<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat-Intelligence on CuraSec</title><link>https://curasec.metacog.co.kr/tags/threat-intelligence/</link><description>Recent content in Threat-Intelligence on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 19:07:02 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/threat-intelligence/index.xml" rel="self" type="application/rss+xml"/><item><title>DisCTI: ML-Based Automated Sector Routing for Cyber Threat Intel</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-discti-who-needs-to-know-timely-automated-sector-aware-cyber/</link><pubDate>Mon, 31 Aug 2026 19:07:02 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-discti-who-needs-to-know-timely-automated-sector-aware-cyber/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The finding that 98% of MISP events lack sector tagging quantifies a real operational gap in shared CTI value; the BERT-based approach achieving F1 0.89 for sector routing is worth tracking as a future tooling direction for CTI triage workflows.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The statistic that nearly all shared CTI events go uncategorized by sector is a useful benchmark for conversations about the operational return on threat intel program investments; no action is required now, but it frames the value case for better-structured intel feeds.&lt;/li>
&lt;/ul></description></item><item><title>Reproducible Pipeline for Labeling Illicit Bitcoin Addresses from HackForums</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-extracting-and-verifying-illicit-bitcoin-addresses-from-unde/</link><pubDate>Mon, 17 Aug 2026 13:03:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-extracting-and-verifying-illicit-bitcoin-addresses-from-unde/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> A dataset of 2,438 verified illicit Bitcoin addresses with HackForums provenance and cybercrime category labels could enrich threat intel feeds or wallet-screening tooling; no immediate detection action required, but worth evaluating the released dataset for integration.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>TTP-R1: RL-Driven ATT&amp;CK Technique Extraction from CTI Text</title><link>https://curasec.metacog.co.kr/insights/2026-08-10-retrieval-constrained-policy-optimization-for-attack-techniq/</link><pubDate>Mon, 10 Aug 2026 13:39:41 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-10-retrieval-constrained-policy-optimization-for-attack-techniq/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> TTP-R1 automates mapping CTI prose to ATT&amp;amp;CK (sub-)techniques with meaningful F1 gains over LLM baselines; worth tracking if your team annotates CTI at scale, but no detection or hunt action follows from this research paper alone.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Unit 42: Identity-Based Attacks Drive 90% of SOC Incidents</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-inside-the-modern-soc-the-identity-front-door/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-inside-the-modern-soc-the-identity-front-door/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Unit 42&amp;rsquo;s analysis of identity-based attack patterns offers context for triage judgment and detection prioritization, though no specific IOCs or new TTPs are surfaced in the summary.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The 90% statistic is a potential board-deck data point, but without independent corroboration of the underlying methodology this is vendor-sourced framing rather than actionable risk input.&lt;/li>
&lt;/ul></description></item><item><title>Google Threat Intelligence Group adopts unified actor naming schema</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-updated-cyber-threat-actor-naming-system/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-updated-cyber-threat-actor-naming-system/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> GTIG is merging Mandiant and TAG naming systems into a cryptonym-based taxonomy; analysts should update internal runbooks and intel mappings to cross-reference old identifiers (e.g. APT numbers) with new names as GTIG rolls out the change.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Unit 42 2026 Global Incident Response Report: AI &amp; Automation Trends</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-ai-automation-and-attacks-unpacking-the-unit-42-2026-global/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-ai-automation-and-attacks-unpacking-the-unit-42-2026-global/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Unit 42&amp;rsquo;s IR report covers AI-assisted attack patterns and automation trends observed across real incidents; useful for calibrating triage judgment and updating mental models of adversary tempo, but no specific IOCs or detections to act on now.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Annual IR benchmarking data from a major vendor is useful for board deck context and budget justification around AI-related threat trends, though it should be weighed against independent corroboration given the Palo Alto source.&lt;/li>
&lt;/ul></description></item></channel></rss>