New SecuritySnack: How attackers are abusing CloudFlare to hide M365 phishing campaigns. 🛡️➡️⚔️
Read the technical breakdown here: https://dti.domaintools.com/securitysnacks/securitysnack-cloudflare-anti-security-for-phishing
#CyberSecurity #Phishing #CloudSecurity #Infosec
DomainTools
A global leader for internet #intel that enables security practitioners to proactively defend their organization in a constantly evolving threat landscape.
🇰🇵Beyond the Fracture: DomainTools Investigations’ latest research analyzes the fragmented and parallel development pipelines behind North Korea’s specialized malware ecosystem.
Read the research here:https://dti.domaintools.com/research/dprk-malware-modularity-diversity-and-functional-specialization
#Cybersecurity #InfoSec #NorthKorea #Malware #Research
🔑New from DTI: Technical breakdown of the TLS private key exposure for Qihoo 360’s "Security Claw" AI Platform.
Read more here: https://dti.domaintools.com/research/exposure-of-tls-private-key-for-myclaw-360-in-qihoo-360-security-claw-ai-platform
#CyberSecurity #ThreatIntel #AI #InfoSec
📰DTI’s latest research dives into the dev-ops of disinformation campaigns. Read our investigation into the Doppelgänger / RRN disinformation ecosystem here 👇
https://dti.domaintools.com/research/doppelganger-rrn-disinformation-infrastructure-ecosystem
🪷 The Petals of Espionage: DomainTools Investigations’ latest research analyzes the “who” ,“how”, and “why” behind Lotus Blossom’s compromise of Notepad++.
Read the investigation: https://dti.domaintools.com/research/lotus-blossom-and-the-notepad-supply-chain-espionage-campaign
This "ChatGPT Ad Blocker"🚧 extension is a data-harvesting tool.
It clones your ChatGPT conversations and sends them to a Discord webhook.
Learn more: https://dti.domaintools.com/securitysnacks/securitysnack-openai-anti-ads-malware
Targeting the Talent: The Rise of "Phishing Interviews" 🎣
Job seekers are the latest target in scams uncovered by the DomainTools Investigations (DTI) team. Read our investigation here: https://dti.domaintools.com/securitysnacks/securitysnack-phishing-interviews
#CyberSecurity #ThreatIntel #Phishing #JobHunt
Spring is here in Seattle🌷, and the March DTI newsletter is live📰.
In this edition Daniel Schwalbe recaps a busy month of research, Ian Campbell's monthly reading list, and where to find us next! https://dti.domaintools.com/newsletters/fifteen-newsletters-on-a-skateboard
🕵️DTI released an analysis of activity attributed to Homeland Justice, Karma/KarmaBelow80, and Handala as a single, coordinated cyber influence ecosystem aligned with Iran’s MOIS.
Read our investigation here: https://dti.domaintools.com/research/handala-mois-linked-cyber-influence-ecosystem-threat-intelligence-assessment
#Cybersecurity #Iran #InfoSec #ThreatIntel
Stop responding to threats and start predicting them. 🛑 Find us at #RSAC to see how our new Real-Time Threat Feeds can help you identify malicious infrastructure before it’s weaponized.
Schedule a meeting with the DomainTools team in SF ⬇️
https://www.domaintools.com/events/rsac-2026
One last February note 💌 The latest Daniel Schwalbe newsletter is here, featuring the DTI team’s latest analysis! Read it here👇 https://dti.domaintools.com/newsletters/fourteen-newsletters-and-fifteen-winters
It’s Day # 2 of #AFCEAWest, and DomainTools Federal is here at the San Diego Convention Center. Stop by Booth # 2309 to talk to our team about how we give you the offensive edge against state sponsored adversaries.
Want to see how the world's best CTI teams map adversary DNS? 🗺️
We’re heading to #BlackHatAsia 2026 to share how we provide 97% internet visibility and detection 10 days ahead of blocklists.
Let's grab coffee! Book 20 mins here ➡️ https://www.domaintools.com/events/black-hat-asia
#BHA2026 #OSINT
DomainTools Federal is at #AFCEAWest at the San Diego Convention Center! Stop by Booth # 2309 to learn how we’re giving bad actors more bad days.
Shift your posture from reactive to proactive at #BHA2026. 🇸🇬
With DomainTools, your team can:
✅ Automate the hunt
✅ Contextualize alerts
✅ Get more from your existing stack
Meet us in Singapore ➡️ https://www.domaintools.com/events/black-hat-asia
#BlackHatAsia #ThreatIntel
From fake BTC “doublers” to wallet-draining presale sites, DTI uncovered a crypto scam network spanning ~250 domains impersonating public figures like Elon Musk and President Donald Trump.
Read the investigation ⬇️ https://dti.domaintools.com/securitysnacks/securitysnack-idolized-crypto-scams
#Cybersecurity #Scams #Crypto #Infosec
We’re heading back to Lille for #FIC2026 🇫🇷
Catch us on April 2 at 2:00 PM to see how security teams are getting real-time insight into malicious infrastructure and staying ahead of attackers.
📅 Book time: https://calendar.app.google/eNsysJgTdz7b4ab56
Make your security tools work smarter not harder. 🛠️ At #RSAC, we’re sharing how DomainTools data integrates with your SIEM, SOAR, and even LLM solutions to reduce cyber risk and boost efficiency.
Sign up to meet our product team ⬇️
https://www.domaintools.com/events/rsac-2026
Access DomainTools via the Model Context Protocol (MCP) 🌐
Connect your LLM or MCP enabled platform directly to our data to:
✅ Automate data retrieval and analysis
✅ Reduce context-switching
✅ Investigate at the speed of AI
Click here to learn more: https://www.domaintools.ai/mcp-access.
Heading to #RSAC 2026? 🌉 Let’s grab 10 minutes to discuss how our DNS infrastructure analysis keeps you ahead of the curve.
Book a coffee chat here ⬇️
https://www.domaintools.com/events/rsac-2026
How do you make AI work for you in the SOC?
Join our webinar with DomainTools MCP experts Taylor Wilkes-Pierce, VP of Solutions Engineering, and Dan White, VP of Product Management to learn how the MCP server acts as an instant force multiplier.
🔗www.domaintools.com/webinars/supercharging-the-soc-with-domaintools-mcp?utm_campaign=mcpwebinar&utm_medium=social&utm_source=mastadon
Connecting your LLM to DomainTools is an instant force multiplier ⚡
Analysts get Domain intelligence directly in their chat interface. No context-switching - just natural language answers at the speed of chat.
Technical breakdown & examples ⬇️ https://www.domaintools.com/blog/integrating-domaintools-into-the-ai-powered-soc
We’re thrilled to announce our new MCP server, enabling you to access DomainTools intelligence directly within your AI workflows. Use natural language prompts for instant analysis of risky infrastructure - no new UI involved.
Learn more today: http://www.domaintools.com/press/domaintools-launches-mcp-server-connecting-ai-agents-directly-to-20-years-of-domain-intelligence
📍 Singapore bound for #BHA2026!
Stop by DomainTools booth # 119 to see how our integrations reduce context-switching and identify evolving threats in real-time.
Don't leave your 2026 strategy to chance. Schedule a chat➡️ https://www.domaintools.com/events/black-hat-asia
#BlackHatAsia #CyberSecurity
The most critical indicators, all in one place
New enhancements to the DomainTools App for Cortex by Palo Alto Networks deliver real-time streaming of critical intelligence feeds, providing seamless access to DomainTools data across Cortex.
Learn more: https://www.domaintools.com/blog/domaintools-palo-alto-networks-best-in-class-dns-intelligence
We’re looking forward to #FIC2026 and connecting with the security community.
At DomainTools, we’re focused on bringing Real-Time risk data into the tools teams already use – from SIEM/SOAR to emerging LLM security workflows.
Lets connect in Lille 👇
https://calendar.app.google/eNsysJgTdz7b4ab56
The DomainTools team is at #RSAC2026 holding meetings at Spaces. In case you missed it, you can still schedule a meeting with us at the link here: https://www.domaintools.com/events/rsac-2026