ThreatBook Research Team

The ThreatBook Research and Response Team leads the forefront of cybersecurity analysis and security operations. Its core research focuses on automated threat intelligence, advanced APT tracking, cybercrime industry monitoring, malware and automated analysis technologies, and major incident response. Composed of seasoned experts in malware analysis, forensic investigation, web attack technologies, attribution, big data, AI, and other advanced security disciplines, the team leverages proprietary systems — including automated intelligence production, cloud sandbox, hacker profiling, threat hunting, tracking and tracing, threat perception, and big data correlation knowledge graphs—to analyze and correlate millions of new malware samples, tens of millions of URLs, PDNS, and Whois records added daily to ThreatBook. Since its inception, the team has consistently been among the first to detect and monitor sophisticated APT groups targeting critical infrastructure and industries such as finance, energy, government, and high-tech. They have supported hundreds of clients worldwide in responding to high-impact global incidents — including the WannaCry ransomware outbreak — and in managing persistent, targeted attacks such as OceanLotus on maritime, high-tech, and financial sectors, and Patchwork campaigns affecting governments, diplomatic entities, universities, and research institutions.

3 min read

Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT

On July 27, 2026, Apple released security updates for iOS 26.6 and iPadOS 26.6, fixing vulnerabilities across several components — Accessibility, Kernel, Libnotify, and WebKit. Among them is CVE-2026-64739, a stack-based buffer overflow in...

Read More

2 min read

Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation

A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a...

Read More

5 min read

APAC's Cyber Threat Landscape: Inside the 2026 Mid-Year Data

ThreatBook Labs recorded 15,205 security incidents across Asia-Pacific between June 2025 and June 2026. Read one at a time, they look like an...

Read More

5 min read

TA558 Uses Steganography to Launch Global Cyberattacks

Overview TA558 (also known as "SteganoAmor") is a financially motivated cybercriminal organization that has been active since 2018. Its attacks are...

Read More

4 min read

Lazarus Group Poisons Axios: Inside the npm Supply Chain Attack

Regarding yesterday's Axios npm supply chain poisoning incident, ThreatBook has conducted in-depth sample analysis and attack tracing. Drawing on...

Read More

3 min read

OpenClaw Users at Risk: Axios on npm Backdoored with Cross-Platform RAT

Axios — one of the most foundational dependencies in the JavaScript ecosystem, with over 3.6 billion annual downloads — was compromised on npm on...

Read More

3 min read

When Security Tools Get Compromised: The LiteLLM Supply Chain Poisoning Incident

On March 24, 2026, ThreatBook Research Team detected a large-scale supply chain attack targeting LiteLLM — a core component widely used across the AI...

Read More

3 min read

Phishing With Google Ads and Fake AI Docs: A Criminal Campaign Targeting the AI Ecosystem

ThreatBook Research and Response Team has identified and tracked an organized threat group conducting a large-scale malware distribution campaign...

Read More

3 min read

Inside the Attack: Complete Technical Breakdown of the AI Ecosystem Threat Campaign

This is the full technical companion to our campaign overview published in Part 1. It documents the Windows and macOS malware chains in detail, and...

Read More

2 min read

How a Malicious Plugin Turned OpenClaw Into a Credential Stealer

Last week, ThreatBook's endpoint detection product, OneSEC EDR, identified and fully captured an active attack targeting OpenClaw users. The attack...

Read More