Blog

Technical insights on whitelist intelligence, SOC optimization, and reducing false positives

Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #11: Prove You're Human

This week's smartest bait isn't a link, it's a checkbox. "Prove you're human," it says, then it asks you to paste one line into a terminal. Two crews wrapped that trick in a name you already trust, from a government portal to HBO Max.

5 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #10: Wearing a Trusted Name

Reputation checks run on a simple bet: a name you recognize is a name you can trust. This week three separate crews cashed that bet in without breaking anything, routing a phishing chain straight through Google's own services and turning AI-provider infrastructure into a covert channel. Plus a MikroTik SSH zero-day, a Citrix NetScaler auth bypass under active attack, and thousands of Redis servers quietly mining.

5 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #9: The Layer Below the Address

A reputation check answers one question well: is this the right address? Two stories this week show what it misses when the trouble lives one layer down. A BGP hijack forged the route to a legitimate update server, and a China-linked crew turned trusted Cisco routers into listening posts. Plus routers backdoored at the factory, a state proxy network seized, and the end of a 23-year-old botnet.

5 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #8: Reputation You Can Borrow

A residential IP feels trustworthy because it belongs to a real home, a car, a TV box. This week two stories show how attackers rent that trust out from under people: a botnet that turns cars into proxies, and a bandwidth-sharing network churning through a thousand fresh exit IPs an hour. Plus npm packages hiding behind a CDN and a research paper on turning CDNs into amplifiers.

6 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #7: No Attacker Domain Required

Two campaigns this week ran their command-and-control entirely inside services a SOC can't block: a Python implant living inside Microsoft 365, and an espionage kit relaying through Google Apps Script. Plus a 14,000-camera botnet and a vCenter bug under active exploitation.

6 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #6: The Network Was the Hiding Place

Three attacks this week didn't beat the network trust signals a SOC relies on. They wore them: a 633-server proxy network, Midnight Blizzard on hotel Wi-Fi, and a proof-of-concept running on Cloudflare's own edge.

6 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #5: Popular Is Not the Same as Safe

Our weekly read on the infosec landscape through an infrastructure-reputation lens. This week: a self-replicating worm rode the trust of hundreds of hugely popular npm packages, Unit 42 turned AI loose and found 14,000 unreported bugs in mature open source, plus the Cisco ASA zero-days, an Azure Cosmos DB cross-tenant escape, and a coordinated OT campaign against Minnesota water systems.

6 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #4: The Trusted Middleman Was the Way Out

Our weekly read on the infosec landscape through an infrastructure-reputation lens. This week: OpenAI's own models escaped an eval sandbox through a self-hosted package proxy and breached Hugging Face, a phishing crew hiding inside 20+ Brazilian .gov.br portals, a botnet resolving its C2 through blockchain naming services, plus the Arista, Zimbra, and TeamCity bugs worth patching.

7 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #3: The Week the Channel Was the Brand

Our weekly read on the infosec landscape through an infrastructure-reputation lens. This week: C2 living inside a Microsoft 365 calendar, the carding market's hunt for 'clean' residential IPs, a botnet that ships with 90+ cloud ranges, plus the SharePoint, Palo Alto, and NGINX bugs worth patching.

6 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #2: The Week AI Built the Botnet

Our weekly read on the infosec landscape through an infrastructure-reputation lens. This week: AI agents spinning up C2 in minutes behind trusted infra, npm and GitHub abused at scale, and the first US sanction of a VPN provider for enabling ransomware.

4 min read
Reput.io Team
Read More
Threat IntelligenceInfrastructure ReputationSOC

Reputation Radar #1: The Week Attackers Rented Trust

Our weekly read on the infosec landscape, seen through an infrastructure-reputation lens. This week: agentic botnets on trusted AI tools, the NetNut residential-proxy takedown, proxyware in fake installers, fake Google/Cloudflare pages, an 81M-attempt run at Microsoft 365, a tricked GitHub AI agent, North Korea's PolinRider campaign, plus the active-exploit news worth patching for.

5 min read
Reput.io Team
Read More

Ready to Reduce False Positives?

Start using whitelist intelligence today. Free plan includes 500 queries/day.