惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
K
Kaspersky official blog
L
Lohrmann on Cybersecurity
T
Tenable Blog
Latest news
Latest news
C
CXSECURITY Database RSS Feed - CXSecurity.com
Security Latest
Security Latest
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
P
Palo Alto Networks Blog
I
Intezer
T
Threatpost
C
Cisco Blogs
A
Arctic Wolf
C
Cyber Attacks, Cyber Crime and Cyber Security
WordPress大学
WordPress大学
月光博客
月光博客
博客园 - 聂微东
Last Week in AI
Last Week in AI
V
V2EX
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Simon Willison's Weblog
Simon Willison's Weblog
T
The Exploit Database - CXSecurity.com
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
Spread Privacy
Spread Privacy
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
T
Threat Research - Cisco Blogs
博客园 - Franky
S
Schneier on Security
Know Your Adversary
Know Your Adversary
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
美团技术团队
T
Tor Project blog
C
Cybersecurity and Infrastructure Security Agency CISA
腾讯CDC
Project Zero
Project Zero
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
量子位
The GitHub Blog
The GitHub Blog
I
InfoQ
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
P
Privacy & Cybersecurity Law Blog
B
Blog RSS Feed

Vectra AI Blog

Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Why You Need an NDR to Protect Your Modern Network Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI named in Gartner hype cycle for security operations 2025 Vectra AI Vectra AI Vectra AI How Sanofi Detected and Stopped a Cyberattack How MITRE ATLAS Helps Detect LLM Attacks in Cloud AI Detecting Iranian APT identity attacks across hybrid environments Vectra AI Vectra AI Vectra AI Breaking down the axios supply chain incident Vectra AI Vectra AI Who’s Doing What on Your Network? FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access Detecting Compromise After the Axios Supply Chain Attack. Vectra AI Vectra AI Vectra AI AI Is Now the Attack Surface: Why Your Security Stack Must Adapt Fast Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How attackers use Brute Ratel (BRC4) Vectra AI Vectra AI Vectra AI The Cutting Edge: AI’s Inevitable Rise in Offensive Security Vectra AI Vectra AI Is AI the Right Tool to Defend Against Modern Cyberattacks? Vectra AI Vectra AI Vectra AI Turns Out Network Security Is Cool Again – and It’s Called NDR Vectra AI Vectra AI Vectra AI Choosing the Right NDR: Gartner’s 5 Questions Every Security Buyer Should Be Asking Vectra AI Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Identity Threat Detection and Response (ITDR) Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI You Have the Right Tools. So Why Are Attackers Still Getting In? Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Challenges in Microsoft Log Monitoring: Insights for Your SOC Vectra AI Platform Visualizes Multi-domain Modern Attacks with Attack Graphs Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Gartner Security and Risk Conference – Chaos meets Opportunity Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Network Detection and Response (NDR) Presenting the 2025 Vectra AI Scholars Simplify Threat Investigation and Hunting with Pre-built Queries in Vectra Investigate The 2025 Gartner® Magic Quadrant™ for Network Detection and Response (NDR) - Why Vectra AI Stands Tall Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How Black Basta Turned Public Data into a Breach Playbook Play’s New Tactics Bypass Traditional Defenses. Are You Ready? Charting a New Era of Network Security: Vectra AI at the Forefront Unlocking Operational Efficiency: How Vectra AI Drives 40% Gains in SOC Performance and 391% ROI Identity-Centric Attacks: The New Reality for UK Retail CISA Flags Fast Flux as a National Threat: Are You Covered? AI Agents: What Do They Mean in Cybersecurity?
Vectra AI
Zoey Chu · 2026-03-11 · via Vectra AI Blog

Threat actors often try to appear disciplined and highly skilled. Some operate ransomware-as-a-business, while others are organized cybercrime groups or state-sponsored teams. They invest time in tools, infrastructure, and evasion.

Public reporting shows that this image does not always match reality.

In several recent cases, attackers made basic operational security (OPSEC) mistakes. These mistakes exposed their infrastructure, their tools, and their behavior. Instead of staying invisible, attackers created visibility for defenders.

Below are three OPSEC failures reported by researchers in December 2025.

Devman: Procedural OPSEC failures in ransomware operations

In a previous article, I covered the technical details of the Devman ransomware, including how it worked and what it reused from existing ransomware code.

After the launch, Devman drew public criticism on X for what researchers described as “poor OPSEC.” Multiple analysts pointed out that the group exposed its own infrastructure and internal systems while rolling out its ransomware-as-a-service (RaaS) offering.

Reported issues included:

  • Exposed internal infrastructure during launch — Systems used to manage the operation, including internal services, were accessible from the internet.
  • Weak protection of management and communication systems — Researchers were able to observe how parts of the operation were coordinated.
  • A rushed public launch — The RaaS platform went live before internal systems were properly isolated or secured.
  • Reuse of tooling without sufficient hardening — The operation relied on existing components that had not been adequately tested from an OPSEC perspective.

The result was a public perception that the operation was immature and poorly controlled, especially for a group trying to attract affiliates.

Scattered Lapsu$ Hunters: Behavioral OPSEC failures in target verification

Actors associated with SLSH publicly claimed they had breached a cybersecurity company. They released screenshots and stated that sensitive data had been stolen.

Follow‑up reporting showed that the accessed systems were not production environments. The attackers had interacted with a honeypot containing synthetic data designed to look realistic.

Researchers highlighted several OPSEC failures:

  • Failure to validate the target environment — Accessible systems were assumed to be real without confirming whether they were isolated or monitored.
  • Trust in synthetic data — Data that appeared legitimate was accepted as proof of compromise without deeper verification.
  • Premature public claims — The breach was announced before it had been confirmed.
  • Automation issues exposing technical details — Repeated scraping and access attempts caused proxy failures that leaked technical information useful for tracking.

The group’s credibility suffered once the claim was shown to be false.

State‑sponsored APT: Technical OPSEC failures in system isolation

Researchers found that a system used by a North Korean threat actor had been infected with LummaC2, a widely used information‑stealing malware. The infected machine belonged to a developer involved in North Korea’s cyber operations.

Log analysis revealed credentials and tools tied to the system. Further investigation linked the machine to infrastructure associated with the $1.4 billion Bybit cryptocurrency theft, attributed to North Korean actors including the Lazarus Group.

The reported OPSEC failures included:

  • Poor endpoint hygiene — An attacker‑controlled system was compromised by a common infostealer.
  • Credential reuse — Email accounts and credentials stored on the device were linked to known malicious infrastructure.
  • Lack of isolation — Tools, phishing domains, and operational assets were present on a single system.
  • Incomplete anonymization — VPN usage failed to fully mask browser configuration, language settings, and usage patterns.

This was not an isolated incident. In May 2025, developers behind the DanaBot malware accidentally infected their own machines, and the recovered credential data was later used by investigators.

Both cases show how attackers can fall victim to the same threats they deploy.

Why OPSEC mistakes matter for defenders

These incidents highlight a simple truth: Threat actors are still human, and even skilled teams make human mistakes.

When those mistakes happen, they create signals defenders can observe:

  • How attackers behave after gaining access
  • Which tools and infrastructure they reuse
  • How they test, validate, and announce success
  • Where isolation and anonymization break down

Deception environments, synthetic data, and behavior‑based monitoring don’t eliminate attacks—they surface attacker behavior when assumptions fail.

Attackers are increasingly adopting AI‑driven tooling. Automation and AI can accelerate reconnaissance, targeting, and exploitation, but they don’t remove human judgment from the loop. They can also introduce new mistakes:

  • Over‑trusting automated outputs
  • Scaling false assumptions faster
  • Repeating mistakes at machine speed

The technology changes. The people don't.

And that’s where defenders still gain visibility.