CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Gambit Security

gambit-security · B · candidate

https://gambit.security/news-resources

researchlang: enfetch failures: 0quiet periods: 0last fetch: 2026-09-23

Israeli threat-intelligence firm; primary MOIS / Iran-linked research. Discovery 2026-05-28: published technical attribution of LACMTA destructive breach to Ababil-of-Minab persona / Iran MOIS via Black Shadow infrastructure overlap. Candidate; promote to active after 3 runs with content contribution. | 2026-06-21 (v2.62): canonical listing corrected to https://gambit.security/news-resources, verified live (drill=Y), a server-rendered index carrying real hrefs to /blog-posts/<slug>, /news/<slug> and /announcement/<slug>. FETCH → webfetch https://gambit.security/news-resources for the index, then webfetch the individual post URL for the body. AVOID: Do NOT use https://gambit.security/blog-posts, that path 404s (no listing index lives there); this supersedes the 2026-06-20 WebSearch slug-discovery workaround. The bare homepage is a JS-rendered Webflow SPA with no usable hrefs, use /news-resources instead.. | 2026-07-05 admiralty audit: B, original threat research corroborated by tier-1 press; stays candidate (still building pipeline track record). NOTE: canonical domain is gambit.security/blog-posts/<slug>; the WebFetch summariser mangles hrefs to www.gambitsecurity.com. | 2026-09-15 intel run: gambit.security/news-resources is JS-rendered with no article listing recoverable via trafilatura extraction; only navigation chrome returned. | 2026-10-04: `extract` of /news-resources shows only the featured post. Working recipe: `url https://gambit.security/blog` returns the /blog-posts/<slug> links (no dates), then `extract` each post (date: field reliable).

Cited in 2 entries

Citation cadence

Citation days per ISO week (18 weeks of coverage span, total 2).