All Newsletters

Valid Points · February 2026

MISP Integration, YARA Improvements, and More

We're excited to announce a MISP integration, YARA improvements, and more in this month's newsletter.

Welcome back to Validin's monthly newsletter and thank you for inviting us into your inbox. This month we are excited to announce a MISP integration and YARA improvements. Additionally, this past month we published a deep dive on the Notepad++ compromise. As always, we appreciate any feedback! - The Validin Team

misp-integration-yara-validin

PLATFORM UPDATES

💬 MISP Integration and YARA Improvements

  • Validin is now available as a MISP expansion module, enabling enrichment of MISP events across all Validin data sources
  • YARA hunts now support both Validin’s virtual host and IPv4 scanning data, expanding visibility to more ports and services

👉 Read the full update blog now.

notepad++-c2-validin

IN CASE YOU MISSED IT

Exploring the C2 Infrastructure of the Notepad++ Compromise

Through Validin's persistent and rapid scanning, we uncovered several new indicators related to previous reports. Access the investigation here

ja4-fingerprints-validin

Introducing JA4+ Fingerprints

We recently introduced JA4+ capabilities, starting with JA4X available to Community and Enterprise users. Read the complete update blog now

pivotcon-2026

👋 See you in Spain

We are excited to announce our continued support of PIVOTcon, an event that focuses on threat research and technical analysis tradecraft. We attended last year and are excited to return to Malaga, Spain as attendees.

Learn more about PIVOTcon

SPOT VALIDIN IN...

🦀 Analysis of ClawHub Malicious Skills Poisoning

The SlowMist security team released an in-depth analysis on ClawHub, the plugin hub for OpenClaw. Read their analysis now.

🎧 Three Buddy Problem | From Epstein to Notepad++: Redactions, Zero-Days and Supply Chain Attacks

Validin was recently featured on the Three Buddy Problem podcast. Listen to the full episode.

💳 When the Checkout Bleeds: An Analysis of Skimming Campaigns in LATAM

The Sage Hollow featured Validin in its recent analysis of skimming campaigns in Latin America. Read the analysis now.

BY THE NUMBERS

Top Viewed Threat Actor Profiles and their position change from last month. If you're logged into Validin, view the full profiles:

  1. Lazarus Group

  2. Poseidon Group (+1)
  3. Lumma Stealer (+1)
  4. ClickFix (-2)
  5. APT38 (new)

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company