- Engineer — Skip
- SOC/IR — Act: Joint US/UK/NL advisory details active Windows malware using Telegram as C2 with email exfil, screenshot, and audio capture capabilities; pull the full advisory for IOCs and hunt for anomalous Telegram API calls or beacon traffic patterns in your estate since the advisory’s disclosure date.
- Leader — Learn: Multi-government attribution of Iranian intelligence espionage tooling targeting journalists and dissidents; relevant background for risk context in media, NGO, or government-adjacent sectors, and useful framing for board discussions on geopolitical threat actors.