Home

Red Sky® Alliance has been serving information security professionals for over twelve years. We invite businesses and organizations, from enterprises to small businesses, to learn more about cyber threats and how to avoid them. We provide TLP White and Green cyber threat reporting for targeted industry segments, international reports, and malware/bot analyses.

A privately held USA-owned cyber threat intelligence firm that delivers proprietary cyber threat intelligence datasets and services. Our company provides insightful, actionable intelligence in formats best suited to your strategic, operational, and tactical needs.

 

Let us better prepare you and your team for new cyber threats.

Redskyalliance.org offers free access to all, and no salesperson will call.

GPS Spoofing – A Transportation Danger

31272051897?profile=RESIZE_400x For years now, Red Sky Alliance has been reporting on vessel name spoofing, using fake email addresses to lure companies in the maritime arena to click on infected emails.  Now Georgia Tech has revealed vessel GPS spoofing, which produced a study showing 367,000 ships affected by global GPS spoofing.  This research included the Red Sea activity detected months before the MSC Antonia…

Read more…

Pulling the Plug to Avoid Attack

31272005864?profile=RESIZE_400x Kiteworks is a provider of secure file-transfer and data-sharing software. Its products are used by organizations to exchange sensitive information with employees, customers, and various other outside organizations. As we've seen in recent months, services sitting at the boundaries between organizations and outside parties are attractive targets for attackers seeking large amounts of…

Read more…

OP Malfex

31271700052?profile=RESIZE_400x Hackread.com posted a great example of cyber security in action.  A long-running supply-chain campaign has used malicious npm packages to deliver a remote access trojan (RAT), steal credentials and maintain access to compromised Windows systems.  CloudSEK’s Global Threat Intelligence team…

Read more…

AGI v. ASI

31271692691?profile=RESIZE_400x

  • Artificial General Intelligence (AGI) and Artificial Superintelligence (ASI) represent successive stages beyond today’s narrow AI systems.
  • Narrow AI (the present)
  • Current AI (also called Artificial Narrow Intelligence or ANI) is specialized. Systems like large language models, image generators, recommendation engines, or game-playing agents excel at…
Read more…

Is it Random?

31269811081?profile=RESIZE_400x A bank creating an encryption key, a state drawing a lottery, and a hospital assigning patients to a trial all need the same thing: a random number that nobody in the room, and nobody who built the machine generating random output, could have known in advance. Ordinary computers aren’t optimized for randomness. They follow recipes. Left alone, they cycle, repeat, or leak the rhythm of…

Read more…

Hackers Fuel Blockchain Dead Drops

31269810271?profile=RESIZE_400x Research published by Chainalysis shows that nation-state cyber actors are leading an unprecedented expansion in the use of public distributed ledgers to orchestrate cyberattacks.  Analysts recorded a 440% year-on-year surge in what the industry terms "blockchain dead drop" (BDD) techniques. In these schemes, threat actors insert malicious commands and routing instructions straight…

Read more…

Cyber Security Breach as Google's Gemini AI Escapes

31269809095?profile=RESIZE_400x Google’s artificial intelligence model Gemini has accessed protected systems belonging to three external companies during a cybersecurity evaluation.  The incident occurred after a configuration error exposed the autonomous agent to the live internet. Gemini was participating in a 'capture-the-flag' challenge to locate hidden data within a simulated target environment. Directed to…

Read more…

Artificial Intelligence and Fraud

31268060069?profile=RESIZE_400x The phone rings and it is a relative or friend's voice on the line.  There has been an accident, they say, and they need money urgently.  It is not really them, as technology has copied their voice.  For years, artificial intelligence and cybersecurity concerns have focused on corporate networks and government systems.  Those threats remain real, but the FBI's fraud data shows that…

Read more…

REDXRAY

MITRE ATT&CK

The MITRE ATT&CK detection library is a publicly available collection of detection guidance mapped to adversary behaviors in the MITRE ATT&CK framework. It helps security teams design and organize detections for attacker techniques such as credential dumping, PowerShell abuse, persistence, and data exfiltration.

In the News

REDSHORT Webinars

Please Join our REDSHORT webinars. 'RED' as something important from Red Sky Alliance, and 'SHORT' in 10 minutes or less weekly. We will cover highlights of trending topics.

REGISTER HERE

Cyber Security Blog

You need to be a member of Red Sky Alliance to add comments!

Comments are closed.

Comments

This reply was deleted.

Red Sky Alliance

For more information about Red Sky Alliance, follow the link, ABOUT