to 58 arrests and the identification of 263 suspects in a police operation across 22 countries and six continents. Called Operation Jackal IV, Interpol coordinated the operation, arresting some of those behind romance and investment scams. It also identified 263 suspects.  "The operation, which brought…

Read more…

Criminals Weaponize QR Codes

31266635694?profile=RESIZE_400x Reports of fraudulent activity in the UK involving quick response (QR) codes have surged by seven hundred percent (700%) over the past four years, according to data from Report Fraud.  Cyber criminals are increasingly turning these familiar pixel patterns into deceptive digital traps designed to swindle consumers out of hard-earned money and sensitive personal information.  Malicious…

Read more…

Casbaneiro

31255963066?profile=RESIZE_400x In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage.

Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use…

Read more…

31266421060?profile=RESIZE_400x Imagine sending a sealed letter across a crowded city where anyone might intercept it. The seal on the envelope keeps the contents private, the signature on the letter proves the sender is who they claim to be, and reusing the same secure channel later without starting from scratch keeps things efficient. That’s roughly how the internet’s main security protocol works every time you…

Read more…

You Can’t Dunk NovaCookies in Milk

31266419499?profile=RESIZE_180x180 Security researchers have uncovered NovaCookies, a phishing-as-a-service platform that helps criminals steal Microsoft 365 authentication sessions in real time.  The platform gives attackers infrastructure that relays a genuine Microsoft sign-in page through attacker-controlled systems.  Victims are directed to what appears to be a legitimate login process, allowing the service to…

Read more…

After Hacking Mistakes

31255876078?profile=RESIZE_400x Getting hacked has a way of making people panic first and think clearly second.  That's understandable, because the moment you realize someone may have gotten into your email, social account, or bank login, your brain tends to jump straight to damage control.  In that rush, many people focus on the most obvious fix and assume the crisis is basically over once they do it.

The…

Read more…

T-Mobile Severs Network Cable to Expel Hackers

31255892685?profile=RESIZE_180x180 Cybersecurity staff at US phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide hacks by Beijing to steal customer data, and Bloomberg has now published a report on the event.   T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut…

Read more…

Multi-Functional Linux – Evooo1Bot

31255879654?profile=RESIZE_400x Researchers have been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot.  The name derives from the hardcoded string “evooo1” found in every binary.  While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH…

Read more…

In the News

REDSHORT Webinars

Please Join our REDSHORT webinars. 'RED' as something important from Red Sky Alliance, and 'SHORT' in 10 minutes or less weekly. We will cover highlights of trending topics.

REGISTER HERE

Cyber Security Blog

You need to be a member of Red Sky Alliance to add comments!

Comments are closed.

Comments

This reply was deleted.

Red Sky Alliance

For more information about Red Sky Alliance, follow the link, ABOUT