All Newsletters

Valid Points · September 2026

September at Validin: Open Directories, iOS Malware Research, and More

Open Directories is now in beta, letting researchers search and compare files exposed across the internet

Validin: VALID POINTS Newsletter

Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. In September, we launched Open Directories in Beta, giving researchers a new way to discover and investigate exposed files across the internet; continued building out new functionality across the Validin platform; and were excited to see iVerify publish great research on the Coruna and DarkSword iOS malware, including infrastructure that can be investigated and pivoted on in Validin.

The Validin Team

Introducing Open Directories to Validin

PLATFORM UPDATES

Introducing Open Directories to Validin

This month, we launched Open Directories in beta for Validin Enterprise customers. The new dataset lets researchers search, browse, and compare files exposed across the internet, using infrastructure attributes like domain, IP address, and port alongside file metadata such as filename, path, extension, size, modification time, content type, and hashes. Analysts can also preview collected files and compare directory captures over time to see what was added, removed, or changed.

👉 Read the full write up here

BY THE NUMBERS

Top-viewed threat actor profiles and how their ranking changed from last month. If you're logged into Validin, you can view the full profiles:

  1. ClickFix (+1)
  2. Kimsuky (+1)
  3. Lazarus Group (+1)
  4. Scattered Spider (new)
  5. MuddyWater (-4)
iVerify: The Proliferation of Coruna and DarkSword

RESEARCH

Proliferation of Coruna and DarkSword

This month, iVerify published new research on the continued proliferation of the Coruna and DarkSword iOS exploit kits. Kevin Hoganson and Mateusz Krzywicki from the iVerify team used Validin alongside custom tooling to help uncover additional infrastructure and track new variants of both frameworks, including deployments combining the two exploit kits.

👉 Read the writeup from iVerify here

Elastic Security Labs: Revstealer

IN CASE YOU MISSED IT

New infostealer being tracked by Elastic

Check out the latest research from Elastic Security Labs on Revstealer, a credential harvesting infostealer.

Learn more about Revstealer

Validin and Malfors

Validin now has a Malfors integration

Malfors now integrates with Validin.

Learn more about Malfors and the Validin integration

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company