GotoHTTP is a tool tracked across 2 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 29, 2026; most recent activity February 5, 2026.
The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…
Cisco Talos reports on the UAT-8099 campaign that has been targeting vulnerable IIS web servers across Asia since August 2025. Key affected regions include India, Pakistan, Thailand, Vietnam, and Japan, with a notable…