ReliaQuest Threat Research
reliaquest · B · active
Added as candidate 2026-07-10 (one new candidate this run), cited as published primary for the Helix data-extortion entry (2026-07-10). ReliaQuest Threat Research publishes identity-attack / data-extortion kill-chain analysis (device-code phishing, SharePoint exfil, BlackFile/ShinyHunters ecosystem tracking). FETCH: jina reader on reliaquest.com/blog/<slug> returned full clean markdown this run. Promote to active after 3 contributing runs. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 4 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs, the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-07-27 intel run: source_health probes bridge-ok, but S3 reports both WebFetch and the direct bridge return only site chrome/nav; the post grid is client-side rendered and no RSS feed was found. Host reachable, recipe does not reach content; fetch_method is already jina. Needs a structured endpoint. Not a demotion. | 2026-09-13 quality audit (G3 broken-recipe duty, closing 2026-09-06 recommendation 3): STILL BROKEN, now diagnosed rather than suspected. Probed this run with extract, jina AND bridge url: every transport returns a marketing/navigation shell with no reachable dated article listing. Not a 403 and not a UA refusal; the listing content is simply not in any served response. Left active and NOT demoted so it stays visible to the operator; raised as an audit recommendation instead. Note it is pinned fetch_method jina, which spends metered credit for a shell. | 2026-09-20 quality audit (G3 re-probe): the pinned jina transport still returns a content-free ad-tracker probe page, so it spends metered reader credit for nothing. PARTIAL RECOVERY: python3 tools/fetch_source.py url https://reliaquest.com/sitemap.xml returns real dated /blog/ URLs (newest lastmod 2026-09-10 at probe time, outside the window); drill per-article from there. fetch_method moved off jina to bridge on that basis.
Cited in 5 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 5).
- An MDR vendor denies a circulating compromise claim and publishes what actually happened: a phone-call phishing attempt that got one MFA push approved, and a device-trust policy that made the resulting session useless2026-08-24
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff2026-08-01
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration2026-07-10
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20
- OP-512: China-linked cluster runs a cryptographically-unique, self-reporting IIS web-shell framework against legacy .NET servers2026-06-06