ThreatBook Blog

Actionable research, threat intelligence trends, product updates, and thought leadership from ThreatBook.

3 min read

Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT

On July 27, 2026, Apple released security updates for iOS 26.6 and iPadOS 26.6, fixing vulnerabilities across several components — Accessibility, Kernel, Libnotify, and WebKit. Among them is CVE-2026-64739, a stack-based buffer overflow in...

Read More

2 min read

Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation

A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a...

Read More

5 min read

APAC's Cyber Threat Landscape: Inside the 2026 Mid-Year Data

ThreatBook Labs recorded 15,205 security incidents across Asia-Pacific between June 2025 and June 2026. Read one at a time, they look like an...

Read More

5 min read

Agentic Security Is the Architecture Decision

The defender math broke a few years ago. Not because the threats got worse. They did, but that has been true every year since the first SOC was stood...

Read More

4 min read

Why We're Becoming the Agentic Company

ThreatBook is now the Agentic Security Company. That sentence will probably get reduced in some headline somewhere to "ThreatBook rebrands." The...

Read More

5 min read

TA558 Uses Steganography to Launch Global Cyberattacks

Overview TA558 (also known as "SteganoAmor") is a financially motivated cybercriminal organization that has been active since 2018. Its attacks are...

Read More

4 min read

Lazarus Group Poisons Axios: Inside the npm Supply Chain Attack

Regarding yesterday's Axios npm supply chain poisoning incident, ThreatBook has conducted in-depth sample analysis and attack tracing. Drawing on...

Read More

3 min read

OpenClaw Users at Risk: Axios on npm Backdoored with Cross-Platform RAT

Axios — one of the most foundational dependencies in the JavaScript ecosystem, with over 3.6 billion annual downloads — was compromised on npm on...

Read More

3 min read

When Security Tools Get Compromised: The LiteLLM Supply Chain Poisoning Incident

On March 24, 2026, ThreatBook Research Team detected a large-scale supply chain attack targeting LiteLLM — a core component widely used across the AI...

Read More

2 min read

The AI Tools Your Security Team Doesn't Know Are Running

A security director at a mid-sized enterprise came to us recently with a question that sounds simple but turns out to be surprisingly hard to answer:...

Read More