Skip to main content
Jeremy Nichols

Jeremy Nichols

Cybersecurity Expert

About Jeremy Nichols

Cybersecurity Leader | Mentor | Threat Intelligence

Technical and innovative leader in the realm of cybersecurity and threat intelligence. Extensive track record of success across analyst, engineer, architect and leadership roles.

Posts by Jeremy Nichols

Byer-Nichols Threat Brief for November 16-30 2025

Byer-Nichols Threat Brief for November 16-30 2025

Qilin leads ransomware activity this period, with CL0P and Akira close behind. Newer and mid-tier groups like Sinobi and DragonForce show rising impact. Victims are primarily small US-based businesses, with manufacturing, technology, retail, and construction most affected.

December 2, 2025

Byer-Nichols Threat Brief for November 1-15 2025

Byer-Nichols Threat Brief for November 1-15 2025

One of the most concerning developments over this period has been the discovery of zero-click vulnerabilities in Samsung mobile devices, which have already been actively exploited by the Landfall spyware.

November 17, 2025

Byer-Nichols Threat Brief for October 16-31 2025

Byer-Nichols Threat Brief for October 16-31 2025

The recent theft of source code from F5 has seen over a quarter of a million F5 BIG-IP instances exposed to potential remote attacks via the Internet, and in terms of victim locations, we see a notable change in this period, with Australia joining the top 5.

November 3, 2025

Byer-Nichols Threat Brief for October 1-15 2025

Byer-Nichols Threat Brief for October 1-15 2025

The emergence of the Scattered LAPSUS$ Hunters 'Trinity of Chaos' has made headlines in recent weeks with their daring extortion attempts of large enterprises whose data they had stolen from SalesForce instances.

October 17, 2025

Byer-Nichols Threat Brief Cybersecurity Data For September 16-30 2025

Byer-Nichols Threat Brief Cybersecurity Data For September 16-30 2025

Of concern in this period is a rise in attacks against Cisco ASA and IOS XE devices, highlighting the exposure of critical network infrastructure. On the malware side, Brickstorm and MetaStealer are showing increased activity, with several lightweight loaders tied to state-backed groups also in play.

October 3, 2025

Byer-Nichols Threat Brief Cybersecurity Data For September 1-15 2025

Byer-Nichols Threat Brief Cybersecurity Data For September 1-15 2025

Of concern in this period is an increase in attackers compromising devices from vendors including SonicWall and especially TP-Link. With many of these being consumer devices, compromises often go undetected for long periods, if they are ever noticed.

September 18, 2025

Byer-Nichols Threat Brief Cybersecurity Data For August 16-31 2025

Byer-Nichols Threat Brief Cybersecurity Data For August 16-31 2025

We all knew that sooner or later we would start to see malware that leverages generative AI. PromptLock, which was recently discovered by ESET, makes use of GenAI to analyze files on victim systems to work out whether to encrypt or exfiltrate the files.

September 3, 2025

Byer-Nichols Threat Brief Cybersecurity Data For August 1-15 2025

Byer-Nichols Threat Brief Cybersecurity Data For August 1-15 2025

Small businesses continue to dominate the ranks of breach victims at 84.25%. When we consider that small businesses represent about half of employment globally and about 44% of US GDP they fall victim to more than their fair share of cyber-attacks.

August 18, 2025

Byer-Nichols Threat Brief Cybersecurity Data For July 16-31 2025

Byer-Nichols Threat Brief Cybersecurity Data For July 16-31 2025

Since our previous brief, Qilin and INC ransomware remain the two most dominant types of ransomware. We do however have a new entrant in the top 5, with Beast representing 6.35% of ransomware attacks.

August 5, 2025

Byer-Nichols Threat Brief Cybersecurity Data For July 01-15 2025

Byer-Nichols Threat Brief Cybersecurity Data For July 01-15 2025

July 2025 cyber threats: Qilin ransomware hit 16.3% of attacks, targeting small businesses (80.6%) in manufacturing & tech. U.S. most affected (49%). Gamaredon, Scattered Spider active. Critical exploits: CVE-2025-47812, CVE-2025-6554. North Korean IT fraud, zero-days, €10M scam. Malware like Anatsa & Gh0stRAT surged. Stay protected!

July 21, 2025