<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><id>https://hecavex.com/en/</id><title>HECAVEX — Cyber Threat Intelligence & Digital Investigations</title><subtitle>Researching the infrastructure, behaviour and people behind digital threats.</subtitle><updated>2026-08-01T20:41:14+03:00</updated><link rel="self" type="application/atom+xml" href="https://hecavex.com/en/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://hecavex.com/en/"/><author><name>Hecavex</name><uri>https://hecavex.com</uri></author><entry><title>Confidence Is a Field, Not a Feeling</title><link href="https://hecavex.com/en/research/confidence-is-a-field/"/><id>https://hecavex.com/en/research/confidence-is-a-field/</id><published>2026-08-01T13:00:00+03:00</published><updated>2026-08-01T13:00:00+03:00</updated><summary>A short note on how HECAVEX will communicate analytical confidence and distinguish evidence from inference.</summary></entry><entry><title>Introducing HECAVEX</title><link href="https://hecavex.com/en/research/introducing-hecavex/"/><id>https://hecavex.com/en/research/introducing-hecavex/</id><published>2026-08-01T12:00:00+03:00</published><updated>2026-08-01T12:00:00+03:00</updated><summary>Why HECAVEX exists and how this independent threat intelligence publication will approach evidence, uncertainty and digital investigations.</summary></entry><entry><title>Information Factories on Lithuania&apos;s Border: How Russian and Belarusian Information Operations Target Lithuania, NATO, and Europe</title><link href="https://hecavex.com/en/research/information-factories-on-lithuanias-border/"/><id>https://hecavex.com/en/research/information-factories-on-lithuanias-border/</id><published>2026-06-21T17:02:43+03:00</published><updated>2026-06-21T17:02:43+03:00</updated><summary>How Russian and Belarusian information operations manufacture, localise, and distribute narratives targeting Lithuania, NATO, and Europe.</summary></entry><entry><title>When Fake News, Scams, and Cloaking All Meet in One Place</title><link href="https://hecavex.com/en/research/when-fake-news-scams-and-cloaking-meet/"/><id>https://hecavex.com/en/research/when-fake-news-scams-and-cloaking-meet/</id><published>2026-06-15T17:21:51+03:00</published><updated>2026-06-15T17:21:51+03:00</updated><summary>An investigation into how fake news, investment fraud, and cloaking combine into a single victim-selection and monetisation infrastructure.</summary></entry><entry><title>ClickFix: Why Modern Threat Actors No Longer Look for Vulnerabilities—they Look for People</title><link href="https://hecavex.com/en/research/clickfix-why-modern-threat-actors-hunt-people/"/><id>https://hecavex.com/en/research/clickfix-why-modern-threat-actors-hunt-people/</id><published>2026-06-05T23:56:58+03:00</published><updated>2026-06-05T23:56:58+03:00</updated><summary>The anatomy of ClickFix campaigns: how fake verification prompts turn users into the execution mechanism and what SOC and CTI teams should detect.</summary></entry><entry><title>One Scam Domain Is Rarely Alone: Using Pivoting to Trace Fraud Infrastructure</title><link href="https://hecavex.com/en/research/one-scam-domain-is-rarely-alone/"/><id>https://hecavex.com/en/research/one-scam-domain-is-rarely-alone/</id><published>2026-06-03T18:09:38+03:00</published><updated>2026-06-03T18:09:38+03:00</updated><summary>A practical infrastructure-pivoting method for moving from one scam domain to related hosts, templates, and backend systems.</summary></entry><entry><title>MFA Is Not a Panacea, and It&apos;s Time We Stopped Pretending It Is</title><link href="https://hecavex.com/en/research/mfa-is-not-a-panacea/"/><id>https://hecavex.com/en/research/mfa-is-not-a-panacea/</id><published>2026-06-02T10:30:41+03:00</published><updated>2026-06-02T10:30:41+03:00</updated><summary>Why MFA is essential but insufficient against session theft, AiTM, token replay, OAuth abuse, and modern account takeover.</summary></entry><entry><title>The Centre of Registers Data Theft — Part 2</title><link href="https://hecavex.com/en/research/centre-of-registers-data-theft-part-2/"/><id>https://hecavex.com/en/research/centre-of-registers-data-theft-part-2/</id><published>2026-06-02T10:23:26+03:00</published><updated>2026-06-02T10:23:26+03:00</updated><summary>Part two of the Centre of Registers data-theft analysis, examining stolen identity, legitimate access, and gaps in behavioural detection.</summary></entry><entry><title>The Centre of Registers Data Theft: When “It’s Just Data” Suddenly Becomes a National Security Issue</title><link href="https://hecavex.com/en/research/centre-of-registers-data-theft-national-security/"/><id>https://hecavex.com/en/research/centre-of-registers-data-theft-national-security/</id><published>2026-06-02T10:12:36+03:00</published><updated>2026-06-02T10:12:36+03:00</updated><summary>Why large-scale theft from Lithuania&apos;s Centre of Registers is not merely a privacy incident but a potential intelligence and national-security issue.</summary></entry><entry><title>MISP for Cyber Threat Intelligence: Installation, Integration, and Automation. [Part 1]</title><link href="https://hecavex.com/en/research/misp-for-cti-part-1/"/><id>https://hecavex.com/en/research/misp-for-cti-part-1/</id><published>2025-03-02T13:00:00+02:00</published><updated>2026-08-01T12:00:00+03:00</updated><summary>A practical guide to installing MISP with Docker, understanding its threat-intelligence data model, integrations and automation options.</summary></entry><entry><title>Unveiling Hidden Dangers on GitHub: Malicious Python Scripts Sending Your Data to Hackers</title><link href="https://hecavex.com/en/research/github-and-malware/"/><id>https://hecavex.com/en/research/github-and-malware/</id><published>2024-11-10T13:00:00+02:00</published><updated>2026-08-01T12:00:00+03:00</updated><summary>A technical investigation of malicious Python code hidden in a GitHub project, its obfuscation and the remote infrastructure receiving stolen data.</summary></entry><entry><title>Unleashing the Dynamic Duo: OSINT and CTI for Proactive Defense against Cyber Threats.</title><link href="https://hecavex.com/en/research/cti-osint-duo/"/><id>https://hecavex.com/en/research/cti-osint-duo/</id><published>2023-10-18T14:00:00+03:00</published><updated>2026-08-01T12:00:00+03:00</updated><summary>How OSINT and cyber threat intelligence work together to reveal threat activity, improve context and support proactive security decisions.</summary></entry><entry><title>Unleashing the Power of OSINT. Google Dorking: Unveiling Hidden Treasures of the Web.</title><link href="https://hecavex.com/en/research/google-dorking/"/><id>https://hecavex.com/en/research/google-dorking/</id><published>2023-10-12T14:00:00+03:00</published><updated>2026-08-01T12:00:00+03:00</updated><summary>Learn how advanced Google search operators support OSINT investigations, cybersecurity research and the discovery of hard-to-find public information.</summary></entry></feed>
