Resources
STRIKE Alert
Resource Library
STRIKE
Your Old Threat Hunting Playbook Is Dead: Inside the 633-Server Network Hiding Criminals and Nation-States Alike
Attackers are increasingly renting the infrastructure that hides them instead of building it. SecurityScorecard’s STRIKE Threat Intelligence Team pulled back the curtain on one such operation: a 633-server proxy fleet, leased out to commodity malware crews and, at low confidence, suspected nation-state tenants.
STRIKE Alert
STRIKE News
Research
Catch Me If You Can: Inside the Anonymization-for-Hire Network
In this briefing, Wade Lance VP, Product Marketing & Sales Enablement walks through STRIKE’s newest report Catch Me If You Can.
Wade takes viewers inside the full commercial stack behind CanOworms — tenants, relay fleet, resellers, and landlord ASNs — and explains why treating a threat-feed-flagged C2 as a single actor’s infrastructure can lead defenders to the wrong conclusion entirely.
This isn’t a read-through of the report. It’s Wade’s field-tested take on what the findings mean for how security teams should actually hunt this kind of infrastructure.
Download the briefing now.
STRIKE Alert
STRIKE News
STRIKE Team
Blog
Inside CanOworms: The 633-Server Proxy Network Hiding Criminal and State-Linked Activity
SecurityScorecard’s STRIKE team uncovered a 633-server anonymization network used by commodity malware operators and suspected state-linked actors, revealing how attackers rent shared infrastructure to evade traditional defenses.
STRIKE Alert
STRIKE News
STRIKE Team
Blog
LapDogs Is Back: Inside UAT-7810’s Expanding ORB Network and Its New Servers
Executive Summary: The latest Cisco Talos research shows these operators did not abandon the LapDogs ORB network after exposure. Instead, they appear to be continuing development through new tooling designed to manage, expand, and sustain compromised routers and other internet-facing devices. Cisco Talos published new research this week on UAT-7810, the threat actor behind LapDogs,
STRIKE Alert
STRIKE News
STRIKE Team
Report
SecurityScorecard’s New Driftnet Engine Reveals America’s Small-Town Surveillance Blind Spot
SecurityScorecard researchers used Driftnet’s internet-scale discovery capabilities to analyze the network footprint of a small U.S. municipal utility provider that also operates as the town’s internet service provider (ISP). The investigation identified widespread exposure across internet-facing systems, including vulnerable surveillance equipment, exposed Industrial Control Systems (ICS), weak encryption configurations, and End-of-Life (EoL) Windows devices.
The utility provider operates its own Autonomous System (AS), meaning internet connectivity and critical infrastructure services exist within the same broader operational environment. This convergence creates a concentrated point of failure where disruption to one service can affect others across the community.
Over a six-month period, Driftnet identified 1,498 services across 692 IP addresses. Of those, 446 IPs (64%) exhibited at least one technical issue that increased exposure risk. SecurityScorecard’s Driftnet engine identifies 150% more internet-facing services than previous scanning methodologies, uncovering exposures traditional approaches miss. Findings included:
30 instances of Dahua and Hikvision surveillance equipment inside the entire footprint of the utilities AS. Banned internet protocol (IP) cameras could enable Man-in-the-Middle (MitM) attacks, Distributed Denial of Service (DDoS) attacks, malware-based campaigns, and more.
Exposed ICS, SCADA, and OT-related services directly reachable from the internet. At least three /24 clusters hosting ICS or IOT services and consumer devices on the same broadcast domain.
Weak or misconfigured encryption across 382 IP addresses, in addition to cleartext FTP and HTTP and unrecognized Certificate Authorities.
EoL Windows hosts reachable via Server Message Block (SMB) and NetBIOS. A relic from the past, rarely ever makes an appearance outside of OT environments.
25 Known Exploited Vulnerabilities (KEVs) identified across internet-facing services.
Convergence of a utility and ISP creates a single point of failure. Power delivery and internet reside on the same AS. Incidents on one impacts the other.
The research also identified multiple network segments where consumer-grade devices, surveillance systems, and ICS-related technologies operated within the same local network environment. This lack of segmentation increases the likelihood that compromise of a lower-security system could enable lateral movement toward operational infrastructure.
To understand the full scope of the findings, download the full report today to see how Driftnet delivers the visibility organizations need to move from reactive security to continuous, threat-informed defense.
STRIKE Alert
STRIKE News
STRIKE Team
STRIKE
9 Year Old Vulnerability Still Affecting Thousands (CVE-2016-10033)
On July 07, 2025, CVE-2016-10033 was added to CISA’s list of Known Exploited Vulnerabilities (CISA-KEV).
STRIKE Alert
STRIKE
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability (CVE-2025-32433) Added to CISA KEV
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability (CVE-2025-32433)
STRIKE Alert
STRIKE
SecurityScorecard Advisory: Synacor Zimbra Collaboration Suite XSS Vulnerability (CVE-2024-27443) Added to CISA KEV
SecurityScorecard Advisory: Synacor Zimbra Collaboration Suite XSS Vulnerability (CVE-2024-27443)
STRIKE Alert
STRIKE
SecurityScorecard Advisory: Apache HTTP Server Improper Escaping of Output Vulnerability (CVE-2024-38475) Added to CISA KEV
SecurityScorecard Advisory: Apache HTTP Server Improper Escaping of Output Vulnerability (CVE-2024-38475) \r\n
STRIKE Alert
STRIKE
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590) Added to CISA KEV
SecurityScorecard Advisory: Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability (CVE-2025-21590)
STRIKE Alert