Resources

Research

Resource Library

Clear filters

Catch Me If You Can: Inside the Anonymization-for-Hire Network

August 10, 2026

Catch Me If You Can: Inside the Anonymization-for-Hire Network
In this briefing, Wade Lance VP, Product Marketing & Sales Enablement walks through STRIKE’s newest report Catch Me If You Can. Wade takes viewers inside the full commercial stack behind CanOworms — tenants, relay fleet, resellers, and landlord ASNs — and explains why treating a threat-feed-flagged C2 as a single actor’s infrastructure can lead defenders to the wrong conclusion entirely. This isn’t a read-through of the report. It’s Wade’s field-tested take on what the findings mean for how security teams should actually hunt this kind of infrastructure. Download the briefing now.
STRIKE Alert
STRIKE News
STRIKE Team
Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire

August 5, 2026

Catch Me If You Can: New Research Reveals CanOworms, a Proxy Network for Hire
Blocklists, geolocation, and ASN reputation all share one assumption: that an IP tells you who’s behind it. CanOworms is built to break that assumption. STRIKE identified 633 confirmed member servers operating as a shared Squid/SOCKS/OpenVPN/IPsec relay fleet — not a command-and-control panel, but the disposable front in front of one. Dozens of tenants, from Remcos and Quasar operators to suspected APT41 and APT43/APT37 infrastructure, have used these same relays. The operator is unattributed by design. Many tenants, one set of relays. What you’ll learn: How the mesh was found. A shared self-signed TLS certificate (O=kickass), corroborated by JARM and JA4X fingerprints, exposed 633 confirmed nodes out of 748 candidate IPs across a dozen dense /24 blocks, six-plus hosting providers, and more than a dozen countries. How it’s run. Five Czech Republic control-plane hosts manage the fleet in a centralized “star” topology, with one node alone touching roughly 256 others and a fleet-wide ~35-second heartbeat back to a single collector — a pressure point defenders can watch. Who’s renting it, and who isn’t. A reseller called “PrivacyFirst” (MAXKO d.o.o., AS214366) surfaces in the paper trail, but only a fraction of its address space actually carries the mesh certificate — a case study in why reseller identity isn’t operator identity isn’t tenant identity. Where the attack traffic lands. Suspected credential-spray traffic exits the fleet toward MikroTik routers, TR-069 CPE, and Hikvision cameras — concentrated in South Africa, India, the U.S., Brazil, and Bangladesh. Commodity-crime geography, not espionage-target geography. Why IP-based defense fails here, and what to fingerprint instead. The report lays out why durable detection means tracking how the infrastructure was built (certificate thumbprints, JARM, JA4X, service-stack signature) rather than chasing IPs that get burned and replaced faster than blocklists can keep up. Full IOCs and MITRE ATT&CK mapping. Appendix A publishes the complete fingerprint set — ready to drop into detection tooling — mapped to ATT&CK Resource Development and C2 techniques (T1583.003, T1090.002, T1571). Download “Catch Me If You Can” for the complete CanOworms research, including the fingerprint methodology, control-plane analysis, and the full IOC appendix.
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers

July 9, 2026

LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
INFORME DE TENDENCIAS EN CIBERSEGURIDAD DE LA CADENA DE SUMINISTRO 2026

March 18, 2026

INFORME DE TENDENCIAS EN CIBERSEGURIDAD DE LA CADENA DE SUMINISTRO 2026
La paradoja del riesgo de terceros: La confianza aumenta mientras la exposición crece La brecha entre la seguridad percibida y la protección real se está ampliando. Si bien las organizaciones tienen más confianza que nunca en su capacidad para superar una brecha de seguridad, los datos subyacentes revelan una realidad diferente: los ecosistemas de cadena de suministro se están expandiendo hasta cientos de miles, mientras que la supervisión interna sigue siendo peligrosamente estancada. Para comprender cómo los líderes globales de ciberseguridad están navegando esta paradoja del riesgo de terceros, SecurityScorecard encuestó a cientos de profesionales que gestionan el riesgo de proveedores. El informe de 2026 destaca la necesidad urgente de ir más allá de las evaluaciones manuales y puntuales hacia una defensa automatizada e informada por amenazas. Hallazgos clave del informe 2026: La Paradoja de la Confianza: El 90% de los líderes confía en que su empresa podría continuar operaciones durante una brecha de un proveedor, aunque el 86% expresa una profunda preocupación por los riesgos de la cadena de suministro. Puntos Ciegos Evidentes: El 78% de las organizaciones admite que sus programas internos de ciberseguridad cubren menos del 50% de su ecosistema total de proveedores. Amenazas Impulsadas por IA: Los líderes ahora clasifican las amenazas impulsadas por IA como su principal riesgo en la cadena de suministro, sin embargo, el 67% todavía depende de auditorías de seguridad estáticas para la evaluación El Retraso en la Remediación: Debido a la dependencia de la comunicación manual como correos electrónicos y llamadas telefónicas, el 60% de las organizaciones tarda 8 días o más en remediar problemas de alta gravedad. Las prácticas de seguridad de la cadena de suministro de ayer no son suficientemente sólidas para las amenazas de hoy. Descargue el informe completo para descubrir cómo sus pares están gestionando sus ecosistemas de enésimas partes y aprenda cómo avanzar en la curva de madurez de su organización con monitoreo continuo impulsado por IA.
2026 Supply Chain Cybersecurity Trends Report

March 18, 2026

2026 Supply Chain Cybersecurity Trends Report
The paradox of third-party risk: Confidence rises as exposure grows The gap between perceived security and actual protection is widening. While organizations are more confident than ever in their ability to weather a breach, the underlying data reveals a different reality: supply chain ecosystems are expanding into the hundreds of thousands, yet internal oversight remains dangerously flat. To understand how global cybersecurity leaders are navigating this third-party risk paradox, SecurityScorecard surveyed hundreds of professionals managing vendor risk. The 2026 report highlights an urgent need to move beyond manual, point-in-time assessments toward automated, threat-informed defense. Key findings from the 2026 report include: The Confidence Paradox: 90% of leaders are confident their business could continue operations during a vendor breach, even though 86% express deep concern about supply chain risks. Glaring Blind Spots: 78% of organizations admit their internal cybersecurity programs cover less than 50% of their total vendor ecosystem. AI-Driven Threats: Leaders now rank AI-driven threats as their #1 supply chain risk, yet 67% still rely on static security audits for assessment. The Remediation Lag: Due to reliance on manual communication such as emails and phone calls, 60% of organizations take 8 days or more to remediate high-severity issues. Yesterday’s supply chain security practices aren’t strong enough for today’s threats. Download the full report to discover how your peers are managing their nth-party ecosystems and learn how to move your organization up the maturity curve with AI-driven, continuous monitoring.
The State of South Korea’s Cyber Supply Chain Risk

March 16, 2026

The State of South Korea’s Cyber Supply Chain Risk
Learn more in this resource.
Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence

February 9, 2026

Beyond the Hype: Moltbot’s Real Risk Is Exposed Infrastructure, Not AI Superintelligence
While the world debates Moltbook’s role in the AI ecosystem, it is just the tip of the iceberg of Titanic risk. SecurityScorecard’s STRIKE team uncovered what lurks beneath: Thousands of exposed OpenClaw (Moltbot) control panels vulnerable to takeover through misconfigured access and known exploits.
STRIKE Team
How to Prepare for Hong Kong’s Protection of Critical Infrastructure Bill in 2026

January 20, 2026

How to Prepare for Hong Kong’s Protection of Critical Infrastructure Bill in 2026
Hong Kong’s Protection of Critical Infrastructures Bill, effective January 1, 2026, introduces a comprehensive cybersecurity framework to safeguard essential services and strengthen national resilience. The legislation mandates operator-level accountability for both internal systems and external dependencies, including cloud platforms, managed services, and third-party vendors. Non-compliance carries severe financial penalties, emphasizing the need for structured governance and continuous oversight. The whitepaper outlines: Scope and Impact: Applies to critical sectors such as energy, finance, healthcare, transport, IT, communications, and government services. Key Requirements: Formal risk assessments, documented mitigation actions, continuous monitoring, and demonstrable supplier oversight. Compliance Challenges: Visibility into external risks, managing complex supply chains, and maintaining real-time control. Strategic Recommendations: Conduct readiness assessments, implement continuous monitoring, strengthen supplier governance, and build auditable reporting frameworks. Global Alignment: The Bill aligns with international standards such as the EU NIS2 Directive and Singapore’s Cybersecurity Act, signaling a global trend toward proactive cyber resilience.   By acting now, organizations can transform compliance obligations into an opportunity to enhance operational resilience and protect against evolving threats. The paper also highlights how SecurityScorecard’s platform enables continuous monitoring, AI-driven risk management, and structured reporting to meet these new regulatory expectations.   Contact us at marketing-apac@securityscorecard.io for further information or assistance.
Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router

November 19, 2025

Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router
SecurityScorecard’s STRIKE team uncovers how attackers turned thousands of ASUS routers into a worldwide spy network.
STRIKE Team
How to Prepare for the  UK Cyber Security and  Resilience Bill in 2025

September 30, 2025

How to Prepare for the UK Cyber Security and Resilience Bill in 2025
Inside the whitepaper: What the upcoming legislation demands, and how it compares to the EU’s NIS2 directive Why 97% of the UK’s top companies have already experienced third- and fourth-party breaches How new rules on incident reporting, supplier classification, and MSP oversight will impact your business Immediate steps to align with the NCSC Cyber Assessment Framework (CAF) Why companies with poor ratings are 13x more likely to be breached From Jaguar Land Rover to M&S, threat actors are breaching companies through their most trusted vendors. The weakest link is now your most urgent priority. Don’t wait for compliance to be enforced, or for a ransomware group to find your blind spots. Download the whitepaper now and take control of your cybersecurity supply chain.
The State of Cyber Resilience in India’s Supply Chains

September 25, 2025

The State of Cyber Resilience in India’s Supply Chains
Key Findings: 52.6% of Indian suppliers experienced at least one third-party breach in the past year; 10.7% publicly reported one. The risk landscape is highly polarized: 26.7% of companies scored an “F” in cybersecurity, the highest failure rate seen in any dataset, while 25.3% scored an “A.” IT services and aerospace had the strongest average scores, but IT vendors also accounted for 62% of all third-party breaches, reflecting their role as critical gateways to global clients. Pharmaceutical and medical device suppliers represented 42.1% of reported breaches and 38.5% of ransomware incidents, underscoring risks to international healthcare supply chains. Semiconductor, electronics, and automotive sectors showed elevated levels of credential compromise, typosquatting, and malware infections. The most common contributors to low ratings were network security gaps, mismanaged certificates, and poor patching practices. The companies were ranked based on various factors, such as network security, potential malware infections, and patching. You can download the full report here.
From the Depths of the Shadows: IRGC and Hacker Collectives Of The 12-Day War

August 5, 2025

From the Depths of the Shadows: IRGC and Hacker Collectives Of The 12-Day War
From reconnaissance to propaganda to payloads, this is how Iran’s digital foot soldiers mobilized across borders and platforms during the war with Israel in June 2025.
STRIKE Team
The State of Cyber Resilience in Singapore

July 23, 2025

The State of Cyber Resilience in Singapore
SecurityScorecard has released its new report, The State of Cyber Resilience in Singapore, revealing that every one of Singapore’s top 100 companies by market capitalization was impacted by third-party cyber breaches over the past year. The findings underscore systemic weaknesses in digital supply chain oversight and fourth-party risk—despite relatively strong internal security ratings. Key Findings: 100% of Singapore’s top 100 companies experienced at least one third-party breach in the past year. 5% suffered a direct breach, primarily caused by malware infections. Companies with an “A” cybersecurity rating demonstrated strong resilience: 93% experienced no known breach. Only 4% of Singaporean firms were rated “C” or lower, a stark contrast to the 31% average across Europe. The Agriculture, Energy, and Healthcare sectors stood out, with 100% of companies earning an A grade. Despite high ratings overall, the Technology sector recorded the highest direct breach rate at 40%. The report benchmarked Singapore against international peers, including the UK, Germany, and Australia. The companies were ranked based on various factors, such as network security, potential malware infections, and patching. You can download the full report here.
2025 Supply Chain Cybersecurity Trends: Why Visibility Is the Next Competitive Advantage

June 25, 2025

2025 Supply Chain Cybersecurity Trends: Why Visibility Is the Next Competitive Advantage
A handful of technology giants now control the infrastructure that powers the global economy. Traditional cybersecurity threats target individual companies, but today’s most devastating attacks exploit the few critical chokepoints that entire industries depend on. Against this backdrop of rising systemic risk, SecurityScorecard set out to assess how enterprises are managing their third-party risk. The responses from nearly 550 CISOs and cybersecurity leaders worldwide reveal a dangerous gap in organizational preparedness. Key findings include: High Concern: 88% of organizations are worried about supply chain cyber risks. Frequent Attacks: Over 70% experienced a significant third-party cyber incident last year; 5% had 10 or more. Poor Visibility: Less than half of organizations monitor even 50% of their extended supply chain for cyber threats. Passive Response: Only 26% integrate incident response into their third-party risk management (TPRM) programs, often relying on assessments or insurance. Misaligned Responsibilities: When breaches occur, TPRM teams often shift the burden to already overloaded Security Operations Center (SOC) staff.
Supply Chain Cyber Risk
Third-Party Risk Management
Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign

June 23, 2025

Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign
SecurityScorecard’s STRIKE team uncovered a new China-Nexus ORB Network targeting the United States and Southeast Asia. Read the report to gain an in-depth look at the LapDogs ORB network, its custom malware, and its role in cyberespionage.
STRIKE Team
The Cybersecurity of Europe’s Top 100 Financial Institutions 2025

June 4, 2025

The Cybersecurity of Europe’s Top 100 Financial Institutions 2025
SecurityScorecard has released its second Europe Financial Cybersecurity Report in two years, revealing that nearly every major financial institution across Europe has been impacted by third-party and fourth-party cyber breaches in the past year. Key Findings: 96% of Europe’s top 100 financial institutions experienced at least one third-party breach in the past year, a dramatic rise from 78% in the previous report. 97% had a breached entity within their fourth-party ecosystem, up from 84%. 7% suffered a direct breach, down from 8%, with malware and insider threats remaining key culprits. 94% of institutions with an “A” cybersecurity rating had no known breaches. 13% of firms were rated “C” or lower, an improvement from 18%, and outperforming the European sector average of 31%. The UK reported the highest number of third-party breaches, followed by Germany and Switzerland, while Malta, Luxembourg, and Portugal had the lowest exposure and highest average cybersecurity grades. The companies were ranked based on various factors, such as network security, potential malware infections, and patching.
Defending The Financial Supply Chain

May 21, 2025

Defending The Financial Supply Chain
A data-backed look at where fintech cybersecurity excels—and where it still breaks. Key Insights You’ll Learn: 41.8% of breaches in fintech stem from third-party vendors. Credential stuffing is now a systemic risk, even for high-performing firms. Digital Assets and BPS firms show surprising security gaps despite high ratings. “A” ratings don’t mean safety—repeat breaches are still common. DNS and application security remain the sector’s weakest points. If you’re in fintech security, this is your playbook. Download the Report
Massive Botnet Targets M365 with Stealthy Password Spraying Attacks

February 24, 2025

Massive Botnet Targets M365 with Stealthy Password Spraying Attacks
A Technical Breakdown of Large-Scale Password Spraying Through Non-Interactive Sign-Ins Your SIEM isn’t flagging it. MFA isn’t stopping it. Attackers are exploiting non-interactive sign-ins to run high-volume password spraying attacks against Microsoft 365, slipping past detection and locking in persistent access.   In this report: How attackers are evading Conditional Access and MFA to compromise accounts. What to look for in your logs—the key signals buried in non-interactive authentication events. Practical steps to disrupt these attacks before access is leveraged.   Read the full technical breakdown now.
STRIKE Team
Lazarus Group is Infecting Open-Source Code. Are You at Risk?

February 13, 2025

Lazarus Group is Infecting Open-Source Code. Are You at Risk?
North Korea’s Lazarus Group is hiding malware inside GitHub repositories and NPM packages, compromising developers and cryptocurrency platforms. Their targets: your code, your wallets, your users.
STRIKE Team
Insurance Carriers Face Unprecedented Supply Chain Cyber Threats

February 6, 2025

Insurance Carriers Face Unprecedented Supply Chain Cyber Threats
SecurityScorecard’s analysis of 150 leading insurance companies exposes a critical weakness: even carriers with robust security are being compromised through their supply chain partners. Our data reveals that threat actors are deliberately exploiting lower-scoring vendors to breach otherwise well-defended insurance organizations. Key Findings: Third-party breach rate hits record 59% in insurance – more than double the global average, with ransomware dominating the attack landscape Insurance carriers outperform vendors in security scores but face heightened risk through weaker supply chain partners Cross-industry software vulnerabilities caused 37% of breaches – nearly triple the rate of insurance-specific software issues U.S. carriers face disproportionate targeting despite strong security postures, with 79% of multi-breach victims being U.S.-based   Download the Report and get the detailed analysis and practical recommendations for strengthening your supply chain security
Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign

January 29, 2025

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign
During STRIKE’s investigation of Operation 99, our team identified multiple command-and-control (C2)\r\nservers active since September 2024.
STRIKE Team