Visualização normal

Antes de ontemEclecticIQ Blog

Compromising the Developer: How Modern Dependency Culture Reshaped the Supply Chain Threat Landscape

17 de Agosto de 2026, 10:47

1. Executive summary

Modern software is assembled, not written. A single application routinely draws on hundreds of third-party components, pulled in on demand and updated continuously as part of normal process. That convenience has quietly become a dependable initial-access route that bypasses traditional perimeter and endpoint defenses. Rather than breaching a hardened production perimeter, adversaries increasingly compromise the developer, the maintainer account, the build pipeline, or the package registry — and let trusted automation carry their code the rest of the way.

EclecticIQ Intelligence Center 3.8: Built for the way security teams are actually working now

Running a threat intelligence program today means operating across more tools, more workflows, and more organizational complexity than most platforms were originally designed to handle. The intelligence is there. The question is whether the platform is keeping up with how your team actually needs to use it.

EclecticIQ MCP Server: Connect your AI agents directly to your threat intelligence

SOC and CTI teams have spent the last two years integrating AI tools into real investigative work, and the results have been meaningful. Analysts move faster through reports, surface connections more quickly, and spend less time on the mechanical parts of initial triage. But the threat intelligence platform sitting at the center of that work has remained largely separate from it, a destination analysts navigate to rather than an environment agents can operate inside. The gap between understanding a threat and recording it in a TIP is still, in most teams, a human problem. The EclecticIQ MCP Server is built to close it.

Keyword lists: Stop re-entering the same organizational context across every workflow

SOC and CTI teams spend a significant part of their day maintaining context that should already be there. The assets they monitor, the technologies they protect, the threat actors they track, this organizational knowledge gets re-entered manually across searches, rules, and requirements, duplicated across individual analyst workflows, and updated inconsistently when environments change. The intelligence keeps up with the threat landscape. The context that scopes it rarely does. That is why Intelligence Center 3.8 introduces Keyword lists, a capability that lets teams define organizational context once and apply it automatically across every workflow.

  • ✇EclecticIQ Blog
  • The AI Arms Race: How Adversaries are Weaponizing AI for Speed and Scale EclecticIQ Threat Research Team
    1. Executive summary For a decade, the cyber threat narrative has been one of escalating sophistication. Over the past twelve months, it has become one of escalating speed. Across reporting from Google [1], Microsoft [2], CrowdStrike [3], Mandiant [4], Anthropic [5] and OpenAI [6], a consistent picture has emerged: artificial intelligence is not fundamentally changing what adversaries can do. Instead, it is letting them execute existing tactics faster, at greater scale, and with fewer skilled p
     

The AI Arms Race: How Adversaries are Weaponizing AI for Speed and Scale

2 de Julho de 2026, 06:01

1. Executive summary

For a decade, the cyber threat narrative has been one of escalating sophistication. Over the past twelve months, it has become one of escalating speed. Across reporting from Google [1], Microsoft [2], CrowdStrike [3], Mandiant [4], Anthropic [5] and OpenAI [6], a consistent picture has emerged: artificial intelligence is not fundamentally changing what adversaries can do. Instead, it is letting them execute existing tactics faster, at greater scale, and with fewer skilled people.

Why doctrine is becoming a technology requirement for modern defense intelligence

22 de Junho de 2026, 04:30

For years, defense organizations have adapted commercially developed cyber threat intelligence platforms to fit military intelligence processes. This arrangement was often accepted as a practical necessity. Commercial platforms delivered valuable capabilities, while intelligence teams developed processes to align outputs with doctrinal requirements, reporting structures, and command expectations.

The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026

11 de Junho de 2026, 05:35

Executive Summary

The People's Republic of China (PRC) represents the most significant long-term cyber threat to defense-aligned and enterprise organizations. PRC-linked threat groups are pre-positioned inside critical networks at scale. This access appears intended for possible activation during a future geopolitical crisis, likely a Taiwan contingency.

SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer

21 de Maio de 2026, 06:04

Executive summary

  • Financially motivated eCrime actors will likely continue to expand opportunistic campaigns by impersonating AI platforms. These campaigns generate direct supply chain risk for enterprises, as threat actors target software developer tooling, including AI coding assistants and package managers, to compromise developer workstations.
  • In early March 2026, EclecticIQ analysts identified an ongoing infostealer campaign targeting Gemini CLI and Claude Code users. Threat actors use SEO poisoning to surface fake domains above legitimate results, directing victims to attacker-controlled infrastructure that mimics genuine AI agent installation pages.
  • The infostealer targets Windows endpoints and executes entirely in memory through PowerShell, harvesting credentials and sensitive data from a wide range of applications before exfiltrating the results in encrypted form to a command-and-control server.
  • Beyond credential theft, the malware provides arbitrary remote code execution capability, which financially motivated operators leverage to transition into hands-on-keyboard intrusions against selected victims and execute interactive code within the compromised environment.
  • Installations from these impersonated websites result in exfiltration of OAuth tokens, CI/CD credentials, corporate VPN details, and sensitive files, giving adversaries a direct path to initial access into the wider enterprise network.
  • This campaign showing that, financially motivated threat actors are capitalizing on widespread enterprise adoption of AI platforms to deliver infostealer malware.
  • Despite sustained law enforcement action, including Operation Magnus against RedLine and META in October 2024 and the May 2025 disruption of LummaC2 infrastructure, infostealer deployment against enterprise targets will likely continue to grow in the near term. Low operating costs and persistent demand for stolen credentials in underground markets sustain this trajectory.

Typosquatted domains impersonate Gemini and Claude Code installation

The Gemini CLI impersonation campaign was first publicly identified by independent threat researcher @g0njxa [1], whose initial discovery enabled analysis and infrastructure pivoting documented in this report. The infection chain begins with a Google search by a developer looking for the official Gemini CLI [2] or Claude Code [3] installation page. Threat actors use SEO poisoning to surface a fake domain at the top of search results, above the legitimate source. The victim clicks through, lands on a malicious page visually consistent with a genuine vendor installation guide and is prompted to execute a single command to complete the install.

Introducing Intelligence Center 3.7: Faster decisions with clearer context across defense and enterprise

Counting intelligence outputs is simple: volume, velocity, coverage. The real question is this: does your intelligence improve decisions under pressure, with confidence you can defend?

Free TIP Bundles to test, validate, and operationalize threat intelligence faster

You cannot confidently choose threat intelligence integrations and services when you have to commit before you can validate operational impact. That is how you end up with tools that look good on paper, but do not always reduce triage time, improve detection quality, or support response the way you hoped.

Disarming disinformation: How EclecticIQ helps you analyze and track influence operations with the DISARM Framework

Disinformation is no longer just a nuisance.  It’s a weapon leveraged by both state and non-state actors.  For information operations analysts tracking influence campaigns across elections, national security threats, and coordinated disinformation efforts, the challenge is growing. Whether you work in a government agency, intelligence service, election security organization, or corporate trust and safety team, the tools at your disposal were not built for this fight.  

Deduplication, done right: Full control, full context, one entity

Threat intelligence teams deal with a constant influx of data from multiple providers, often describing the same threat actor, malware, or vulnerability in slightly different ways. Instead of speeding up analysis, this duplication adds friction and slows decisions. 

Mission-ready threat intelligence: Aligning with doctrine through Defense TIP

The defense community deserves a threat intelligence platform that speaks their language. With our new Defense TIP mode, EclecticIQ aligns fully with NATO and US military doctrine, eliminating the friction caused by mismatched terminology, structure, and limited interoperability with joint and coalition intelligence workflowsThis is a mission-ready capability built to meet the strategic and operational demands of modern defense intelligence.

  • ✇EclecticIQ Blog
  • Europe's Security Capital Deserved Better. So We Got to Work. a.milne@eclecticiq.com (Andrew Milne)
    Last summer, a conversation took place between a group of security professionals from EclecticIQ and Booz Allen Hamilton. The topic was straightforward: The Hague is home to NATO, Europol, the Dutch NCSC, and The Hague Security Delta - the largest security cluster in Europe. It is also home to major global enterprises, financial institutions, and critical national infrastructure that represent some of the most significant concentrations of cyber risk on the continent. By any measure, The Hague i
     

Europe's Security Capital Deserved Better. So We Got to Work.

Last summer, a conversation took place between a group of security professionals from EclecticIQ and Booz Allen Hamilton. The topic was straightforward: The Hague is home to NATO, Europol, the Dutch NCSC, and The Hague Security Delta - the largest security cluster in Europe. It is also home to major global enterprises, financial institutions, and critical national infrastructure that represent some of the most significant concentrations of cyber risk on the continent. By any measure, The Hague is one of the most important security hubs in the world.  

And yet it had no grassroots community event to reflect that status. No accessible, practitioner-led space where the community could come together, share real knowledge, and connect outside of a commercial setting... and notably, no BSides event. 

The question was simple. Why had nobody done this? What followed was equally simple.  

We decided we would. 

  • ✇EclecticIQ Blog
  • We're at Black Hat Europe EclecticIQ
    EclecticIQ is proud to sponsor and exhibit at Black Hat Europe 2025, one of the world’s leading cybersecurity and threat intelligence conferences. This year’s event brings more than 3,000 security professionals from over 70 countries to London’s ExCeL for two days of technical briefings, hands-on research, and emerging security insights.
     

We're at Black Hat Europe

3 de Dezembro de 2025, 10:31

EclecticIQ is proud to sponsor and exhibit at Black Hat Europe 2025, one of the world’s leading cybersecurity and threat intelligence conferences. This year’s event brings more than 3,000 security professionals from over 70 countries to London’s ExCeL for two days of technical briefings, hands-on research, and emerging security insights.

  • ✇EclecticIQ Blog
  • The reality: Bargains bring risk EclecticIQ
    From Black Friday to Boxing Day, shopping surges and so do cyber scams. Countdown timers and “last chance” offers create urgency that attackers exploit. Every click has consequences if you’re not prepared. 
     
  • ✇EclecticIQ Blog
  • Why no business is immune to cyberattacks EclecticIQ
    The reality: every organization is a potential target Cybersecurity is no longer a concern reserved for the world’s largest enterprises or government agencies. In today’s hyperconnected world, every organization — regardless of size, sector, or geography — is a potential target.
     

EclecticIQ Intelligence Center 3.6: Built for finished intel, custom data modeling, and faster investigations

EclecticIQ Intelligence Center 3.6 isn’t just an update - it’s a leap forward. With smarter finished intelligence reporting, flexible intelligence modelling, and next-level AI features, this release helps cybersecurity teams move faster, work smarter, and deliver more value across the organization. Let’s break down what’s new, what it means, and why it matters.

❌
❌