Cyber Dispatch™️
403 subscribers
34 photos
4 videos
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch
Download Telegram
FBI to ShinyHunters: 'We know how to find you'.
Behind the Verdict: A Analyst’s Guide to the Vendors Powering Multi-Engine Threat Detection

By Yara Tabet
September 30, 2026

When I submit a suspicious file or URL to VirusTotal, I do not treat the resulting vendor verdicts as absolute truth. A “Clean” result means no engine detected a threat at that moment. It does not mean the file is safe. Understanding who these vendors are—their origins, specialties, and limitations—is essential for accurate analysis. This guide is based on my review of public documentation, company filings, VirusTotal partner pages, and historical records conducted between January and September 2026. I did not independently test each engine. Where claims come from vendor marketing, I note that.

European and Russian Origins

Kaspersky is a Russian company founded in Moscow in 1997 by Eugene Kaspersky. Its origin story dates to 1989, when a Cascade virus infection sparked his interest. Kaspersky operates globally but faces geopolitical scrutiny; the U.S. banned its software from federal systems in 2017. Sophos, founded in Oxford in 1985, is a British security firm acquired by Thoma Bravo in 2020. ESET (Slovakia, 1992), Bitdefender (Romania, 2001), G Data (Germany, 1987), Dr.Web (Russia, 1992), and Emsisoft (Austria, 2003; now New Zealand) round out the European antivirus tradition. Avira, AVG, and Avast also contribute engines through various acquisitions.

Asian and Regional Players

Quick Heal (India, 1995) holds multiple patents in ransomware protection. Rising (China, 1991) serves Chinese government clients. Antiy-AVL (China) is a threat detection leader. ESTsecurity, AILabs (MONITORAPP), and ZeroCERT are South Korean firms specializing in endpoint, AI threat intelligence, and live forensics. Lionic (Taiwan) focuses on embedded antivirus and DPI. Sangfor (China, 2000) is a major Asia-Pacific network security vendor. Viettel Threat Intelligence (Vietnam) monitors dark web activity and has detected millions of stolen accounts. CyRadar (Vietnam, backed by FPT) is a rising regional player. Criminal IP by AI SPERA (South Korea) offers AI-driven threat intelligence.

Network, Cloud, and Web Security Platforms

Fortinet (2000) remains a network security giant. Forcepoint ThreatSeeker analyzes web and email traffic at scale. Google Safe Browsing and Yandex Safe Browsing provide URL reputation. Webroot (Colorado, 1997) pioneered cloud-based endpoint protection; it is now part of OpenText. Acronis offers integrated cyber protection. Heimdal provides unified security and compliance. AlienVault created the Open Threat Exchange and is now part of LevelBlue, a 2024 AT&T and WillJam Ventures joint venture. Sucuri SiteCheck and Quttera scan websites for malware and defacement. ADMINUSLabs (India) provides threat intelligence. desenmascara.me helps unmask scam sites. BlockList, GreenSnow, CTX AI, Scantitan, Seclookup, ThreatHive, URLQuery, ViriBack, VX Vault, and Malwared provide blocklists, URL analysis, and malware repositories.

Community-Driven and Specialized Feeds

PhishTank (2006, OpenDNS) pioneered community phishing verification. OpenPhish uses automation to identify phishing sites. Phishing Database and URLhaus (abuse.ch) share active phishing and malware URLs. MalwarePatrol (2005) provides threat intelligence to over 175 countries. CINS Army offers a curated threat feed. EmergingThreats (now Proofpoint) maintains widely used IDS rules. Abusix focuses on network abuse and email security. Blueliv covers open, deep, and dark web intelligence. Certego provides Italian MDR services. CRDF is a nonprofit building global cyber capacity. Cyble has grown into a global dark-web and AI threat intelligence company. SOCRadar now offers agentic AI threat intelligence. SCUMWARE.org, sponsored by PREBYTES, offers free malware reports. StopForumSpam helps block spam accounts.

Non-Profit Standout: Chong Lua Dao
Chong Lua Dao (CLD) is a Vietnamese non-profit founded in 2020 by Ngô Minh Hiếu (Hieu PC). Hacker was arrested in 2013 and later extradited to the U.S. for an identity-theft operation affecting about 200 million Americans. After serving a 13-year sentence, he returned to Vietnam in 2020, joined the Vietnam National Cybersecurity Center, and became a white-hat defender. CLD combines a small analyst team with over 200 volunteers. Its API processes over one million daily queries, and it has detected over 1.4 million malicious websites. Its work has been cited in UNODC reports on Southeast Asian cybercrime. I note this background because it illustrates how diverse paths can lead to threat intelligence—and because a good analyst verifies sources, including a founder’s public record.

Trends and Implications for Analysts

Three trends stand out. First, consolidation: AlienVault into LevelBlue, Webroot into OpenText, and many smaller feeds into larger platforms. Second, the rise of non-profit and community feeds like CLD, URLhaus, and PhishTank, which fill gaps left by commercial vendors. Third, the shift to AI-driven detection, seen in OpenPhish, SOCRadar’s agentic AI, and Criminal IP. For analysts, this means vendor verdicts are signals, not verdicts. Always check the scan date, the vendor’s regional focus, and whether the detection is heuristic or signature-based. A “Clean” result from a single engine proves little.

Becoming a Security Analyst

A degree helps, but certifications and hands-on skills often matter more. Start with CompTIA Security+, then CySA+ for SOC roles, and GIAC GCTI for threat intelligence. Learn networking, operating systems, SIEM tools, Python, MITRE ATT&CK, and the Cyber Kill Chain. Practice on TryHackMe, Hack The Box, CyberDefenders, and LetsDefend. Join CTFs, follow open-source intelligence feeds, and build a public portfolio. Ethics and legal boundaries are non-negotiable.

These vendors form the global threat intelligence ecosystem. Whether you want to join them or simply read their verdicts more accurately, understanding who they are—and what they do not tell you—is the first step.

Disclosure: I have no financial relationship with any vendor mentioned. This article is for educational purposes and does not constitute endorsement. Some vendor claims are from company marketing and should be independently verified.

@TheGhostITM #TGITM
Spectre bug is back, this time to haunt JIT engines.
UK rail cops' £320K face-scanning spree nets zero matches.
A San Francisco hackathon rejected a former Israeli intelligence Unit 8200 engineer, telling him it didn't want Israel's military to make participants' pagers, phones and laptops "explode in their faces."

Organiser Mostapha Benhenda pointed to the 2024 pager attacks in Lebanon and later told the former Israeli intelligence member Adam Levi there was "no way to know" he wasn't involved.
Citrix NetScaler attackers are using a second-stage payload that creates a superuser and disguises a PHP web shell behind CSS-like URLs.

The same Perl script stages configuration data for upload, changes /bin/sh permissions, and erases itself after execution.
Attackers exploited a Zimbra flaw to plant web shells and harvest authentication secrets.

CVE-2026-73570 can be triggered by a crafted SMTP request when SNMP notifications are enabled and zimbra-snmp is installed.
Attackers are using phishing emails to turn legitimate MSP360 installs into a path for ScreenConnect.


Microsoft says the dual-RMM setup gives them redundant remote access, then supports tool delivery, information collection, and credential-access activity.
Cisco says attackers are exploiting a critical SD-WAN Manager authentication bypass.

CVE-2026-76504 lets a remote attacker access the Manager API as admin without credentials. Cisco has fixes, no workaround, and log checks for suspicious activity.
Attackers are abusing ChatGPT Custom GPTs to infect users with RAT malware.

Sponsored Google results lead to attacker-created GPTs, then to Google Sites pages with fake Cloudflare CAPTCHAs. Huntress says at least 40 users were infected.
Attackers are exploiting a Citrix NetScaler flaw to gain root access and hide PHP web shells behind .deb and .sig files.

The attacks also deploy SLAPSHOT, a Python tunneler. In at least one case, attackers used it for internal reconnaissance and credential theft.
Citrix NetScaler CVE-2026-88772 can turn 120 crafted DTLS records into root-level shellcode execution.

watchTowr’s new analysis shows how about 174 KB of reassembled data overruns a 35,840-byte scratch buffer, hijacks control flow, and uses mprotect() to bypass NX.

The flaw is already exploited in the wild.
Ukraine Seeks to Boost High-Tech Exports — Ukraine plans to export military and digital technologies, including AI, anti-drone systems, and digital government expertise, while moving data centers underground.
Private Firms Enter Cyber Warfare with AI — Bloomberg reported offensive cyber startups like RemoteThreat are raising funds to use AI for faster, broader attacks, with ex-NSA chief Paul Nakasone advising.
Bitget Exchange Loses $387 Million in Hack — Hackers exploited a zero-day in third-party security products to breach wallet infrastructure; Bitget’s CEO blamed North Korean hackers.
Trump Renames “AI” to “Superintelligence” in US Government — An executive order directs US agencies to use “superintelligence” instead of “artificial intelligence” in new documents and asks for legal definitions within 60 days.
Iran Official Warns Starlink Expansion Threatens Cyberspace Governance — Iran’s deputy ICT minister said Starlink’s independence from domestic infrastructure could undermine user management and authentication, with no clear policy yet.
DeepSeek and Huawei Team Up to Reduce Nvidia Reliance — DeepSeek is working with Huawei on programming tools for Ascend AI chips and a 128-chip Ascend 950 system, with open-source infrastructure planned.
TeamViewer Warns of High-Severity Vulnerabilities — TeamViewer Full Client and Host on Windows, Linux, and macOS are affected; one flaw could let a low-privileged local user create or modify files with higher access.
AI-Generated Fake Images Raise Election Misinformation Fears — A fake AI image of a Georgia mayor spread widely on Facebook, showing how deepfakes can distort political perceptions before being debunked.