In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4
Researchers at @sysdig found JadePuffer used an LLM agent to conduct a ransomware attack. Is this future of ransomware? In this case, a human still steered it and struggled with the basics.
The Gentlemen ransomware, in a BYOVD attack, used a zero-day exploit to kill EDRs before deploying their payload. The driver they abused wasn't on any public blocklist. Here's our analysis of their techniques. 🧵
"The Gentlemen" ran a tight RaaS operation.
Then they got breached.
CPR analyzed the full leak: org structure, access brokers, active CVEs, victim comms, and financials.
Real operators, real tradecraft, fully exposed.
research.checkpoint.com/2026/thus-spok…
Need a high-level overview of the latest Mini Shai Hulud? Aaron Walton breaks down how the latest supply chain attack happened, what defenders should do now, and prepare for the next one. expel.com/blog/mini-shai…[…]pl/?utm_medium=social&utm_source=twitter&utm_campaign=blog-promo