CyberQuay cybersecurity companyCybersecurity is the practice of safeguarding digital systems, networks, and data from attacks, theft, and damage. It defends against threats like malware, ransomware, and phishing across all digital environments. As businesses become more digital, effective cybersecurity is essential to protect sensitive information, maintain operations, and preserve business continuity.

CyberQuay, Inc. specializes in cybersecurity solutions that protect the file formats most commonly used around the globe. The company’s technology strips away embedded malicious content from files before they can cause damage, making file sharing inherently safer. Instead of responding to cyber threats after a security breach happens, CyberQuay takes a proactive stance by securing the file containers that typically carry malware, tackling a significant portion of cyber risk at its source.

This upstream protection strategy offers several advantages. It restricts how cybercriminals can distribute harmful payloads and guarantees secure handling of widely used file formats. The approach also supports workplace efficiency by reducing interruptions from security incidents and decreases dependence on expensive, resource-heavy tools like sandboxing systems and endpoint detection platforms.

  • PowerShell in security actions

PowerShell, Both Ways: How Attackers Hide Payloads In It, and How Defenders Hunt Through It

August 27th, 2026|

PowerShell has always had two reputations. To an attacker, it's a scripting engine that's pre-installed on every Windows box, trusted by default, and powerful enough to download, decode, and execute a second-stage payload without ever writing a traditional executable to disk. To a defender, it's the same engine — and increasingly, via the Microsoft Graph SDK, the fastest way to query Entra ID sign-in logs, risk detections, and account hygiene at scale. The attacker side: a payload that doesn't even [...]

  • Medusa ransomware review

Medusa Ransomware Passes 500 Victims: Phishing Remains One of Its Doors In

August 21st, 2026|

Medusa ransomware has now affected more than 500 organizations since it was first identified in June 2021, according to an updated joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency, and the U.S. Department of Health and Human Services. Released on August 18, 2026, the update incorporates information from FBI investigations conducted as recently as April 2026. The victim list crosses multiple critical-infrastructure sectors, including healthcare, defense, critical manufacturing, government services, information technology, and financial services. Organizations in [...]

  • Microsoft August 2026 patch

Microsoft’s August 2026 Security Update: One Exploited Zero-Day, Four Server RCEs, and a SharePoint Chain

August 12th, 2026|

Patch prioritization is not a CVSS ranking exercise. This month's release shows why exploitation in the wild, service exposure, and the file that establishes initial access matter more than raw severity, and where a Content Security Layer fits alongside patching. Microsoft's August 2026 security release is another unusually large update cycle, but patch volume alone does not determine operational risk. The exact count depends on the methodology used. The Zero Day Initiative tallied 398 newly addressed CVEs, while SecurityWeek counted [...]

  • Bank of America phishing emails

When the Bank Email Ships a Script: A VBScript Phishing Chain and Where Content Security Actually Helps

August 5th, 2026|

A fake Bank of America notice ends with a silent remote-access install. The interesting part for defenders is where in that chain a file threat can be neutralized, and where it cannot. Huntress recently documented a phishing campaign that impersonates Bank of America and ends with a stealthy remote monitoring and management tool planted on the victim's machine. It is a good case study, not because any single step is novel, but because the chain shows exactly how a file-borne [...]

  • The AutoIT campaign

AutoIT Is Back: Why Script Interpreters Remain a Powerful Malware Delivery Layer

July 30th, 2026|

For years, defenders have associated malware with macros, Office documents, and suspicious executables. Yet attackers continue to rely on something far less conspicuous: legitimate scripting frameworks already trusted by the operating system. A recent analysis published by SANS Internet Storm Center demonstrates exactly how dangerous this approach remains. Threat actors are abusing AutoIT—a legitimate Windows automation platform—to deliver multi-stage malware that ultimately injects malicious code into trusted system processes. The campaign itself is not revolutionary. What matters is the architectural [...]

The Crypter Arms Race Is Unwinnable by Detection. Here Is Why the File Boundary Still Wins

July 27th, 2026|

A newly documented crypter service called Cruciferra rebuilds itself every few minutes and stitches together more than ninety custom encryption routines for the sole purpose of defeating signature and static analysis. It is a clear signal that detection-based defenses are structurally on the losing side of the delivery race. The question worth asking is not how to detect the undetectable, but whether the malicious file needs to arrive intact at all. In mid-July 2026, Proofpoint's Threat Research Team published an [...]

  • ACR Stealer malware

How WebDAV and MSHTA Delivery Turns One Lure Into an Invisible Theft

July 20th, 2026|

Threat Analysis  |  File-Based Delivery  |  FileDNA CADR Microsoft has warned enterprise defenders about a sustained surge in ACR Stealer activity that ran from late April 2026 into mid-June 2026, observed across customer environments by its Defender Experts team. The campaigns share a single social engineering entry point, the now familiar ClickFix lure, yet they split into two very different delivery and execution chains once a victim takes the bait. That divergence is the entire point. By varying how the [...]

  • Cisco Talos tracks UAT-11795

UAT-11795 Shows Why Modern Financial Attacks Are Won or Lost at the File

July 16th, 2026|

Threat Analysis · Content Analysis, Disarm and Reconstruction Cisco Talos has disclosed a financially motivated intrusion set it tracks as UAT-11795, a Russian-speaking group that has been active since at least June 2025 and has focused on victims in the United States and Europe, with additional cases seen in Germany, Romania, and Venezuela. The campaign is a clear example of how today's cybercriminals combine custom malware with carefully staged delivery to slip past traditional endpoint defenses. The operation relies on [...]

  • Microsoft patch Tuesday 622 vulnerabilities

Microsoft’s Largest Patch Tuesday Ever Delivers a Record Vulnerability Load

July 15th, 2026|

Microsoft's July 2026 Patch Tuesday is unprecedented by any measure. The company shipped fixes for a record vulnerability load that lands somewhere between 569 and 622 CVEs depending on how each vendor counts Windows-specific versus product-wide flaws, with Microsoft's own tally reaching 622 across 154 security updates. Either figure roughly triples the previous record of 198 CVEs set only a month earlier in June, and the year-to-date total already exceeds every full-year total from the past two decades. The sheer [...]

  • Vibe-coded malware

Vibe-Coded Malware Changes How Malware Is Built, Not How Enterprises Should Defend Against It

July 13th, 2026|

Attackers have found a faster way to write malicious code. They have not found a way to avoid delivering it. Artificial intelligence is rapidly changing the economics of cybercrime. Over the past year, security researchers have increasingly documented what has become known as vibe-coded malware, meaning malicious software produced largely through natural-language prompts rather than traditional software development. The concept is straightforward. Instead of spending hours writing PowerShell, JavaScript, or Python code by hand, an attacker describes the desired behavior [...]

  • FileDNA vs GigaWiper

GigaWiper and the File That Starts the Attack

July 12th, 2026|

What Microsoft found inside GigaWiper, and where preventing a single file stops the damage before it begins. In October 2025, Microsoft Threat Intelligence began seeing machines being wiped clean inside compromised networks. When researchers looked closer, they found the tool behind it. On July 9, 2026, Microsoft published its analysis of that tool, which it now tracks as GigaWiper. GigaWiper is not one program with one job. It is a Go-based backdoor that bundles several older attack tools into a [...]

  • multiplatform QuimaRAT

QuimaRAT Shows How Malware-as-a-Service Is Moving Beyond Windows

July 7th, 2026|

A new malware-as-a-service operation is giving lower-skill attackers a full cross-platform toolkit, and it says something important about where file-based attacks are heading in 2026. Researchers at LevelBlue SpiderLabs have published an analysis of QuimaRAT, a Java-based remote access trojan capable of running on Windows, Linux, and macOS from a single codebase. The finding is notable not because QuimaRAT is a particularly novel implant on its own, but because of what surrounds it. The threat actor behind it is not [...]

  • CADR vs ransomware groups

New Era of Ransomware Consolidation: Why Stopping Malicious Files Before They Execute Matters More Than Ever

July 4th, 2026|

Threat Landscape Analysis The ransomware landscape has shifted in a way that changes how defenders should think about risk. Instead of hundreds of loosely organized crews competing for scraps, the criminal ecosystem is consolidating around a small number of highly professionalized ransomware-as-a-service operations with mature infrastructure, aggressive affiliate recruitment and rapidly evolving tooling. Qilin has spent most of 2026 as the world's most active ransomware operation. Independent trackers differ on exact victim counts because they measure different things (leak site [...]

  • StrikeShark attack chain

StrikeShark and SharkLoader: How Modern Intrusions Still Begin at the File and Application Layer

June 27th, 2026|

A newly identified cyber espionage campaign tracked as StrikeShark shows how advanced threat actors keep combining public facing vulnerability exploitation, malicious software installers, and stealth memory loading techniques to quietly establish long term access inside high value enterprise environments. Security researchers have linked the activity to a previously undocumented malware family named SharkLoader, a custom loader designed specifically to deploy a Cobalt Strike Beacon while evading conventional endpoint detection. A Globally Distributed Targeting Campaign Researchers tracking the activity observed victims [...]

  • TA577 cybercrime active group

TA577 Group: The Growing Business of File-Based Cyberattacks

June 22nd, 2026|

Not every cybercriminal group spends its time building ransomware or developing advanced malware. Some focus on something much simpler, and often much more effective: getting inside organizations by tricking people into opening files they trust. One of the best examples right now is TA577, one of the most consistently active cybercrime groups operating today. Rather than running attacks from start to finish, TA577 mainly specializes in the earliest stage of compromise — delivering malicious files, phishing links, and carefully crafted [...]

  • malicious attachments used in VEC

VEC: One of Cybercrime’s Most Effective Attack Surfaces

June 15th, 2026|

How modern Vendor Email Compromise campaigns take advantage of everyday financial workflows, weaponized invoice files, and trusted supplier relationships to slip past traditional security controls. Business Communication Has Become a Trusted Delivery Channel for Attackers Most organizations run on a steady stream of contact with outside partners. Finance teams process invoices, procurement coordinates supplier contracts, sales exchanges quotes, and vendor managers talk daily with contractors, agencies, distributors, and service providers. All of that activity builds one of the most trusted [...]

  • June 2026 Patch Tuesday Breaks Records

June 2026 Patch Tuesday Breaks Records as AI Accelerates Vulnerability Discovery

June 10th, 2026|

Microsoft shipped one of the largest security updates in its history, and the volume itself is the story. Artificial intelligence is now finding flaws faster than organizations can deploy fixes. Microsoft's June 2026 Patch Tuesday landed as one of the largest security update releases the company has ever published, delivering fixes for roughly 200 documented vulnerabilities across Windows, Microsoft Office, Visual Studio Code, IIS, BitLocker, Azure components, and many supporting technologies. The release reflects a broad shift across the security [...]

Multi-Vector Phishing Operations: How Modern Cybercrime Has Evolved

June 5th, 2026|

Recent threat intelligence paints a clear picture: financially motivated cybercriminals keep getting more sophisticated, and they are increasingly willing to mix and match their methods. A single operation might combine large-scale phishing, social engineering written in the victim's own language, credential theft, remote access malware, and even legitimate administrative software, all aimed at breaking into organizations around the world. The days of relying on one favorite trick are fading. Today's attackers work from a flexible playbook, adjusting their approach based [...]

  • FileDNA helps address the risk of AI-embedded malicious data

The File Is the Payload: How Ordinary Documents Are Becoming Weapons for AI-Driven Attacks

May 31st, 2026|

A web page that makes ChatGPT show you a phishing link. A README that tells an AI coding assistant to run a malicious process. A PDF that instructs an AI agent to forward your emails. The threat is not in executable code anymore. It is in the data your AI systems are asked to read. In May 2026, a security researcher at Permiso Security published a straightforward demonstration. They took a normal public web page, added a small block of [...]

  • AI-powered cybercrime development pipeline

How Large Language Models Are Reshaping Cybercrime

May 30th, 2026|

The same artificial intelligence platforms that businesses use to draft emails, develop software, and automate routine tasks are increasingly being leveraged by cybercriminals. These tools are helping threat actors create malware, launch highly convincing phishing campaigns at scale, and automate attacks that previously required the resources and expertise of entire teams. This is no longer a theoretical concern or a future scenario—it is an operational reality unfolding today. In early 2025, three teenagers with no prior programming experience used an [...]

  • China's Hackers Are Following the Money and the Oil

China’s Hackers Are Following the Money and the Oil

May 30th, 2026|

A new ESET report covering October 2025 to March 2026 shows that China-aligned hacking groups are not choosing their targets randomly. Every intrusion links directly to something Beijing needs: oil supply visibility, reconstruction contracts, AI technology, or maritime intelligence. When a Chinese hacking group broke into a Venezuelan government agency in January 2026, it was not a random attack. A U.S. military operation in the region had just created uncertainty around Venezuelan oil exports, and China buys roughly half of [...]

  • Grandoreiro Banking Trojan

Grandoreiro: The Banking Trojan That Refuses to Die

May 28th, 2026|

What started as a regional Brazilian banking fraud tool in 2016 has grown into one of the most persistent financial malware operations on the planet. Law enforcement arrested its operators, dismantled its infrastructure, and declared victory. The malware came back stronger. Most malware families have a natural lifespan. They emerge, spread, get detected, and eventually fade as defenders adapt. Grandoreiro has spent nearly a decade defying this pattern. Originating in Brazil, it quietly expanded across Latin America, crossed the Atlantic [...]

  • JavaScript and PowerShell phishing attacks

How Attackers Use JavaScript and PowerShell to Steal Your Credentials

May 27th, 2026|

The PureLogs infostealer campaign is a textbook example of a technique that is spreading fast: use normal Windows tools to silently steal everything on your machine. Here is how it works, why it is so hard to stop, and what defenders can do. When most people think about malware, they imagine a suspicious file downloaded from a shady website. The reality in 2026 looks very different. Today's most effective attacks start with an ordinary-looking email, use tools that are already [...]

  • Microsoft SharePoint RCE vulnerability

Microsoft Patches a Dangerous SharePoint Flaw That Lets Attackers Run Code on Your Server

May 26th, 2026|

Any user with basic site access can exploit this vulnerability remotely. Here is what it means, how attackers have abused similar flaws in the past, and what you need to do right now. Microsoft has released a security patch for a newly discovered flaw in on-premises SharePoint Server, tracked as CVE-2026-45659. The vulnerability carries a CVSS score of 8.8 out of 10 and allows an attacker to remotely run malicious code on a SharePoint server without needing administrator access. Any [...]

  • AI vs. AI: How Machine Intelligence Became Both the Greatest Threat and the Strongest Defense

How Machine Intelligence Became Both the Greatest Threat and the Strongest Defense

May 25th, 2026|

Cybercriminals and defenders are racing to deploy artificial intelligence at scale. What happens when neither side is human anymore? For most of the internet's history, a cyberattack required a human at the keyboard. Someone had to craft the phishing email, probe the network, write the exploit, and decide when to strike. That model is becoming obsolete. In 2025 and into 2026, artificial intelligence has decoupled offensive capability from human effort at a scale that is genuinely unprecedented, and the same [...]

  • Anthropic - Project Glasswing announcement and vulnerability discovery data

A New Chapter in AI-Assisted Cybersecurity

May 23rd, 2026|

Anthropic has announced that its newly launched Project Glasswing initiative has already contributed to the discovery of more than 10,000 high- and critical-severity software vulnerabilities across some of the most widely deployed technologies in the world. Introduced last month, the program represents a significant step in the company's broader strategy to integrate AI into cybersecurity research at scale. At the core of the initiative is Claude Mythos Preview, an advanced frontier AI model purpose-built for vulnerability discovery and deep source-code [...]

  • Modern cybersecurity

Cybersecurity: From Reactive Defense to Continuous, Identity- and Content-Centric Security

May 22nd, 2026|

For decades, enterprise cybersecurity relied on a relatively stable defensive model. Organizations built security programs around perimeter protection, malware detection, network segmentation, antivirus engines, and signature-based analysis. The assumption was straightforward: malicious software would attempt to enter the environment, defenders would detect it, and security controls would contain or remove it before significant damage occurred. That model is now undergoing a profound transformation. The modern threat landscape is increasingly dominated not by traditional malware alone, but by identity compromise, browser-based [...]

  • Megalodon CI/CD supply chain attack

Operation Megalodon: Thousands of GitHub Repositories Backdoored in Coordinated CI/CD Supply Chain Attack

May 22nd, 2026|

An extensive software supply chain compromise campaign has exposed how modern CI/CD infrastructure can be weaponized at scale. In a highly automated operation tracked under the codename megalodon, attackers silently injected malicious GitHub Actions workflows into thousands of repositories in only a few hours, transforming trusted development pipelines into credential-harvesting platforms. According to research published by SafeDep on May 21, 2026, the operation targeted GitHub repositories by modifying automation workflows rather than directly altering application source code. The attackers focused [...]

  • CVE-2026-41091

When Your Antivirus Becomes the Attack Vector

May 22nd, 2026|

CVSS Score 7.8 (High) Severity High Disclosed May 19, 2026 CISA KEV Deadline June 3, 2026 Think you work in an office building with a security guard (Microsoft Defender) who has a master key to every room. You slip a fake sign on a broom cupboard that says "Server Room". The guard dutifully unlocks the actual server room on your behalf because they followed your sign without checking where it really pointed. That fake sign is a symbolic link: a pointer on the [...]

  • Cybersecurity software FileDNA in action

File-Based Malware Delivery and the Growing Role of Content-Aware Security

May 21st, 2026|

Modern cyberattacks increasingly rely on deception rather than direct exploitation. Instead of immediately deploying obvious malware binaries, threat actors now use carefully engineered social engineering campaigns designed to convince users to voluntarily download and execute malicious files. These attacks often begin with phishing emails, fake collaboration notifications, fraudulent invoices, cloned login portals, or malicious advertisements that redirect victims toward attacker-controlled infrastructure. In many cases, the downloaded payload initially appears harmless, disguised as a business document, compressed archive, CAPTCHA verification tool, [...]

  • PureLog infostealer phishing campaign

PureLogs Infostealer Is Going Global

May 20th, 2026|

Cybercriminals behind the PureLogs infostealer have been quietly expanding their reach, targeting Windows users worldwide through phishing campaigns that are a lot more creative and a lot harder to catch than what most organizations are prepared for. Fortinet researchers recently documented how these attackers are stashing malware inside ordinary image files, including pictures of cats, to slip past security tools that would normally flag a suspicious download. It's part of a wider pattern in modern cybercrime: ditch the obvious executable, [...]

  • Malicious SVG files

Malicious SVG Files: How Attackers Abuse Scalable Vector Graphics and Why Traditional Protections Are Not Enough

May 20th, 2026|

Scalable Vector Graphics (SVG) files are widely used across modern digital environments. They power website graphics, marketing assets, user interface components, email signatures, cloud-hosted content, QR codes, and responsive web applications. Because SVG files are typically associated with logos and illustrations, they are often perceived as harmless image files. That assumption is increasingly dangerous and measurably so. Security firms including Kaspersky, Trustwave, and Sophos have documented a dramatic rise in SVG-based attacks starting in late 2024 and accelerating sharply through [...]

  • File Recovery from Backup via WBAdmin.exe

ADVERSARIAL TECHNIQUE ANALYSIS: File Recovery from Backup via WBAdmin.exe

May 17th, 2026|

This research provides a comprehensive technical analysis of a post-exploitation technique that abuses Windows' native backup and recovery infrastructure to obtain sensitive system files that are normally protected on a live operating system. By leveraging wbadmin.exe — a Microsoft-signed, built-in administrative utility — an attacker with sufficient privileges can silently recover historical copies of credential stores and configuration files, bypassing modern endpoint defences entirely. The technique is particularly dangerous because it requires no custom tooling, leaves a minimal forensic footprint [...]

  • FileDNA active content analysis

Malware-Free Intrusions: How Modern Attacks Weaponize Trusted Tools and Active Content

May 16th, 2026|

Traditional malware is no longer required to compromise enterprise environments. Increasingly, threat actors are achieving full operational access without deploying conventional executable payloads at all. Instead of relying on ransomware binaries, trojans, or obvious malicious files, attackers are abusing legitimate administrative utilities, trusted scripting frameworks, cloud identity infrastructure, and active content embedded inside common business documents. This evolution has fundamentally altered the cybersecurity landscape. Many modern intrusions now resemble normal administrative activity rather than recognizable malware infections, allowing adversaries to [...]

  • Turla botnet modular architecture

Turla Rebuilds Kazuar Into a Resilient Peer-to-Peer Espionage Framework

May 16th, 2026|

The Russian state-sponsored threat group commonly tracked as Turla has significantly redesigned its long-running Kazuar malware platform, transforming the once monolithic backdoor into a modular peer-to-peer botnet engineered for operational resilience, stealth, and long-term intelligence collection. Associated with Russia's Federal Security Service (FSB), specifically Center 16, Turla has historically conducted cyber-espionage operations against government agencies, diplomatic entities, military organizations, and strategic infrastructure targets across Europe and Central Asia. The group is widely recognized under numerous aliases including Secret Blizzard, Snake, [...]

  • Salt Typhoon Chinese malware
  • Twill Typhoon Chinese malware

Chinese Cyber-Espionage Groups Expand Operational Scope and Evolve Intrusion Tooling

May 15th, 2026|

Several Chinese state-aligned advanced persistent threat (APT) groups have recently demonstrated both an expansion in targeting priorities and a noticeable evolution in their malware ecosystems. Recent investigations show these actors adapting their operations to geopolitical developments while continuing to refine long-term persistence strategies, modular malware delivery, and stealth-focused intrusion techniques. Salt Typhoon Shifts Focus Toward Strategic Energy Infrastructure During the period between December 2025 and February 2026, researchers identified a cyber-espionage operation attributed to Salt Typhoon, a Chinese-linked threat actor [...]

  • Microsoft on Tuesday released patches for 138 security vulnerabilities across its product ecosystem

Microsoft Patches: 138 security vulnerabilities across its product ecosystem

May 13th, 2026|

Microsoft on Tuesday released patches for 138 security vulnerabilities across its product ecosystem, although none of the flaws were reported as publicly disclosed or actively exploited at the time of release. Among the vulnerabilities addressed, 30 were classified as Critical, 104 as Important, three as Moderate, and one as Low severity. Privilege escalation vulnerabilities represented the largest category with 61 flaws, followed by 32 remote code execution vulnerabilities, 15 information disclosure issues, 14 spoofing flaws, eight denial-of-service vulnerabilities, six security [...]

  • Tycoon2FA Phishing Platform

Tycoon2FA Phishing Platform: Post-Takedown Rebuild

May 12th, 2026|

On March 4, 2026, Europol and Microsoft seized 330 domains belonging to Tycoon2FA, a phishing-as-a-service platform responsible for roughly 62% of adversary-in-the-middle (AiTM) phishing attacks blocked by Microsoft in early 2026. Operators began rebuilding the same day, and a fully operational new campaign was confirmed active by April 2, 2026 — just 20 days later. What Changed Infrastructure: Moved from Cloudflare (which was seized) to BunnyCDN for kill switch hosting, and to freshly registered Russian domains Lure hosting: AWS S3 [...]

  • TCLBANKER Banking Trojan Attack Workflow

TCLBANKER: A Sophisticated Brazilian Banking Trojan Targeting Banks and Cryptocurrency Platforms

May 12th, 2026|

Security researchers at Elastic Security Labs have uncovered a previously undocumented Brazilian banking trojan known as TCLBANKER, a malware family capable of targeting 59 financial organizations, including traditional banks, fintech services, and cryptocurrency platforms. The campaign is currently tracked as REF3076. Researchers assess TCLBANKER as a major evolution of the Maverick malware family, previously associated with a threat cluster identified by Trend Micro as Water Saci. Earlier activity from this group involved the SORVEPOTEL worm, which propagated through compromised WhatsApp [...]

  • AI-Developed Zero-Day Exploit Detected

AI-Assisted Hacking: Google Uncovers a Likely First

May 11th, 2026|

In an unsettling sign of things to come, Google has uncovered evidence that hackers used an AI program to discover a previously unknown software vulnerability that could have been exploited at mass scale, marking what the company believes is the first confirmed case of an AI-developed zero-day exploit. What Was Found According to a recent Google report examining AI-related cyber threats, the zero-day vulnerability targeted a widely used open-source, web-based system administration tool. Specifically, the flaw would have allowed attackers [...]

  • Quasar Linux RAT (QLNX)

QLNX: Covert Linux Implant Takes Aim at Developers and Software Supply Chains

May 8th, 2026|

A previously unknown Linux malware strain, designated Quasar Linux RAT (QLNX), has surfaced as a highly advanced threat with developers, DevOps engineers, and software supply chain environments squarely in its crosshairs. Security analysts at Trend Micro characterize the malware as a modular, stealth-focused remote access trojan purpose-built to infiltrate development ecosystems and siphon high-value credentials tied to cloud infrastructure, CI/CD pipelines, package registries, and containerized workloads. Unlike typical Linux malware that centers on persistence or data destruction, QLNX weaves together [...]

  • MSFT reports new phishing campaign

Microsoft warns of sophisticated phishing campaigns that bypassed multi-factor authentication

May 5th, 2026|

Microsoft's Defender Research team has disclosed a large-scale phishing campaign that used fake workplace compliance notices to lure employees into surrendering their Microsoft account credentials, and, critically, their authentication session tokens through an adversary-in-the-middle (AiTM) attack. Scale and targeting The campaign targeted more than 35,000 users across 13,000 organizations in 26 countries, with the United States accounting for many targets. Microsoft did not disclose how many accounts were successfully compromised. How the attack was constructed The campaign ran in waves [...]

  • Claude Security Platform

Anthropic Introduces Claude Security to Equip Defenders with AI-Driven Protection

May 3rd, 2026|

The cybersecurity landscape is evolving at a pace that traditional defensive approaches struggle to match. Advanced artificial intelligence models are no longer theoretical risks—they are already capable of identifying software vulnerabilities with high precision. Emerging generations of these systems are expected to go further, potentially automating the exploitation of those weaknesses. Systems such as Mythos model illustrate this trajectory, and similar capabilities will inevitably emerge across competing platforms. As these technologies proliferate, access will extend beyond legitimate use cases to [...]

  • Oracle April 2026 patch

Oracle: Overview of the April 2026 Critical Patch Update

April 22nd, 2026|

Oracle has released its April 2026 Critical Patch Update (CPU), delivering a substantial set of 481 security fixes across 28 product families. This update represents one of the more expansive remediation cycles in recent quarters and reflects the continued prioritization of network-exposed attack surfaces within enterprise environments. Notably, more than 300 of the addressed vulnerabilities are classified as remotely exploitable without authentication, placing them in the highest-risk category due to their accessibility over network interfaces and lack of prerequisite access [...]

  • two dozen fraudulent cryptocurrency applications targeting iOS users

FakeWallet Campaign: Fake Cryptocurrency Apps Found on Apple App Store

April 21st, 2026|

More than two dozen fraudulent cryptocurrency applications targeting iOS users have been discovered on the Apple App Store, according to Kaspersky. The campaign, known as FakeWallet, has been active since at least autumn 2025 and is designed to steal users' recovery phrases and private keys. The apps first drew attention in March when they began appearing frequently in Chinese App Store search results. Because many legitimate cryptocurrency wallet applications are currently blocked in China, attackers exploited that gap by mimicking [...]

  • ZionSiphon Malware Targets Water Infrastructure

ZionSiphon Malware Targets Water Infrastructure with Emerging OT Capabilities

April 20th, 2026|

Researchers at Darktrace have identified a previously undocumented malware strain, referred to as ZionSiphon, that appears to be engineered for targeting water treatment and desalination facilities in Israel. While the malware incorporates a range of capabilities commonly associated with commodity remote access tooling, its inclusion of operational technology (OT)–focused logic—particularly functionality interacting with industrial control systems (ICS)—marks it as a notable evolution toward infrastructure-focused cyber operations.Analysis of embedded strings within the sample strongly suggests geopolitical motivation. One decoded string explicitly [...]

  • weaknesses in Microsoft Defender to obtain elevated execution context

Attackers Exploit Microsoft Defender Zero-Days to Gain SYSTEM Privileges and Disrupt Protection Mechanisms

April 19th, 2026|

Huntress has identified active intrusion activity in which operators are leveraging a cluster of recently disclosed weaknesses in Microsoft Defender to obtain elevated execution context and degrade endpoint protection controls. Campaign Chains The campaign chains three publicly released zero-day techniques, BlueHammer, RedSun, and UnDefend, that originally published by the researcher operating under the aliases Chaotic Eclipse and Nightmare-Eclipse following a dispute over disclosure timelines. The researcher expressed frustration with Microsoft's handling of the vulnerability disclosure process on April 2, 2026, [...]

  • Cargo Theft Actor by Proofpoint report

Beyond the Breach: Inside a Cargo Theft Actor’s Post-Compromise Playbook

April 16th, 2026|

In late February 2026, Proofpoint researchers executed a malicious payload from a threat actor targeting transportation organizations inside a controlled decoy environment operated by their partners at Deception.pro. Unlike typical short-lived sandbox observations, the environment was intentionally left accessible for over 30 days, enabling full-spectrum visibility into post-compromise activity, operator decision-making, and iterative tooling deployment.The attacker abused multiple remote access tools to establish persistence, including the use of a previously unknown third-party signing-as-a-service capability. Proofpoint also observed extensive reconnaissance to [...]

  • The exploited SharePoint Server vulnerability is tracked as CVE-2026-32201 and it has been described as a spoofing issue.

Microsoft’s April 2026 Patch Tuesday: 165 Vulnerabilities and an Actively Exploited SharePoint Zero-Day

April 15th, 2026|

Microsoft's April 2026 Patch Tuesday addresses 165 vulnerabilities across the Windows ecosystem. The most pressing issue is an actively exploited SharePoint Server zero-day, tracked as CVE-2026-32201. A closer technical reading sheds light on the true exploitation risk and the most likely attack paths. SharePoint Zero-Day (CVE-2026-32201): What You Need to Know This vulnerability is a network-based spoofing flaw stemming from improper input validation in Microsoft Office SharePoint Server. Microsoft rated it "Important" with a CVSS score of 6.5, but active [...]

  • 108 malicious Chrome extensions operating as a coordinated campaign under a shared C2 infrastructure

108 malicious Chrome extensions: coordinated campaign targeting Google and Telegram users

April 14th, 2026|

Socket's Threat Research Team identified 108 malicious Chrome extensions operating as a coordinated campaign under a shared C2 infrastructure at cloudapi[.]stream. The extensions are published under five distinct publisher identities — Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt — and collectively account for approximately 20,000 Chrome Web Store installs.The extensions were still live at the time of writing; Socket has submitted takedown requests to both the Chrome Web Store security team and Google Safe Browsing. What each extension actually [...]

  • Anubis Ransomware Gang Claims Theft of 2TB of Patient Data

Anubis Ransomware Gang Claims Theft of 2TB of Patient Data from Massachusetts’ Signature Healthcare

April 14th, 2026|

The Anubis ransomware group claimed on Thursday, April 10, 2026, that it had stolen about 2 terabytes of highly sensitive patient data from Massachusetts-based Signature Healthcare. The attack was first detected on April 6 and affected multiple systems across the organization. Anubis publicly took responsibility on April 9 and stated that it did not encrypt critical systems—an unusual move compared to typical ransomware behavior, and likely an attempt to reduce backlash over potential risks to patient care. The group gave [...]

  • MITRE Launches Fight Fraud Framework to Bridge Cyber and Fraud Teams

MITRE Launches Fight Fraud Framework to Bridge Cyber and Fraud Teams

April 13th, 2026|

The MITRE Corporation has released a new framework designed to help organizations combat financial fraud, which cost Americans $16.6 billion in 2024 which is nearly four times the $4.2 billion lost in 2020. A core structural problem underlies those losses: fraud investigators and cybersecurity analysts have long operated in silos, using separate tools, different terminology, and incompatible mental models of how attacks unfold. The MITRE Fight Fraud Framework (F3) aims to close that gap. What F3 Is F3 is a [...]

  • Google fixed Chrome 14 vulnerabilities in 417 Release

Chrome 147 Release Delivers Patches for 60 Vulnerabilities

April 12th, 2026|

Google's disclosure around the stable release of Chrome 147 follows its usual rapid patching rhythm, but the nature and distribution of vulnerabilities in this release deserve more careful technical examination especially the two critical flaws identified within the WebML subsystem. Critical WebML Vulnerabilities Chrome 147 delivers patches for 60 vulnerabilities in total, two of which carry a critical classification: CVE-2026-5858 (heap buffer overflow) and CVE-2026-5859 (integer overflow), both residing in the WebML component. WebML forms part of Chrome's growing client-side [...]

  • GlassWorm malware IDE attack

GlassWorm’s Latest Evolution: Zig-Based Dropper Targeting All Installed IDEs

April 11th, 2026|

Security researchers at Aikido have identified a new advancement in the GlassWorm threat campaign, highlighting a clear escalation in both sophistication and execution strategy. This latest variant introduces a dropper written in Zig, a modern systems programming language, specifically designed to silently discover and compromise every compatible Integrated Development Environment (IDE) present on a developer’s system in a single, covert operation. This development represents another phase in a campaign that has been under observation for more than a year. GlassWorm [...]

  • Treat incoming files as a potential threat

“Payroll Pirates” Are Hijacking Canadian Workers’ Wages

April 10th, 2026|

A cybercriminal group with clear financial motives has been running a sophisticated operation against Canadian workers, quietly rerouting their paychecks into bank accounts the attackers control. The scheme was uncovered by researchers at Microsoft, who have been tracking the group's methods in detail. The Setup: Fake Ads, Poisoned Search Results, and a Very Convincing Login Page The attackers, whom Microsoft has labeled Storm-2755, don't bother targeting specific companies or industries. Instead, they cast a wide net geographically, going after Canadian [...]

Advanced Zero-Day Exploit Weaponizing Adobe Reader Through Malicious PDF Files

April 9th, 2026|

A sophisticated, previously unknown vulnerability in Adobe Reader has been discovered and is currently being exploited in the wild using specially crafted PDF documents. Uncovered by security researcher Haifei Li and the EXPMON platform, this attack represents a new breed of file-based threat that blends exploit execution with covert reconnaissance and selective payload delivery. Rather than relying on traditional malware distribution, this campaign focuses on data collection, environment profiling, and targeted follow-on attacks — making it considerably harder to detect [...]

Russian Military Hackers Hijack Internet Traffic Through Vulnerable Routers

April 8th, 2026|

The UK's National Cyber Security Centre (NCSC) has released an official advisory warning that the Russian state-backed group APT28 has been actively compromising consumer and small-business routers. The objective is to reroute internet traffic through attacker-controlled infrastructure, enabling large-scale credential theft and covert monitoring. Who is APT28? The NCSC states with high confidence that APT28, also known as Fancy Bear, Forest Blizzard, Sofacy, and Pawn Storm, is linked to Russia’s Main Intelligence Directorate (GRU), specifically Unit 26165 of its 85th [...]

  • AI assisted phishing attack

AI-Powered Device Code Phishing Campaign Exploits OAuth Flow for Account Takeover

April 7th, 2026|

A large-scale phishing operation that abuses the OAuth Device Code Authentication flow to seize control of organizational accounts has been discovered by MSFT Defender team . The campaign leverages automation and on-demand code generation to circumvent the standard fifteen-minute expiration window on these codes. AI-assisted tooling further amplifies the operation, enabling attackers to coordinate and scale their efforts at speed. Attack overview Device Code Authentication is a legitimate login mechanism designed for devices that lack the capability to render a [...]

  • Qilin and Warlock ransomware attacks

Ransomware Operators Weaponize Vulnerable Drivers to Blind Security Tools

April 6th, 2026|

Two active ransomware operations , Qilin and Warlock, have recently been caught using a technique known as "bring your own vulnerable driver" (BYOVD) to disable the security software protecting their target systems. Research published by Cisco Talos and Trend Micro reveals how both groups are deploying legitimate but exploitable kernel-level drivers to kill endpoint defenses before dropping their ransomware payloads.When Qilin operators gain access to a target environment, usually through stolen credentials, they drop a file called msimg32.dll into a [...]

  • Drift protocol heist Solana

North Korea Suspected Behind $285 Million Drift Protocol Heist

April 6th, 2026|

On April Fool's Day, there was nothing funny happening on the Solana blockchain. In a meticulously engineered attack weeks in the making, suspected North Korean state-sponsored hackers drained approximately $285 million from Drift Protocol, the largest decentralized perpetual futures exchange on Solana — and the largest DeFi exploit of 2026 so far. The attack did not rely on a software bug. It relied on patience, deception, and a fake token worth a few thousand dollars. What Is Drift Protocol? Drift, [...]

  • Claude source code leak

Threat Actors Use Leaked Claude Code as a Malware Trap

April 4th, 2026|

On March 31, 2026, Anthropic accidentally exposed the full source code of Claude Code, its terminal-based AI coding tool, through a 59.8 MB JavaScript source map file that was mistakenly included in a public npm package (@anthropic-ai/claude-code version 2.1.88). Source map files are meant for debugging and are not supposed to be shared publicly, as they reveal the original code behind an application. The issue was first noticed by security researcher Chaofan Shou, whose post quickly spread online. Anthropic confirmed [...]

  • WhatsApp VBS campaign flow

Microsoft Flags WhatsApp-Based Malware Campaign Deploying VBS Scripts and MSI Backdoors

April 1st, 2026|

Microsoft Defender Experts have documented an active threat campaign, first observed in late February 2026, in which malicious Visual Basic Script files are being distributed through WhatsApp messages to Windows users. Once a recipient executes the attachment, it triggers a carefully orchestrated, multi-stage infection chain designed to quietly establish persistence and open a durable remote access channel into the compromised system. The specific social engineering lures used to convince targets to run the scripts have not yet been publicly identified, [...]

  • EvilTokens phishing attacks on Microsoft 365 users

EvilTokens: The Surge of Device Code Phishing Targeting Microsoft 365

April 1st, 2026|

Security analysts at Sekoia have observed a marked escalation in device code phishing activity targeting Microsoft 365 environments. This increase is closely associated with the emergence of EvilTokens, a purpose-built phishing toolkit that is actively marketed as a service through Telegram channels. Understanding Device Code Phishing Device code phishing represents a manipulation of a legitimate authentication workflow in which attackers coerce users into completing a valid login sequence that ultimately grants adversaries control over access and refresh tokens. The Legitimate [...]

  • malware as an ecosystem

The Malware-as-a-Service Ecosystem: From Underground Craft to Industrialized Crime

April 1st, 2026|

The cybercriminal landscape has undergone a fundamental transformation. What was once dominated by isolated actors developing bespoke malware has evolved into a mature, service-oriented underground economy. By 2025, the Malware-as-a-Service (MaaS) ecosystem has reached a level of scale, professionalism, and operational efficiency that rivals legitimate software markets, dramatically lowering the barrier to cybercrime and intensifying global security risks. Driven by sustained demand and entrepreneurial criminal innovation, MaaS enables low-skilled actors to conduct highly sophisticated attacks by purchasing pre-built malware packages [...]

The Rise of Venom Stealer: A New Benchmark in Credential Theft Infrastructure

March 31st, 2026|

Cybercriminal operations have consistently demonstrated that the most effective method of compromising systems is not through perimeter defenses, but through credential compromise. As a result, credential harvesting has evolved into a foundational pillar of modern cybercrime. The tooling ecosystem supporting this activity has matured into a highly organized, commercially driven market. Venom Stealer exemplifies this evolution — an advanced infostealer framework that not only expands technical capabilities but also reflects a level of operational professionalism comparable to legitimate software products. [...]

  • Russian origin CTRL RAT toolkit

Russian-Origin CTRL Toolkit Delivered via LNK-Based Multi-Stage Intrusion Chain

March 30th, 2026|

Cybersecurity researchers at Censys have uncovered a sophisticated remote access toolkit linked to a Russian threat actor, which is being spread through malicious Windows shortcut (LNK) files disguised as folders containing private keys. The distribution method exploits user trust by making the harmful file appear to be a harmless folder, increasing the chances that a victim will open it. The toolkit — named CTRL by researchers at Censys — is built on the .NET framework and comprises a modular set [...]

  • TeamPCP distributed malware that designed for cross-platform execution across Windows, Linux, and macOS environments, with platform-specific behavior.

Supply Chain Threat Actor TeamPCP Expands Campaign to Telnyx Python Package

March 29th, 2026|

A threat actor tracked as TeamPCP, previously associated with supply chain compromises involving Trivy, KICS, and litellm, has broadened its activity by embedding malicious code into the telnyx Python package. Two altered versions were published to PyPI on March 27, 2026, and were subsequently quarantined. The Malicious Versions and Initial Discovery Versions 4.87.1 and 4.87.2 of the telnyx package were identified as containing credential-harvesting logic concealed within a .WAV audio file — a steganographic delivery method previously observed in this [...]

  • China-nexus BPF core

Telecom Networks Under Long-Term Infiltration by China-Nexus Threat Actor

March 28th, 2026|

A sophisticated and sustained intrusion campaign has been identified operating within telecommunications infrastructure across the Middle East and Asia, with activity dating back to at least 2021. Security researchers at Rapid7 have attributed the operation to a threat cluster known under multiple tracking designations — Red Menshen, Earth Bluecrow, DecisiveArchitect, and Red Dev 18 — a China-nexus actor with a documented history of targeting regional telecom providers. Rapid7 characterized the implants discovered within these networks as among the most covert [...]

  • LiteLLM supply chain attack

LiteLLM Package Poisoning Traced Back to Earlier Trivy Breach

March 28th, 2026|

Two tampered versions of LiteLLM, a widely adopted Python library, were uploaded to the official Python Package Index (PyPI) by a malicious actor. Before being taken down, the corrupted packages were downloaded roughly 47,000 times in under an hour. LiteLLM serves as a unified interface layer allowing developers to connect with multiple AI providers through a single API — making its broad user base a high-value target. How It Was Found Security researcher Callum McMahon stumbled upon the issue after [...]

  • WebRTC-Based Payment Skimmer

New WebRTC-Based Payment Skimmer Exploits Magento Vulnerability

March 27th, 2026|

Cybersecurity analysts at Sansec have identified an advanced payment skimmer that utilizes WebRTC data channels for both payload delivery and data exfiltration. This approach enables the malware to evade traditional security monitoring mechanisms. In contrast to conventional skimmers that depend on HTTP requests or image beacons to communicate with attacker infrastructure, this variant leverages WebRTC’s peer-to-peer framework, as outlined in a recent report by a European security research firm. Skimmer Campaign The campaign has been observed targeting an automotive manufacturer’s [...]

  • SmartApeSG Campaign Delivers Multi-Stage RAT Deployment

SmartApeSG Campaign: Multi-Stage Malware Delivery Through Fake CAPTCHA Pages

March 26th, 2026|

Brad Duncan at Exchange tracks a threat campaign called SmartApeSG and has documented an attack sequence that tricks users into infecting their own machines, then quietly installs several malicious tools over the following hours. The operation stands out because of how methodical it is — rather than dropping everything at once, the attackers introduce each new tool at a specific moment, suggesting someone is actively managing the intrusion from the other side. Over the course of a single observed session, [...]

  • Tax season phishing

Tax Season Phishing Surge: Credential Theft and RMM-Based Intrusions Target U.S. Organizations

March 24th, 2026|

Microsoft's threat intelligence division has uncovered a wave of coordinated attacks timed to coincide with U.S. tax season. Threat actors are capitalizing on the stress and urgency that surrounds tax filing to trick individuals and organizations into handing over credentials, installing malware, or granting remote access to their systems — all through communications designed to look indistinguishable from legitimate tax correspondence. How the Attacks Are Structured The foundation of these campaigns is simple but effective: flood inboxes during a period [...]

  • Files vs Logs for FileDNA

Gap in Modern Security: Why Files Matter More Than Logs

March 22nd, 2026|

Security teams have spent years refining detection capabilities — deploying more advanced EDR platforms, building increasingly complex SIEM rules, integrating richer threat intelligence, and relying on skilled analysts to interpret results. All of this effort is built on a shared assumption: when malicious activity occurs, tools will detect it, alerts will trigger, and an investigation will follow. That assumption contains a structural weakness. Detection depends on data, and the data most organizations retain is often not the data required for [...]

  • EDR killer threat kill chain

BYOVD-Powered EDR Killers and Their Role in Modern Ransomware Operations

March 21st, 2026|

A recent ESET investigation into tools designed to disable endpoint detection and response (EDR) software found that a large number of them use a technique called "bring your own vulnerable driver" (BYOVD). In total, 54 different tools were found using this method, taking advantage of 35 known weak drivers. These tools have become a key part of how ransomware attacks work — attackers use them to knock out security software before unleashing their file-encrypting malware. Why EDR Killers Exist Ransomware [...]

  • DarkSword IOS malware like Coruna

DarkSword: Researchers Uncover a New iOS Exploit Kit

March 19th, 2026|

Researchers at Google have identified a sophisticated iPhone exploit framework called DarkSword, active since November 2025, that chains together multiple zero-day vulnerabilities to compromise iOS devices. The discovery follows recent reporting on a comparable toolkit, Coruna, leveraged by both state-affiliated threat actors and cybercriminals. Where Coruna relied on a broader variety of infection vectors, DarkSword is distinguished by its sequential chaining of six discrete vulnerabilities to achieve remote code execution and malware deployment. The vulnerability chain targets critical subsystems within [...]

  • LeakNet attack flow

LeakNet Adopts ClickFix and Deno-Based Payloads for Rapid Expansion

March 18th, 2026|

The ransomware group known as LeakNet has notably evolved its network intrusion strategy by incorporating the ClickFix social engineering technique. Unlike its previous dependence on acquiring stolen credentials from initial access brokers (IABs), this approach is primarily distributed through compromised but otherwise legitimate websites injected with malicious scripts. A technical analysis by ReliaQuest highlights this as a significant operational pivot. By eliminating reliance on IABs, LeakNet removes a key external dependency that previously constrained both the scale and tempo of [...]

  • GlassWorm Attack Chain and GitHub Supply Chain Compromise

GlassWorm Campaign Expands to GitHub Supply Chain Attacks

March 17th, 2026|

According to research by StepSecurity the threat actors, who obtained developer credentials during the VS Code GlassWorm campaign, are now using stolen tokens to infiltrate GitHub accounts and inject malicious code into Python repositories.The attacks, active since March 8, have zeroed in on Python ecosystems by spanning Django applications, machine learning projects, PyPI packages, and Streamlit dashboards with the apparent goal of siphoning cryptocurrency and other sensitive information. Operating through hijacked developer accounts, the attackers alter legitimate repositories by rebasing [...]

  • How criminal infrastructure worked

Operation Synergia III: Global Cybercrime Crackdown

March 16th, 2026|

A seven-month, 72-country operation dismantled tens of thousands of malicious servers and made 94 arrests. The confirmed results are a useful snapshot of the global cybercrime economy. They also leave the technical mechanics largely undescribed, which is worth being honest about before drawing conclusions. On 13 March 2026, INTERPOL announced the results of Operation Synergia III, an international law enforcement effort that ran from 18 July 2025 to 31 January 2026. According to INTERPOL, law enforcement from 72 countries and [...]

  • A government-aligned threat cluster has been conducting cyber espionage operations against military organizations across Southeast Asia

State-Sponsored Cyber Espionage Campaign Targeting Military Organizations

March 15th, 2026|

A government-aligned threat cluster has been conducting cyber espionage operations against military organizations across Southeast Asia since at least September 2020. Palo Alto Networks Unit42 is traking the malware activity under a CL-STA-1087 name as formal threat designation used to categorize state-motivated cyber operations.The campaign demonstrates hallmarks of long-term intelligence collection rather than opportunistic intrusion or financially motivated cybercrime. Its operational design suggests careful planning and sustained access to sensitive networks. Strategic Intent What distinguishes this activity from typical cyber [...]

  • ShinyHunters Exploits Misconfigured Salesforce Experience Cloud Sites

ShinyHunters Exploits Misconfigured Salesforce Experience Cloud Sites in Large-Scale Data Theft Operation

March 14th, 2026|

The cybercrime group ShinyHunters has claimed responsibility for an extensive data theft campaign targeting organizations that rely on Salesforce. Unlike many breaches involving software flaws, the entry point in this case stems from configuration mistakes within Salesforce deployments rather than a vulnerability in the platform itself. What Happened On March 10, 2026, Salesforce confirmed that attackers were exploiting publicly accessible or improperly configured Salesforce Experience Cloud portals. The activity has been attributed to the ShinyHunters threat group. Salesforce clarified that [...]

  • Hive0163 AI-assisted malware

Hive0163 Deploys AI-Assisted “Slopoly” Malware to Maintain Persistent Access in Ransomware Campaigns

March 13th, 2026|

Cybersecurity researchers at IBM X-Force have identified a suspected AI-assisted malware component known as Slopoly, attributed to a financially motivated threat group tracked as Hive0163. The malware serves a targeted role within multi-stage ransomware intrusion chains — specifically, maintaining long-term, covert access to compromised environments after the initial breach has already been established. AI-Assisted Malware Development Code analysis of the Slopoly malware reveals several structural characteristics commonly associated with AI-assisted development. Researchers noted the presence of highly structured inline comments [...]

  • Malicious Rust packages

Malicious Rust Packages and AI-Assisted CI/CD Attacks Expose New Supply Chain Risks

March 12th, 2026|

Researchers at Socket uncovered a set of malicious Rust crates disguised as time-related utilities, built to harvest sensitive data from developer environments. The packages were engineered to locate and exfiltrate .env files — which routinely store API keys, authentication tokens, and other credentials — transmitting their contents to infrastructure controlled by the attacker. Rust Crates The following crates were briefly listed on the crates.io registry: chrono_anchor dnp3times time_calibrator time_calibrators time-sync The packages were crafted to impersonate legitimate tooling associated with [...]

  • Microsoft patch Tuesday, March 26

Microsoft March 2026 Patch Tuesday: Vulnerability Analysis

March 11th, 2026|

Microsoft's March 2026 Patch Tuesday addresses 83 proprietary CVEs and 10 republished third-party vulnerabilities. Eight are rated Critical; 75 are rated Important. None have been detected as actively exploited at time of release, though two were publicly disclosed prior to patching, qualifying them as zero-days under common industry definitions. Elevation of privilege (EoP) vulnerabilities dominate this release, comprising approximately 55% of all CVEs patched. Remote code execution (RCE) flaws account for roughly 20%. While the release is considered relatively quiet [...]

  • BoryptGrab malware campaign on GitHub

BoryptGrab: Distributed Through Fake SEO-Optimized GitHub Repositories

March 10th, 2026|

The BoryptGrab campaign, reported by Trend Micro, relies on fraudulent GitHub repositories optimized for search engines and deceptive download pages to distribute a data-stealing malware family targeting Windows users. The malware deployment chain ultimately delivers multiple payloads, including a reverse SSH backdoor. Evidence from repository commit histories suggests the activity dates back to at least April 2025, while malicious ZIP samples began appearing toward the end of 2025. This timeline indicates a sustained and evolving operation rather than a short-lived [...]

  • ClickFix InstallFix malware

Fake Claude Code Install Pages Are Spreading “InstallFix” Malware

March 9th, 2026|

Researchers at Push Security have uncovered a new malware distribution campaign targeting developers who search for how to install Claude Code, Anthropic's command-line AI coding assistant. Attackers are using Google Search ads to push cloned installation pages that look nearly identical to the real thing, but secretly serve malicious terminal commands. Clone Sites Built to Fool Developers The attackers built pixel-perfect copies of Anthropic's official Claude Code installation page and hosted them on lookalike domains (e.g., domains that swap characters [...]

  • BadPaw and MeowMeow malware

BadPaw and MeowMeow: A Multi-Stage Malware Campaign Targeting Ukrainian Organizations

March 9th, 2026|

Security researchers at ClearSky have found a spy-focused hacking campaign going after Ukrainian organizations, using two newly discovered malware programs called BadPaw and MeowMeow. The attack is built around a step-by-step infection process meant to quietly dig in for the long term while staying as hard to detect and analyze as possible.The campaign pulls together several moving parts: phishing emails to get a foot in the door, a .NET-based loader, gradual payload delivery, and a backdoor that sticks around. It [...]

  • Operation toolset - Havoc Demon

From QuickAssist to Demon: Fake IT Support Campaign Distributes Customized Havoc C2 Framework

March 7th, 2026|

In February 2026, Huntress identified a cluster of intrusions across five partner organizations sharing a common attack pattern: email spam bombardment as initial bait, followed by a vishing call from an actor posing as IT support, culminating in the deployment of a heavily modified Havoc C2 Demon agent. In one organization, the adversary moved from initial access to nine additional endpoints over eleven hours, deploying a mix of custom Havoc Demon payloads and legitimate RMM tools for persistence.The campaign's tactics, [...]

  • Coruna exploit at GitHub

A Sophisticated iOS Exploit Kit Traced from Russian Espionage to Criminal Cybercrime

March 6th, 2026|

Two independent cybersecurity organizations — Google Threat Intelligence Group and iVerify — released reports on the same day describing a powerful iOS exploit kit known internally as Coruna.GTIG first discovered the threat in February 2025 and later uncovered its full scope after obtaining a developer debug build that revealed the internal names of its components. Around the same time, iVerify independently identified the same exploit kit and carried out its own detailed investigation over several weeks. Both teams reached similar [...]

  • Hacktivists coalitions during war in Iran

Hacktivists Ramp Up Cyberattacks After Middle East Military Strikes

March 5th, 2026|

After the U.S. and Israel launched coordinated military operations against Iran (called Epic Fury and Roaring Lion), cybersecurity experts have seen a big jump in retaliatory cyberattacks. Hacking groups have been hitting government agencies, infrastructure, and businesses across the region. According to Radware, between February 28 and March 2, two groups — Keymous+ and DieNet — were behind nearly 70% of all attacks. The first attack in this wave was a denial-of-service (DDoS) attack launched on February 28, 2026, by [...]

Silver Dragon Attacks Governments in Europe and Southeast Asia

March 4th, 2026|

Silver Dragon is a Chinese state-sponsored Advanced Persistent Threat (APT) group assessed to be operating as a subgroup within the broader APT41 umbrella and also tracked as Winnti and Barium. APT41 is one of the most prolific Chinese hacking collectives on record, with documented cyber espionage activity dating back to 2012 spanning healthcare, telecommunications, high-tech manufacturing, education, travel services, and media. The group is further believed to engage in financially motivated operations that may operate partially outside direct state control. [...]

  • Adversary-in-the-middle attack

A Technical Deep-Dive into the Starkiller Phishing Platform

March 3rd, 2026|

Starkiller is an advanced phishing-as-a-service (PhaaS) platform developed and distributed by a threat group calling itself Jinkusu. Unlike conventional phishing toolkits that rely on static copies of legitimate websites, Starkiller operates as a live reverse proxy, mirroring real brand login pages in real time and routing victim interactions through attacker-controlled infrastructure.This approach eliminates many of the traditional weaknesses that security tools rely on to detect phishing pages, while simultaneously lowering the technical barrier for attackers. The result is a tool [...]

  • Staelite RAT

All-in-One Malware Platforms Are Merging Data Exfiltration and Ransomware Operations

March 1st, 2026|

A newly advertised remote access trojan (RAT) called Steaelite has emerged on underground marketplaces, presenting operators with a web-based console for comprehensive control over compromised Windows systems. Rather than relying on separate utilities for different phases of intrusion, the platform aggregates remote execution, credential harvesting, real-time surveillance, data theft, and ransomware deployment into a single management interface. What Differentiates This Tool According to the BlackFog the defining characteristic of the tool is not a novel capability, but the consolidation of [...]

  • dohdoor malware

UAT-10027 and the “Dohdoor” Backdoor Campaign

March 1st, 2026|

A newly identified threat cluster, labeled UAT-10027 by Cisco Talos, has been actively targeting U.S. healthcare providers and educational institutions since December 2025. What makes this campaign stand out is its strong operational security — specifically, its use of DNS-over-HTTPS (DoH) to hide command-and-control (C2) communications, and its focus on running malicious code entirely in memory to leave fewer traces and get around standard endpoint defenses. 1. How the Attack Gets In and Runs The exact entry point is still [...]

  • UNC-2814 espionage group

Google Disrupts Cloud-Abusing Espionage Infrastructure Linked to UNC2814

February 27th, 2026|

Google Threat Intelligence Group (GTIG) and Mandiant, operating with international partners, last week concluded a coordinated takedown of a persistent cyber-espionage campaign targeting government and telecommunications infrastructure across four continents. Attribution points to UNC2814, a suspected People's Republic of China-nexus threat actor operational since at least 2017, with 53 confirmed victims across 42 nations and suspected compromise indicators across an additional 20 countries. Abuse of Legitimate Cloud Infrastructure for C2 Rather than exploiting software vulnerabilities, UNC2814's defining technical approach was [...]

  • Fake Next.js repository

Developer-Targeted Attack Campaign Uses Fake Next.js Projects to Hijack Systems

February 26th, 2026|

A large-scale attack campaign is targeting software developers by disguising malicious code inside fake Next.js repositories and phony technical interview assignments. The goal is to get developers to unknowingly run attacker-controlled code that gives hackers persistent, remote access to their machines.Microsoft's security research team published an analysis this week linking the activity to a broader set of operations that use job-themed bait. Because the malicious code is hidden inside normal development tasks, victims are far less likely to notice anything [...]

  • UAC-0050 Russian hakers group

UAC-0050 (Mercenary Akula) Expands Operations to Financial Institutions

February 25th, 2026|

The Russia-aligned threat group UAC-0050 — also known as the DaVinci Group and identified by BlueVoyant as “Mercenary Akula” — has executed a spear-phishing campaign targeting a Western European financial institution engaged in regional development and reconstruction initiatives. This activity suggests a geographic expansion beyond the actor’s historically Ukraine-focused operations. The targeted individual was a senior legal and policy advisor responsible for procurement processes, a role that provides elevated visibility into institutional financial workflows and operational decision-making. Attack Chain The [...]

  • Lazarus group attecks healthcare industry

North Korea’s Lazarus Group Now Using Medusa Ransomware

February 25th, 2026|

Researchers at Symantec and Carbon Black (both under Broadcom) have linked the North Korean hacking group Lazarus — also known as Diamond Sleet or Pompilus — to attacks using Medusa ransomware. One confirmed attack hit an organization in the Middle East, and a second attempted attack on a U.S. healthcare organization was caught before it succeeded. What is Medusa? Medusa is a "ransomware-as-a-service" (RaaS) operation, meaning it's a criminal platform that rents out ransomware tools to paying members. It launched [...]

MuddyWater Launches “Operation Olalampo”

February 23rd, 2026|

The Iranian state-aligned threat actor MuddyWater — also tracked under the aliases Earth Vetala, Mango Sandstorm, and MUDDYCOAST — has launched a new campaign, internally designated Operation Olalampo, directed at organizations and individuals across the Middle East and North Africa. Group-IB researchers first detected the activity on January 26, 2026. Infection Chain The operational methodology follows established MuddyWater tradecraft patterns. The intrusion sequence begins with spear-phishing emails containing malicious Microsoft Office documents. These attachments embed macro code designed to decode [...]

  • cve-2026-26119

CVE-2026-26119: Critical Privilege Escalation Flaw in Windows Admin Center

February 22nd, 2026|

Microsoft has disclosed a critical vulnerability in Windows Admin Center (WAC), a browser-based management platform widely used by enterprise IT teams to administer Windows clients and servers, clusters, Hyper-V hosts, virtual machines, and Active Directory-joined systems. The flaw, tracked as CVE-2026-26119, allows privilege escalation and carries serious implications for organizations relying on WAC as a centralized infrastructure management interface. Discovery and Disclosure The vulnerability was discovered in July 2025 by Andrea Pierini, a security consultant at Semperis, and stems from [...]

  • Promptware

Promptware: Reclassifying AI Prompt Injection as a Distinct Threat Class

February 21st, 2026|

Security researchers from Tel Aviv University, Ben-Gurion University of the Negev, and Harvard — including well-known cryptographer Bruce Schneier — argue that the AI industry has been fundamentally misreading prompt injection attacks by comparing them to an older, simpler type of attack. Their paper introduces a new category called promptware: malicious instructions that use an AI language model itself as the engine to carry out an attack. The Problem With the SQL Injection Comparison The industry has long treated prompt [...]

  • PromptSpy Android malware

PromptSpy: Android Malware That Uses AI to Stay on Your Device

February 20th, 2026|

Security researchers at ESET have discovered PromptSpy, the first Android malware known to use a generative AI model as part of how it actually operates. This is a landmark finding because it's the first time a large language model (LLM) has been built into malware to help it run malicious tasks on a device.The name "PromptSpy" comes from how it works: it sends prompts to Google's Gemini AI to get step-by-step instructions for controlling the Android interface. With those instructions, [...]

  • Massiv is a full remote access trojan

Fake IPTV Apps Are Spreading a New Android Banking Trojan

February 19th, 2026|

Cybersecurity researchers at Dutch mobile security firm ThreatFabric have discovered a new Android banking trojan called Massiv that gives attackers full remote control over infected devices. The malware spreads through fake IPTV streaming apps and is designed to steal banking credentials and carry out fraudulent transactions directly from victims' accounts. Who Is Being Targeted? The first major campaign was spotted earlier this year and focused on users in Portugal and Greece, though malware samples suggest the attackers were quietly testing [...]

  • Net Monitor for Employees to manipulate system accounts

RMM Tool Abused in Ransomware Attacks

February 17th, 2026|

Net Monitor for Employees: system accounts manipulations The Two Incidents: What Happened Case 1 — Late January 2026 (Unknown Initial Access) In late January 2026, cybersecurity firm Huntress identified suspicious account manipulation activity on a compromised host, triggering an investigation into a broader intrusion. Attackers leveraged the legitimate employee monitoring software Net Monitor for Employees to manipulate system accounts, disable the Guest account, enable the built-in Administrator account, and execute multiple net commands to enumerate users, reset credentials, and create [...]

The Fake Meeting Trap: Video Conference Invites to Install Remote Access Tools

February 16th, 2026|

A large phishing campaign is targeting companies worldwide by abusing the trust people place in video conferencing platforms. Researchers at Netskope Threat Labs have observed attackers sending fake meeting invitations for Zoom, Microsoft Teams, and Google Meet to trick employees into installing legitimate remote monitoring and management (RMM) software.Unlike traditional phishing that mainly steals passwords, this campaign aims to gain full administrative control of employee computers. More than 900 organizations have already been affected, especially in education, healthcare, and financial [...]

  • GTI Group discovered CANFAIL malware

CANFAIL Malware Campaign Targets Ukrainian Organizations

February 14th, 2026|

Google Threat Intelligence Group has identified a previously undocumented threat actor suspected to be linked to Russian intelligence services that is conducting phishing operations to deliver CANFAIL malware primarily against Ukrainian organizations. This cyber espionage group has demonstrated evolving capabilities, particularly in leveraging artificial intelligence technologies to enhance operational effectiveness. Target Profile and Scope The threat actor has focused its operations on a diverse range of Ukrainian entities. Primary targets include defense, military, government, and energy organizations within the Ukrainian [...]

  • Microsoft Outlook malicious plugin

Compromised Outlook Extension Used to Harvest 4,000+ Microsoft Account Credentials

February 13th, 2026|

Cybersecurity analysts have identified a supply chain attack targeting a dormant but previously authentic Microsoft Outlook extension, which was weaponized to deploy a credential-stealing phishing interface. The campaign, tracked by Koi Security under the name "AgreeToSteal," led to the compromise of over 4,000 Microsoft user credentials. Attack Methodology: Exploiting Dormant Infrastructure Through Dynamic Content Loading The targeted extension, called AgreeTo, was initially created to facilitate calendar synchronization and availability sharing through email communications. Active development concluded following its final release [...]

Insomnia Data Leak Operation Emerges as New Threat to U.S. Healthcare Organizations

February 12th, 2026|

A recently discovered cybercriminal group called Insomnia has become an escalating threat to the healthcare sector, an industry long recognized as particularly vulnerable to cyber extortion given the operational dangers posed by service interruptions and potential impacts on patient welfare. Following its appearance on underground leak websites in the past several weeks, Insomnia has posted 18 purported victims to its data leak platform, with over half being healthcare service providers or organizations connected to the healthcare field. The listed organizations [...]

  • Raynolds BYOVD ransomware

Reynolds Ransomware Integrates BYOVD Driver to Disable Security Tools and Accelerate Attacks

February 11th, 2026|

Carbon Black Threat Hunter Team cybersecurity researchers have identified an emerging ransomware family designated Reynolds, which embeds a Bring Your Own Vulnerable Driver (BYOVD) capability directly within its ransomware executable. This architectural approach enables the malware to neutralize security protections and circumvent detection systems as an integrated component of the encryption phase. BYOVD represents a widely adopted adversarial technique that exploits legitimate but flawed signed drivers to obtain elevated system privileges and terminate or disable Endpoint Detection and Response (EDR) [...]

Microsoft Feb 2026 Patch: Six Actively Exploited Zero-Days Addressed

February 11th, 2026|

Microsoft’s February 2026 Patch Tuesday release resolves 59 security vulnerabilities, including six zero-day issues confirmed to be actively exploited in real-world attacks. The exploited flaws affect key Windows components such as Windows Shell, the MSHTML Framework, Microsoft Office Word, Desktop Window Manager, Remote Desktop Services, and the Remote Access Connection Manager. Three of the zero-days allow attackers to bypass security protections, including Windows SmartScreen, enabling execution of malicious files without triggering standard user warnings. The remaining vulnerabilities enable privilege escalation or [...]

  • Ivanti EPMM breach

Zero-Day Campaign Targets European Government Mobile Device Management Infrastructure

February 11th, 2026|

A coordinated cyberattack campaign exploiting critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile has successfully compromised multiple European government agencies, exposing sensitive employee data and raising serious concerns about the security of enterprise mobile device management platforms across the public sector. Dutch Government Institutions Compromised The Dutch Data Protection Authority and the Council for the Judiciary both fell victim to this exploitation campaign, with their compromise confirmed in correspondence delivered to the Dutch parliament on Friday by Justice Secretary Arno [...]

  • bloody wolf malware

Bloody Wolf’s NetSupport RAT Campaign

February 9th, 2026|

The threat actor tracked as Bloody Wolf has conducted a large-scale malware distribution operation impacting organizations in Uzbekistan and Russia. Kaspersky Labs monitors this activity under the designation Stan Ghouls and has recorded operations dating back to at least 2023. The adversary has consistently targeted organizations in the manufacturing, financial, and IT sectors across Russia, Kyrgyzstan, Kazakhstan, and Uzbekistan. The current wave of activity has resulted in the compromise of approximately 50 systems in Uzbekistan and a further 10 systems [...]

  • phishing attack through Signal messenger app

German Authorities Warn of State-Backed Campaign Hijacking Signal Messenger Accounts

February 8th, 2026|

Germany's Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) have issued a joint cybersecurity warning about an active cyber campaign likely conducted by a state-sponsored threat actor. The operation focuses on phishing attacks carried out through the Signal messaging platform. The campaign targets high-level individuals in political, military, and diplomatic positions, as well as investigative journalists throughout Germany and Europe. Officials warn that compromised messaging accounts can reveal sensitive private communications [...]

  • TGA-STA-30 group

TGR-STA-1030 Cyberespionage Campaign: Technical Analysis

February 7th, 2026|

Security researchers at Palo Alto Networks Unit 42 identified activity tracked as TGR-STA-1030, also known as UNC6619, while investigating targeted phishing operations aimed at European government entities in early 2025. The designation TGR-STA is used as an interim label for suspected state-aligned activity until attribution assessments are refined. Infrastructure analysis indicates that components associated with this actor have been active since at least January 2024, suggesting sustained operations extending across roughly two years. Campaigns attributed to this group have resulted [...]

  • Kimwolf botnet attack

AISURU/Kimwolf Botnet: Record-Breaking DDoS Attack

February 7th, 2026|

The AISURU botnet, also called Kimwolf, carried out a record-breaking distributed denial-of-service attack that peaked at 31.4 terabits per second. The attack lasted about 35 seconds and occurred in November 2025.Cloudflare's automated systems detected and stopped the attack. The company reported this event as part of a larger pattern of extremely high-volume HTTP DDoS attacks during the final three months of 2025. These attacks represent a growing trend where threat actors launch very short but exceptionally powerful bursts of malicious [...]

  • DEAD#VAX attack chain

DEAD#VAX Campaign Leverages IPFS-Based VHD Files to Distribute AsyncRAT

February 6th, 2026|

Security researchers have identified a sophisticated malware distribution operation designated DEAD#VAX that exploits native Windows functionality alongside carefully orchestrated evasion tactics to deliver the AsyncRAT remote administration tool while avoiding traditional security controls. The campaign's architecture centers on Virtual Hard Disk files distributed through the InterPlanetary File System, combined with heavily obfuscated scripting layers, dynamic payload decryption during execution, and direct shellcode injection into legitimate system processes. The technical approach ensures that executable malware components never materialize on the filesystem [...]

  • Stealthy Supply-Chain Attack Targeting Developers

The MaliciousCorgi: A Stealthy Supply-Chain Attack Targeting Developers

February 5th, 2026|

In early 2026, cybersecurity researchers uncovered a large-scale spyware campaign targeting software developers through malicious extensions published on the official Microsoft Visual Studio Code (VS Code) Marketplace. The operation, named the MaliciousCorgi Campaign, exploited the popularity of AI coding assistants to covertly exfiltrate source code, credentials, and user activity data from developer environments worldwide. The campaign achieved significant impact by embedding spyware within fully functional developer tools, resulting in more than 1.5 million installations and establishing itself as one of [...]

  • macOS python based infostealer

Python-Based Infostealers Expand to macOS Through Malvertising and Social Engineering

February 4th, 2026|

Microsoft has issued a warning regarding the rapid expansion of information-stealing malware operations beyond their traditional Windows targets, with attackers now increasingly focusing on Apple macOS systems. Threat actors are leveraging cross-platform programming languages such as Python while abusing widely trusted distribution channels to deploy malware at scale across heterogeneous environments. Campaign Tactics and Malware Families Analysis from Microsoft's Defender security researchers indicates that multiple campaigns observed since late 2025 have specifically targeted macOS users through social engineering techniques, including [...]

Metro4Shell Exploitation: Critical React Native CLI Vulnerability

February 4th, 2026|

Security researchers at VulnCheck have warned that attackers are actively exploiting a critical vulnerability impacting React Native, with malicious activity observed since late December 2024. The flaw, tracked as CVE-2025-11953 and rated 9.8 on the CVSS severity scale, was publicly disclosed in early November. It impacts the React Native Community CLI NPM package (@react-native-community/cli), a widely used component downloaded roughly two million times per week. The package belongs to the React Native Community CLI project, which was split from the core [...]

  • ClawHavoc: 341 malicious packages linked to multiple coordinated campaigns

OpenClaw Users at Risk: Malicious Skills Found Across Multiple Campaigns

February 3rd, 2026|

A recent security review of 2,857 skills on the ClawHub marketplace found that 341 of them were malicious packages, tied to several coordinated attack campaigns. The research was carried out by Koi Security and sheds light on a growing threat known as a software supply chain attack — where bad actors sneak harmful code into tools that people trust and install voluntarily. ClawHub is a community marketplace where users can find and install third-party skills for OpenClaw, a self-hosted AI [...]

  • BravoX is a recently emerged Ransomware-as-a-Service (RaaS)

Dark Web Profile: BravoX Ransomware

February 3rd, 2026|

BravoX is a recently emerged Ransomware-as-a-Service (RaaS) operation that appeared in early 2026 after announcing itself on the RAMP underground forum. First seen in January 2026, the group currently shows low activity levels and only a few listed victims, while actively seeking affiliates to grow its operations. Background and Emergence BravoX became publicly known on January 23, 2026, when it posted a Tor address on the RAMP forum. Soon after, researchers discovered a dedicated data leak site linked to BravoX, [...]

  • Notepad++ server compromised attack

Notepad++ Updates Targeted Through Hosting Provider Attack

February 2nd, 2026|

After the security issue was announced with Notepad++ version 8.8.9, investigators have been working with cybersecurity experts and the hosting company to understand what happened. The investigation shows that attackers broke into the hosting provider's systems rather than exploiting any weakness in Notepad++ itself. What Happened Security researchers found that attackers gained unauthorized access to the shared hosting infrastructure that ran notepad-plus-plus.org. This allowed them to intercept and redirect some update requests. Rather than changing Notepad++ code or its update [...]

  • NetSupport RAT tactics and techniquest

NetSupport RAT: A Technical Overview of Weaponized Remote Access Software

February 1st, 2026|

NetSupport RAT is a malicious version of NetSupport Manager, a legitimate remote administration tool that has been used for technical support and IT management for a long time. Cybercriminals exploit this software's remote control features to spy on victims and keep unauthorized access to infected computers.The malware spreads through targeted social engineering attacks. Criminals use hacked websites to push automatic downloads, send fake messages that look like browser update notifications from Google Chrome, and distribute files disguised as popular game [...]

  • Browser extensions hijacking

Malicious Browser Extensions: Three Major Threat Campaigns Identified

February 1st, 2026|

Recently security teams have discovered several coordinated attacks using browser extensions distributed through official extension marketplaces. These campaigns use extensions to commit affiliate fraud, steal data, and harvest user credentials while appearing completely legitimate to users. Campaign 1: Affiliate Link Hijacking via E-Commerce Extensions Discovery and Scope Socket security researcher Kush Pandya discovered a network of 29 malicious Chrome extensions targeting popular e-commerce platforms, including Amazon, AliExpress, Best Buy, Shein, Shopify, and Walmart. One of the main extensions, called "Amazon [...]

  • Security flow in Telnet servers

Critical Security Flaw in Telnet Servers

January 31st, 2026|

In January 2026 have been discovered a severe vulnerability in a widely used version of the Telnet server software. Attackers are already actively searching the internet for vulnerable systems. Approximately 800,000 Telnet services remain exposed online, creating significant risk for potential attacks.The problem is especially serious for industrial control systems and operational technology environments. These include factory equipment, industrial controllers, and embedded Linux systems that often run for years without security updates. Many internet-connected devices and legacy IoT equipment also [...]

  • The ShinyHunters extortion gang has claimed responsibility for an ongoing series of voice phishing attacks

ShinyHunters Gang Launches Voice Phishing Campaign Against Corporate SSO

January 30th, 2026|

The ShinyHunters extortion group has taken credit for an active wave of voice phishing (vishing) attacks aimed at single sign-on (SSO) accounts tied to major platforms such as Okta, Microsoft, and Google. Through these attacks, threat actors are able to break into corporate software-as-a-service (SaaS) environments and exfiltrate company data, which is then leveraged for extortion. Attack Methodology The campaign follows a deliberate and repeatable playbook that combines social engineering with abuse of authentication workflows. Attackers pose as IT support [...]

  • fake jobs interviews

How Early-Season Hiring Scams Target Job Seekers

January 30th, 2026|

The beginning of the year often represents a fresh start. Companies open their hiring budgets, seasonal positions become available, and people searching for work to be whether unemployed, changing careers, or seeking better opportunities, so they begin submitting applications. Scammers have learned to exploit this predictable pattern. Recent research reveals a significant increase in fraudulent recruitment emails strategically timed to take advantage of the early-year hiring surge. These messages impersonate well-known employers and staffing agencies, advertising easy jobs, quick interviews, [...]

  • stanley chrome extension

Stanley Malware Toolkit: Russian-Made Chrome Extension Phishing Service

January 30th, 2026|

A newly identified malware-as-a-service toolkit known as Stanley is emerging as a serious threat to browser security. Sold on underground cybercrime forums, the toolkit enables criminals to steal credentials and personal data using malicious Google Chrome extensions. According to Varonis, its most alarming feature is a claimed ability to bypass Chrome Web Store security reviews, guaranteeing publication of malicious extensions. Stanley was first observed on January 12, 2026, in promotional posts on Russian-language cybercrime forums. Pricing ranges from $2,000 to [...]

Multiple Threat Groups Actively Exploiting WinRAR Security Flaw

January 29th, 2026|

Security researchers have identified widespread exploitation of a critical security vulnerability in the popular WinRAR file compression software. The flaw is being used by various threat groups, including government-sponsored hackers and cybercriminals, to break into computer systems and install malicious software. The Vulnerability The security flaw, designated CVE-2025-8088, received a severity rating of 8.8 out of 10. It was fixed in WinRAR version 7.13, which was released on July 30, 2025. However, the vulnerability was first discovered and exploited by [...]

  • Moltbot AI platform vulnerability

AI Agent Platform Moltbot Exposes Serious Security Flaw

January 28th, 2026|

Moltbot: Public Control Panels Enable Account Theft and System Takeover A security investigation has uncovered a critical weakness affecting hundreds of publicly exposed administrative control panels tied to Moltbot (formerly Clawdbot), an open-source AI agent platform. Moltbot allows large language models (LLMs) to connect with messaging apps and automation tools. Many of the exposed dashboards were live production systems—not test environments—and could be accessed by anyone who knew where to look. This exposure allowed unauthorized users to view sensitive data, [...]

  • PeckBirdy malware attack chain

PeckBirdy: A JScript-Based C2 Framework Used by Chinese APT Groups

January 28th, 2026|

Cybersecurity researchers have discovered PeckBirdy, a modular command-and-control (C2) framework built using JScript. The framework has been used by Chinese advanced persistent threat (APT) groups since at least 2023. It has been seen targeting online gambling sites in China and government and private organizations throughout Asia. Background and Discovery Security firm Trend Micro first identified PeckBirdy in 2023 after finding malicious script injections on several Chinese gambling websites. These injected scripts downloaded and ran additional JavaScript code, allowing attackers to [...]

  • Windows App-V Script Abuse for Infostealer Delivery

Windows App-V Script Abuse for Infostealer Delivery

January 28th, 2026|

Researchers at Blackpoint Cyber have uncovered an advanced malware campaign that uses several evasion tactics to deliver the Amatera information stealer. The attack is designed to bypass enterprise security tools and avoid detection by analysts. Attack Vector and Social Engineering The attack starts with fake CAPTCHA verification pages that trick users into manually running malicious commands using the Windows Run dialog (Win + R). This step is critical for the attackers: it avoids automated sandbox analysis and exploits the user’s [...]

  • Critical Zero-Day Flaw in Microsoft Office Receives Emergency Patch

Critical Zero-Day Flaw in Microsoft Office Receives Emergency Patch

January 27th, 2026|

Microsoft released emergency security updates on Monday to address a high-severity zero-day vulnerability affecting Microsoft Office applications. The flaw, actively exploited by threat actors, has been assigned the identifier CVE-2026-21509 and poses significant risks to organizations worldwide. Understanding the Vulnerability Core Technical Information Tracking Information: CVE-2026-21509 Severity Rating: 7.8/10.0 (High) Classification: Security Feature Bypass Impacted Products: Microsoft Office versions 2016, 2019, 2021, and Microsoft 365 What Makes This Vulnerability Dangerous The security flaw represents a bypass mechanism that undermines Microsoft [...]

  • Konni powershell APT campaign

Konni APT Expands AI-Assisted PowerShell Campaigns Against Blockchain Developers

January 27th, 2026|

The North Korean threat actor known as Konni has been observed deploying PowerShell-based malware that appears to be partially developed with the assistance of artificial intelligence (AI) tools. The activity currently focuses on developers and engineering teams operating in the blockchain and cryptocurrency space. Recent phishing campaigns have impacted targets in Japan, Australia, and India, signaling a geographic expansion beyond the group’s traditional concentration on South Korea. Prior operations have also been recorded across Russia, Ukraine, and multiple European countries. [...]

  • Osiris Ransomware

Osiris Ransomware: Technical Analysis

January 27th, 2026|

Osiris is a newly identified ransomware family first observed in November 2025 during an attack on a large food service franchise operator in Southeast Asia. Although it shares its name with a Locky ransomware variant from 2016, analysis by Symantec and the Carbon Black Threat Hunter Team confirms that this malware is entirely unrelated to earlier threats. Osiris is a new and distinct ransomware family. The attack shows clear tactical similarities to Inc ransomware operations, which may indicate shared affiliates, [...]

  • Arkanix Stealer

Arkanix Stealer: Technical Analysis Summary

January 26th, 2026|

Arkanix Stealer is malware designed to steal credentials and personal data. It's actively being developed and promoted on Discord, with frequent updates and new features. The malware comes in two versions: Standard Version: Written in Python Premium Version: Written in C++, offering additional theft capabilities Both versions are distributed through Discord (disguised as legitimate tools) and various online forums. Distribution and Access The malware's control panel is located at arkanix[.]pw/login. Access requires an invite code distributed through Discord channels. The [...]

  • The Russian government-backed hacking group Sandworm attacks Polish power grid

Sandworm APT Conducts Destructive Cyberattack Against Polish Critical Energy Infrastructure

January 25th, 2026|

The Russian government-backed hacking group 1Sandworm, also known as APT44, UAC-0113, and Seashell Blizzard, is believed to be behind a major cyber-attack targeting Poland's power grid on December 29-30, 2025. According to Energy Minister Miłosz Motyka, this was the most significant attempted cyber-attack on Polish energy systems in recent years. Sandworm operates as Military Unit 74455 within Russia's Main Intelligence Directorate (GRU) and maintains a documented history of destructive operations against critical infrastructure, particularly in Ukraine and NATO-aligned nations. Technical [...]

  • Russian Organizations Hit by Multi-Stage Malware Attack

Russian Organizations Hit by Multi-Stage Malware Attack Using Cloud Services and Anti-Virus Bypass Tools

January 24th, 2026|

A new multi-step phishing attack has been found targeting users in Russia, leading to the installation of ransomware and a remote access tool called Amnesia RAT. Security researchers at Fortinet FortiGuard Labs found that the attack starts with carefully designed fake emails containing business-related documents that look normal and safe. These fake documents, along with hidden scripts, act as distractions, showing victims fake tasks or messages while harmful programs run secretly in the background. Campaign Features One important part of [...]

  • RMM credential theft attack chain

Weaponizing Legitimate RMM Tools via Credential Theft

January 23rd, 2026|

Cybersecurity researchers have uncovered a sophisticated two-phase intrusion campaign in which threat actors exploit stolen credentials to deploy legitimate Remote Monitoring and Management (RMM) software for persistent, covert access to compromised systems. By abusing trusted administrative tools rather than deploying custom malware, the attackers effectively bypass traditional security controls and blend malicious activity into normal IT operations. Attack Methodology Core Attack Strategy - MITRE ATT&CK Tactics: Initial Access, Persistence, Defense Evasion The threat actors rely on valid account credentials as [...]

  • Most active ransomeware in 2025

Ransomware 2025: Technical Analysis of Emerging Threats and Attack Methods

January 23rd, 2026|

Despite unprecedented international law enforcement activity and numerous takedowns of high-profile ransomware operations, the ransomware ecosystem showed remarkable resilience throughout 2025. Rather than shrinking, the threat landscape simply evolved. As established groups disappeared, new operators, affiliates, and Ransomware-as-a-Service (RaaS) platforms rapidly emerged to fill the void, keeping overall attack volumes virtually unchanged.According to industry tracking of public ransomware leak sites, 4,737 ransomware victims were published during 2025, representing a slight 0.8% increase over the 4,701 victims recorded in 2024. While [...]

  • Phishing emails

Energy Companies Under Attack: New Phishing Threat Explained

January 22nd, 2026|

Microsoft has issued an alert regarding a highly sophisticated phishing campaign aimed specifically at organizations in the energy sector. The attacks rely on an “Adversary-in-the-Middle” (AiTM) technique that enables threat actors to harvest user credentials and hijack corporate email accounts. How the Attack Works The campaign begins with emails that appear to originate from trusted business partners with whom the victim organization already has an established relationship. The subject line typically references a routine item such as “NEW PROPOSAL – [...]

  • PurpleBravo Contagious Interview

North Korean PurpleBravo Campaign: Fake Job Interviews to Attack Thousands of Computers

January 22nd, 2026|

Threat intelligence analysis indicates that a North Korean–linked cyber campaign tracked as PurpleBravo targeted at least 3,136 unique IP addresses pretending to conduct job interviews - a scheme known as "Contagious Interview." Who Was Affected The hackers went after about 20 companies in different industries, including artificial intelligence, cryptocurrency, financial services, IT and software companies, and marketing firms. These targeted organizations are located in countries across Europe, South Asia, the Middle East, and Central America. How the Attack Worked The [...]

  • North Korean state-sponsored hacking groups

North Korean Hackers Target macOS Developers Using Malicious VS Code Projects

January 22nd, 2026|

Security researchers at Jamf Threat Labs have uncovered a new attack campaign linked to North Korean state-sponsored hacking groups. The attackers are targeting macOS software developers by abusing malicious Visual Studio Code (VS Code) project files shared through trusted code repositories. How This Campaign Is Different This campaign is an evolution of earlier North Korean operations such as Operation Dream Job, Contagious Interview, ClickFix Interview, and DeceptiveDevelopment. Previous attacks often relied on web-based tricks like HTML smuggling or fake browser [...]

  • VoidLink Malware Framework and Its AI-Assisted Genesis

The VoidLink Malware Framework and How AI Helped Build It

January 21st, 2026|

A detailed technical analysis by Check Point Research has found that the VoidLink framework, a newly discovered, highly sophisticated malware toolkit built to provide long-term, hidden access to Linux-based cloud systems which are created mostly with help from artificial intelligence, directed by one person. This finding marks VoidLink as the first major case of an advanced, feature-packed malware family where the code was largely written by an AI model following instructions from a human. This represents an important change in [...]

  • PDFSider attack flow

PDFSider: A Hidden Backdoor Used by Hackers and Ransomware Groups

January 20th, 2026|

PDFSider is sophisticated hacking software that's being used by both government-sponsored hackers and ransomware criminals. It creates a secret backdoor into computers with fully encrypted communications, allowing attackers to spy on victims long-term and remotely control infected systems. The backdoor gives hackers a hidden command terminal where they can run commands and see results in real time. All communication between the hacker and the infected computer is encrypted using the Botan security library. Once running, PDFSider stays mostly in computer [...]

  • Evelyn Stealer malware abuse VS extensions

Evelyn Stealer Malware Uses Fake VS Code Extensions to Attack Developers

January 20th, 2026|

The malware attack that uses fake Microsoft Visual Studio Code (VS Code) extensions to install a data-stealing program called Evelyn Stealer has been discovered by Trend Micro. The attack specifically targets software developers, using their computers as a way to break into companies and steal digital assets. The attackers focus on organizations where developers use VS Code and third-party extensions, especially when those developers have access to important systems like production servers, cloud platforms, source code, and cryptocurrency. How the Attack [...]

  • Ransomware attack kill chain

Ingram Micro Ransomware Attack: Complete Technical Analysis

January 19th, 2026|

IT distribution giant Ingram Micro1 suffered a major ransomware attack in July 2025 that exposed the personal information of 42,521 employees and job applicants. The SafePay2 ransomware group broke into the company's systems, stole 3.5 terabytes of data, and shut down operations worldwide for nearly a week. The attack caused massive disruption across the global IT supply chain and potentially cost the company $136 million per day in lost revenue. Timeline of the Attack The attack unfolded rapidly over several [...]

  • NexShield malicios Chrome extension

Fake Browser Crash Alerts Transform Chrome Extension Into an Enterprise Backdoor

January 19th, 2026|

Browser extensions continue to represent a disproportionately high-risk attack surface for enterprise environments, offering threat actors a pathway to bypass perimeter defenses and establish persistence directly on corporate endpoints. A recent investigation highlights this risk through a malicious Chrome extension named NexShield, which demonstrates how a single user-initiated installation—sourced from an official and ostensibly trusted marketplace—can escalate into full remote access within a corporate network. Malicious Extension as Initial Access Vector Huntress researchers identified NexShield as a trojanized browser extension [...]

  • Endesa CRM data breach

Endesa Data Breach: Analysis of a Credential-Based Attack on Customer Database

January 19th, 2026|

In early January 2026, a hacker using the names "glock" and "spain" started selling a stolen database from Endesa, Spain's biggest electricity company. The hacker claimed to have personal and financial information for over 20 million people and advertised it on underground websites where stolen data is traded. On January 11, 2026, Endesa publicly admitted that someone had gained unauthorized access to customer data related to energy contracts. The company said passwords weren't stolen and that, when they made the [...]

  • Malware trends in 2025

2025 Malware Trends and What They Mean for 2026

January 18th, 2026|

The malware world changed dramatically throughout 2025. Ransomware attacks jumped 32 percent compared to 2024, and hackers developed new attack methods that will shape cybersecurity challenges in 2026. Looking at last year's campaigns shows several important trends that organizations need to address in their 2026 security plans. Ransomware Gets Bigger What Happened in 2025: Throughout 2025, ransomware attacks reached record levels. Groups like Qilin, Akira, and INC led the way, with Qilin launching over 1,000 attacks and Akira hitting 765 targets. [...]

  • 5 malicious Chrome extensions

Enterprise Platform Accounts Breached Through Orchestrated Malicious Chrome Extension Attack

January 17th, 2026|

Cybersecurity analysts at Socket have identified a systematic attack involving five harmful Google Chrome browser extensions masquerading as authentic human resources and enterprise resource planning software, specifically targeting Workday, NetSuite, and SAP SuccessFactors. These extensions were engineered to achieve complete account compromise through credential theft, blocking administrative remediation efforts, and facilitating large-scale session takeover. The harmful extensions discovered in this attack are: DataByCloud Access Extension ID: oldhjammhkghhahhhdcifmmlefibciph Publisher: databycloud1104 Installs: 251 Tool Access 11 Extension ID: ijapakghdgckgblfgjobhcfglebbkebf Publisher: databycloud1104 Installs: [...]

Reprompt Attack: Single-Click Data Theft from Microsoft Copilot

January 16th, 2026|

Security researchers have uncovered a new attack method called "Reprompt" that allows hackers to silently steal data from AI assistants like Microsoft Copilot. The attack requires just one click from a user and works without any plugins or additional software. How the Attack Works The attack is triggered when a user clicks what appears to be a normal Microsoft Copilot link. Once clicked, the attacker gains control of the Copilot session and can continue stealing data even after the user [...]

  • Gootloader ZIP parser evasion technique

Gootloader: Advanced ZIP File Tricks and Multi-Stage Script Attacks

January 16th, 2026|

Gootloader is a malware loader that's been active since at least 2020. It has come back with major improvements to how it hides from security tools, mainly by using broken ZIP files that are designed to confuse security software. Delivery Method The new Gootloader attacks use specially corrupted ZIP files as their delivery method. These ZIP files contain hundreds or even 1,000 smaller ZIP archives stitched together into one file. The trick works because different programs handle these files differently. [...]

Security Researchers Stop Kimwolf and Aisuru Botnets by Blocking Over 550 Control Servers

January 15th, 2026|

Researchers at Lumen Technologies' Black Lotus Labs shut down a major botnet operation by blocking more than 550 command servers since October 2025. They did this by cutting off communication between the control servers and millions of infected devices. By blocking these internet addresses, they stopped infected devices from receiving instructions and updates. The Botnet Threat The Aisuru/Kimwolf botnet is one of the largest ever seen. It mainly targets cheap Android TV streaming boxes that come with poor security settings. [...]

Hackers Use c-ares DLL Side-Loading to Avoid Detection and Install Malware

January 15th, 2026|

Security researchers have found an active malware campaign that exploits a weakness in how the c-ares library loads files. This method helps attackers get past standard security tools and install various types of trojans and data-stealing malware.According to Trellix, the attack works by placing a malicious file called libcares-2.dll next to a legitimate, digitally signed program called ahost.exe. Attackers often rename this program and bundle it with the fake DLL file. Because the program doesn't specify a secure path for [...]

  • Pluggyape malware attack

PLUGGYAPE Malware Campaign Uses Signal and WhatsApp to Target Ukrainian Military

January 14th, 2026|

Ukraine's Computer Emergency Response Team (CERT-UA) has issued a warning about targeted cyberattacks that occurred between October and December 2025 against Ukrainian defense organizations. The attacks use a new malware family called PLUGGYAPE and rely on popular messaging apps to trick victims into installing malicious software.CERT-UA believes with moderate confidence that a Russian-linked threat group called Void Blizzard (also known as Laundry Bear or UAC-0190) is behind these attacks. This group has been active since at least April 2024 and [...]

  • Microsoft Windows DWM security chain

Microsoft: 114 Windows Security Problems in January 2026 Update

January 14th, 2026|

Microsoft released its first security update of 2026, fixing 114 security problems in Windows. One of these vulnerabilities is currently being exploited by attackers in real-world attacks, making it critical for organizations to install this update quickly. Out of the 114 fixed issues, eight are rated as Critical severity, while 106 are rated Important. The majority of these problems, 58 in total, are privilege escalation vulnerabilities, which allow attackers to gain higher-level access to systems. The update also addresses 22 [...]

SHADOW#REACTOR Campaign: Complex Attack Chain to Install Remote Access Tool

January 13th, 2026|

A multi-stage Windows campaign chains an obfuscated VBS launcher, a self-healing PowerShell downloader, plain-text payload staging, a .NET Reactor-protected in-memory loader, and MSBuild abuse to deliver a commodity remote access trojan while leaving almost nothing on disk for signature scanners to catch. Security researchers at Securonix have documented a multi-stage Windows malware campaign they track as SHADOW#REACTOR, and it is a useful case study in how far commodity malware operators have moved beyond the simple dropper. The campaign's ultimate goal [...]

  • U.S. Warns of Increased Cyber Threats After Venezuela Operation

U.S. Warns of Increased Cyber Threats After Venezuela Operation

January 13th, 2026|

Cybersecurity officials are warning that a recent U.S. military operation in Venezuela has raised the risk of cyberattacks on critical American infrastructure like power grids, water systems, and communications networks. The Cybersecurity and Infrastructure Security Agency (CISA) reports that the U.S. already faces ongoing cyber threats from countries like China and Russia. These threats have grown more serious after the U.S. conducted a raid in Caracas targeting Venezuelan President Nicolás Maduro.While the U.S. hasn't shared details about how the operation was [...]

  • Gobruteforcer exploytation of cryptocurrency infrastructure

GoBruteforcer Campaign: Exploits Default Credentials in Cryptocurrency Infrastructure

January 12th, 2026|

Security researchers at Check Point have identified an evolved variant of the GoBruteforcer malware conducting targeted campaigns against cryptocurrency and blockchain platforms. The attacks exploit weak authentication across multiple database services including FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux-based systems. Root Causes According to Check Point Research's recent findings, two primary factors enable these attacks: AI Training Data Contamination: Large language models trained on database documentation and deployment tutorials now generate code containing the same vulnerable default credentials present in [...]

  • FileDNA offers proactive defense strategy

FileDNA™ from CyberQuay, Inc.: Proactive Defense Strategy

January 12th, 2026|

Morphing malware variants have emerged as among the costliest and operationally challenging threat types confronting enterprises in today's landscape. Current industry analyses link roughly $350 million in avoidable damages to malicious code that perpetually alters its signature to circumvent conventional detection mechanisms. Given that approximately 18 percent of recently identified malware utilizes adaptive or shape-shifting capabilities, reliance on signature-matching defenses has proven inadequate for safeguarding contemporary organizations. This situation highlights the critical imperative to advance cybersecurity approaches from reactive identification [...]

  • VSS Stealer Discord malware

VVS Stealer: A Technical Analysis of Discord-Targeting Malware

January 12th, 2026|

VVS Stealer is a highly evolved information-stealing malware designed specifically to compromise Discord users and harvest sensitive authentication data. Developed in Python, this threat combines advanced obfuscation, durable persistence mechanisms, and Discord-focused exploitation techniques to sustain long-term access to infected systems while effectively evading conventional security controls. Discovery and Distribution Model VVS Stealer was first observed circulating in Telegram channels in April 2025, where it was promoted under a malware-as-a-service (MaaS) business model. The operators implemented a tiered subscription structure [...]

  • MassLogger malware email distribution

MassLogger Malware Distribution via Email Attachments

January 11th, 2026|

On January 7, 2026, security researchers documented a campaign distributing MassLogger credential-harvesting malware through email attachments containing compressed files. The threat actors employed business-oriented social engineering tactics, such as fake invoices and procurement documents, to persuade targets into opening and running concealed malicious executables. After activation, the malware conducted host reconnaissance, verified internet access, and transmitted stolen credentials using SMTP protocols.This campaign exhibited behavioral patterns typical of MassLogger operations, including compressed archive distribution methods, execution of .NET-based payloads, and email [...]

  • Kimwolf Botnet

Tracing the Kimwolf Botnet’s Infrastructure

January 10th, 2026|

In early 2026, researchers from KrebsOnSecurity exposed Kimwolf, a large-scale botnet that compromised more than two million devices by abusing unofficial Android TV streaming boxes. Investigators have since reconstructed the ecosystem of operators, proxy services, and hosting providers that enabled its growth and resilience. Discovery and Early Attribution Chinese security firm XLab published its detailed Kimwolf analysis on December 17, 2025. The malware coerces infected devices into launching DDoS attacks and relaying traffic for residential proxy networks. Kimwolf specifically targeted [...]

  • flowchart of packed malware

pkr_mtsi Packer: Technical Analysis and Detection Guide

January 10th, 2026|

Based of research from Reversing Labs the pkr_mtsi packer operates as a general-purpose loader primarily delivered through malvertising and SEO-poisoning campaigns. Rather than exploiting software supply chains, it relies on user deception by distributing trojanized installers that impersonate legitimate applications such as PuTTY, Rufus, and Microsoft Teams. Through this mechanism, the packer has been observed delivering a range of secondary payloads, including Oyster, Vidar, Vanguard Stealer, and Supper. Longitudinal tracking over an eight-month period shows that pkr_mtsi has undergone iterative development, [...]

  • BlackCat SEO poinsoning

Black Cat: Deploys SEO Poisoning to Distribute Data-Stealing Backdoor

January 8th, 2026|

Cybersecurity researchers from National Computer Network Emergency Response Technical Team/Coordination Center of China1 (CNCERT/CC) and Beijing Weibu2 Online (ThreatBook) have identified an advanced search engine manipulation campaign attributed to the Black Cat3 threat group. This operation relies on fraudulent websites to distribute backdoor malware designed to covertly exfiltrate sensitive data from infected systems. Attack Methodology The attackers manipulate search engine rankings on platforms such as Microsoft Bing, ensuring that malicious websites appear prominently in searches for popular and legitimate software [...]

  • supply chain malware attack

NodeCordRAT: Node.js–based Remote Access Trojan

January 8th, 2026|

Zscaler ThreatLabz identified a malicious npm supply chain campaign in November 2025 involving three related packages: bitcoin-main-lib, bitcoin-lib-js, and bip40. The first two packages function as wrappers and execute a postinstall.cjs script during installation. This script ultimately installs and launches bip40, which contains the actual malware payload. The final implant, designated NodeCordRAT by Zscaler ThreatLabz, is a Node.js–based remote access trojan with credential theft and remote command execution capabilities.While bip40 is commonly delivered via the wrapper packages, it is also [...]

  • PHALT#BLYX RAT

PHALT#BLYX Attack Analysis

January 7th, 2026|

Threat actors are conducting targeted intrusion campaigns against organizations in the hospitality sector using a highly orchestrated, multi-stage infection chain. The operation combines sophisticated social engineering with deliberate abuse of trusted Microsoft framework components to deliver DCRat, a Russia-linked remote access Trojan (RAT) known for its extensive post-compromise functionality. Security researchers at Securonix1 have tracked this activity under the campaign identifier PHALT#BLYX. The campaign relies on phishing emails impersonating legitimate Booking.com reservation cancellation notifications, exploiting the operational workflows of hospitality [...]

  • Tycoon 2FA streading path

Email Spoofing Attack Vector

January 7th, 2026|

For years, organizations have invested heavily in email security, multi-factor authentication (MFA), and identity protection. Yet attackers continue to exploit one of the most trusted elements in enterprise communication: messages that appear to originate from inside the organization itself.Rather than exploiting a software vulnerability, these campaigns take advantage of inconsistent email authentication and complex mail-routing architectures. The result is a phishing email that appears to have been sent by a legitimate employee or internal department, dramatically increasing the likelihood that [...]

  • UAC-0184 Viber Campaign: Technical Analysis

UAC-0184 Viber Campaign: Technical Analysis

January 7th, 2026|

Russia-Aligned Threat Actor Deploys Sophisticated Multi-Stage Attack Chain Against Ukrainian Targets UAC-0184, also tracked as Hive0156, is a Russia-aligned cyber espionage threat actor that conducted sustained campaigns against Ukrainian military and government targets throughout 2025. The operation reflects a deliberate shift away from traditional email phishing toward abuse of encrypted messaging platforms, with Viber selected as the primary delivery channel due to its widespread adoption among Ukrainian officials and the comparatively limited security monitoring applied to messaging traffic. Initial access [...]

  • PDF based deception

Advanced Malware Distribution Through Weaponized PDF Containers

January 6th, 2026|

The state-sponsored hacking group Transparent Tribe (also designated APT36) has launched a sophisticated attack campaign against Indian governmental, academic, and strategic organizations. This Pakistani-origin threat actor, active since 2013, continues to refine its methods for deploying remote access trojans that establish persistent control over compromised systems. PDF-Based Deception Tactics According to CYFIRMA's technical analysis, the campaign demonstrates advanced social engineering through PDF-centric deception. Attackers distribute weaponized Windows shortcut files disguised as legitimate PDF documents, with the malicious LNK files containing [...]

Cultural Assumptions as Hidden AI Security Risks

January 6th, 2026|

Recent international research reveals that many AI security failures stem not from software bugs, but from cultural and contextual assumptions baked into AI systems during development. These assumptions enter through training data selection, design decisions, and operational parameters—creating predictable vulnerabilities that attackers actively exploit, particularly in global deployments. Why Assumptions Become Vulnerabilities AI systems are predominantly built and trained in a narrow set of regions, languages, and social contexts. They excel in familiar environments, but reliability deteriorates elsewhere. This creates: [...]

  • AI assisted supply chain attack

AI-Enabled Offensive Operations in 2026: Supply Chain Credibility Engineering

January 6th, 2026|

The offensive security landscape in 2026 is increasingly defined by adversaries’ ability to manufacture trust at scale using artificial intelligence. Rather than introducing fundamentally new attack classes, threat actors are amplifying established techniques by automating the creation of credibility signals that previously required sustained human effort. Two converging vectors now pose elevated risk to enterprises: the systematic engineering of supply chain legitimacy and the exploitation of AI-enabled internal workflows. Together, these developments erode long-standing trust assumptions that underpin modern software [...]

  • malware variants churn

AI-Accelerated Malware Variant Churn

January 5th, 2026|

By 2026, generative AI will be reshaping malware distribution not through new exploitation techniques, but by industrializing malware variant production. The most significant effects are observed in early-stage infection components such as loaders, droppers, and staging scripts, where high-velocity polymorphism directly undermines signature-based detection and degrades indicator-driven intelligence. The Variant Churn Shift Traditional malware development followed relatively slow iteration cycles. A loader or dropper often remained structurally consistent across campaigns, with manual changes introduced only after detection rates became operationally [...]

  • Agentic micro tasking for attackers

Agentic Task Automation: Micro-Tasking the Intrusion Lifecycle

January 5th, 2026|

As of 2026, the most credible application of AI in offensive cyber operations is not autonomous exploitation but goal-driven orchestration of discrete tasks across the intrusion lifecycle. The technical advance is the compression of planning, execution, and feedback cycles through AI-assisted coordination and persistent state management. The Operational Model Core Architecture Modern agentic systems operate as a human-directed control plane coupled with an AI-driven execution and reasoning layer. The human provides intent and constraints, while the AI decomposes, sequences, and [...]

  • the perfect storm AI in cybersecurity 2026

AI-Assisted Social Engineering: The 2026 Threat Landscape

January 4th, 2026|

The Evolution Beyond Simple Phishing Social engineering attacks in 2026 will have a fundamental transformation. Where organizations once focused on training employees to spot suspicious emails, adversaries now orchestrate sophisticated, multi-stage campaigns that seamlessly blend across communication channels. The shift represents not merely an incremental improvement in attacker tactics, but a structural change in how social engineering operates at scale. The traditional model - an AI language model generating a convincing phishing email - has given way to integrated campaign [...]

  • cybersecurity challenges in the healthcare industry

Cybersecurity Challenges in Healthcare

January 3rd, 2026|

The healthcare sector remains one of the most persistently targeted industries in the cyber threat landscape. Despite growing awareness and increased spending on security technologies, cyber incidents continue to escalate—often with direct consequences for patient safety and clinical operations. A Relentless Threat Environment Recent studies indicate that 93% of U.S. healthcare organizations experienced at least one cyberattack in the past year, with an average of 43 security incidents per organization. The most common attack vectors include cloud account compromise, [...]

  • Malicious Browser Extension Campaign

Global Malicious Browser Extension Campaign Attributed to China-Aligned Threat Actor

January 2nd, 2026|

Cybersecurity researchers have identified a long-running, highly coordinated campaign involving malicious browser extensions operated by a single China-aligned threat actor. Active for approximately seven years, the operation has compromised an estimated 8.8 million users through weaponized extensions targeting Chromium-based browsers (Google Chrome, Microsoft Edge) and Mozilla Firefox.The activity cluster - tracked under the designation DarkSpectre - encompasses three distinct but technically interrelated campaigns. All leverage abuse of browser extension APIs as a supply chain attack vector, enabling large-scale data collection, [...]

  • Silver Fox distributed ValleyRAT

Silver Fox: Rising Technical Maturity

January 2nd, 2026|

The recent phishing activity targeting Indian taxpayers is not an isolated incident but rather a representative component of a broader, highly adaptive operational model employed by the China-aligned threat actor Silver Fox. Current intelligence indicates a clear progression toward layered infection chains, modular tooling, and diversified initial access vectors, reflecting a maturing adversary with both strategic intent and operational discipline. Campaign Analysis: Indian Tax Phishing Kill Chain Analysis conducted by CloudSEK highlights a meticulously engineered infection chain designed to defeat [...]

  • MITRE ATT&CK kill-chain

Modern Cyber Threats: Year 2025 Defense Insights

December 31st, 2025|

Foundation: Methodology and Analytical Basis The 2025 Threat-Led Defense Report from Tidal Cyber1 is derived from tens of thousands of documented adversary behaviors collected through its threat intelligence platform. The analysis correlates observed real-world attack activity with the MITRE ATT&CK framework, enabling consistent comparison of adversary behavior across campaigns, industries, and geographic regions. This behavior-centric methodology reveals repeatable attacker tradecraft rather than isolated incidents, forming the foundation for the three major threat evolutions outlined below. Evolution 1: Scattered Spider’s Strategic [...]

  • Evasive Panda DNS poisoning with MgBot malware

APT Group Evasive Panda: DNS Poisoning to Distribute MgBot Malware

December 29th, 2025|

A sophisticated cyber-espionage operation has been attributed to Evasive Panda, a China-affiliated Advanced Persistent Threat (APT) actor also tracked under the aliases Bronze Highland, Daggerfly, and StormBamboo. Active since approximately 2012, the group has established a long-standing record of highly targeted intrusion campaigns aligned with strategic intelligence-collection objectives. Since November 2022 Evasive Panda conducted a focused and sustained campaign primarily affecting organizations and individuals across Türkiye, China, and India. The activity demonstrated a strong emphasis on selective victim profiling, with operations [...]

  • documents malware techniques

2025 Document-Based Malware Landscape

December 28th, 2025|

Modern email and document-driven attack chains have evolved beyond single exploits. Today's threats prioritize reliable delivery mechanisms combined with rapid credential harvesting and readily available loaders or remote access tools. The dominant outcomes fall into two categories: credential-stealing malware and commodity remote access tools, typically deployed through lightweight loaders and system-native execution methods. Credential-Focused Infostealers Lumma Stealer (LummaC/LummaC2) Prevalence in 2025: Microsoft identifies Lumma as the most frequently encountered infostealer throughout the reporting window spanning mid-2024 through mid-2025. Delivery Chain: [...]

  • AI assisted malware

AI-Powered Malware: A New Era in Cyber Threats

December 28th, 2025|

The Evolution of Cybercrime Through Artificial Intelligence Cybercriminals have begun integrating artificial intelligence into their operations, moving beyond traditional defensive security applications. These adversaries now employ AI to streamline malicious software creation, mechanize attack processes, and expand operations focused on stealing login credentials and establishing unauthorized system access through fraudulent software distribution. This blend of automated processes and manipulation tactics has made cybercrime more accessible to novices while simultaneously enhancing the speed, accuracy, and severity of attacks. Instead of creating [...]

  • malware in today's cybersecurity life

Modern Malware Campaigns: Abuse of Organizational Trust

December 27th, 2025|

Modern malware campaigns are increasingly shifting away from direct exploitation of system vulnerabilities and toward the abuse of organizational trust. Instead of breaking into environments through software flaws, adversaries now conceal malicious logic within data files, developer tools, code repositories, and open-source components—assets that enterprises routinely trust and process as part of normal operations.This represents a meaningful evolution in the threat landscape. Malware no longer presents itself as an obvious executable; it masquerades as legitimate data, software dependencies, or development [...]

  • WebRAT backdoor

Fake PoC Repositories Weaponized to Distribute WebRAT

December 26th, 2025|

Threat actors are increasingly abusing the trust-driven culture of the security research community by weaponizing fake proof-of-concept (PoC) repositories to distribute malware. A newly observed campaign targets students and early-career information security professionals by masquerading as legitimate exploit demonstrations for recently disclosed vulnerabilities, including CVE-2025-59295, CVE-2025-10294, and CVE-2025-59230.According to analysis published by Kaspersky, attackers host malicious ZIP archives within public code repositories that appear, at first glance, to be professionally curated vulnerability research projects. The intent is not mass exploitation, [...]

  • AI generated malicious code

Web Security Threats That Defined 2025

December 26th, 2025|

As 2025 draws to a close, the web security community is confronting a critical reality: legacy web application defense models are no longer sufficient against modern adversarial techniques. The convergence of AI-assisted development, automated exploit generation, and large-scale supply chain compromise has fundamentally altered the web threat landscape. Attacks that once required manual expertise are now executed at scale, impacting hundreds of thousands of production environments simultaneously. This assessment outlines some of dominant threat categories that redefined web, data and email [...]

  • CVE 2025-9491

Microsoft Quietly Rolls Out Fix for Windows Shortcut File Vulnerability

December 25th, 2025|

Microsoft has discreetly implemented a "mitigation" for a serious security flaw affecting Windows shortcut (.LNK) files. The vulnerability was actively exploited by approximately 11 state-backed hacking groups and cybercriminal organizations, yet Microsoft initially declined to classify it as an urgent security threat. Understanding CVE-2025-9491 This vulnerability exploits how command-line arguments are displayed in Windows. Attackers employ a straightforward technique to conceal malicious code from users: The Technique: Threat actors insert large amounts of whitespace into a shortcut file's "Target" [...]

  • Inc Dragon adversary group

Ink Dragon Malware Expands Operations to Southeast Asia and South America

December 25th, 2025|

The sophisticated threat actor Jewelbug, tracked by Check Point Research as Ink Dragon, has significantly expanded its targeting scope since July 2025. While maintaining operations against entities in Southeast Asia and South America, the China-aligned group has increasingly focused on European government organizations. The cybersecurity community also references this cluster as CL-STA-0049, Earth Alux, and REF7707.Active since at least March 2023, Ink Dragon's ongoing campaign has compromised several dozen victims across Europe, Asia, and Africa, with primary targets including government [...]

  • obfuscated malware loader

GachiLoader: Node.js Based Malware Advanced EDR Evasion

December 24th, 2025|

Security researchers have uncovered GachiLoader, a highly obfuscated malware loader written in Node.js that incorporates advanced evasion capabilities and unconventional code-injection techniques. The malware is propagated via the so-called “YouTube Ghost Network,” a coordinated distribution operation that abuses compromised YouTube accounts to promote malicious installers disguised as legitimate software, including cracked applications, game cheats, and productivity utilities. Technical Execution and Evasion Techniques GachiLoader employs a multi-stage infection chain specifically engineered to bypass modern endpoint detection and response (EDR) solutions. In [...]

  • Countloader malware

Updated Malware Delivered via Pirated Software Portals

December 24th, 2025|

Threat researchers have uncovered a sophisticated malware distribution campaign that leverages websites offering pirated software to disseminate an updated variant of CountLoader, a modular and evasive malware loader engineered to bypass endpoint defenses and facilitate follow-on compromise. According to analysts from the Cyderes Howler Cell Threat Intelligence team, CountLoader functions as the initial access component within a multi-stage intrusion framework. Its role is to establish foothold access, evade security controls, and enable the deployment of additional malicious payloads across infected [...]

  • Agentic browser chain attack

MITRE ATT&CK: Agentic AI Browser Abuse

December 23rd, 2025|

Recent disclosures highlight two emerging attack patterns that exploit AI-powered browser agents by embedding malicious intent within otherwise legitimate user-facing content. These techniques bypass traditional exploit primitives and instead rely on instruction delegation, implicit trust, and autonomous task execution by large language model (LLM) agents integrated with cloud services. The attacks demonstrate how agentic workflows can be coerced into destructive actions without exploiting memory corruption, sandbox escapes, or classic prompt injection. Technique 1: Email-Based Agent Instruction Abuse (Google Drive Wipe) Attack [...]

  • Top DDR Vendors in cybersecurity

Data Detection and Response (DDR) vendors

December 23rd, 2025|

Data Detection and Response is one of the faster-growing corners of the security market, and it is crowded with vendors whose approaches differ more than their shared category label suggests. This is an honest map of that landscape, the players worth knowing, and the distinct position a content-first approach occupies within it. CyberQuay operates in the Data Detection and Response space, a market defined by real-time visibility into sensitive data and the ability to act on threats to that [...]

  • Operation MoneyMountISO attack chain

Phishing Operation: Deployment Of Phantom Stealer via ISO-Based Payloads

December 23rd, 2025|

Security analysts have identified an ongoing, targeted intrusion campaign—designated Operation MoneyMount-ISO1—actively targeting Russian enterprises, with a pronounced focus on financial, banking-adjacent, and accounting functions. The operation demonstrates deliberate victim profiling and controlled malware delivery consistent with financially motivated intrusion activity. Attack Chain and Delivery Methodology The campaign relies on highly tailored spear-phishing emails crafted to resemble time-sensitive financial communications, most commonly requests to verify or approve bank transfer transactions. Attached to these emails is a compressed ZIP archive containing [...]

  • GostPoster malware attack

Technical Analysis of the “GhostPoster” Malware Campaign

December 22nd, 2025|

The “GhostPoster” campaign represents a sophisticated abuse of the browser extension supply chain, leveraging steganographic techniques and delayed execution logic to maintain long-term stealth. Researchers at Koi Security identified malicious JavaScript embedded directly within image assets—specifically logo files—used by at least 17 extensions distributed through the Mozilla Firefox add-on ecosystem. These extensions, which accumulated more than 50,000 downloads, were positioned as benign productivity and privacy tools, including VPN clients, ad blockers, weather widgets, translation utilities, and media downloaders. Steganographic Loader [...]

  • MuddyWater group - UDPGangster attack flow

Iranian MuddyWater APT: UDPGangster Backdoor Deployed in Regional Espionage Campaign

December 21st, 2025|

Security researchers at Fortinet have identified a new cyber-espionage operation attributed to the Iranian state-aligned APT group MuddyWater, targeting organizations across Turkey, Israel, and Azerbaijan. The campaign introduces a previously undocumented backdoor, dubbed UDPGangster, which leverages the User Datagram Protocol (UDP) for command-and-control (C2) communications, enabling a low-profile channel designed to evade traditional network inspection and detection mechanisms. Campaign Entry Vector The intrusion chain is initiated through highly targeted spear-phishing emails masquerading as official correspondence from the “Turkish Republic of [...]

  • Nanoremote backdoor

NANOREMOTE Malware Abuses Google Drive for Covert Command-and-Control

December 20th, 2025|

Security researchers at Elastic1 have uncovered a newly identified Windows backdoor, dubbed NANOREMOTE, that repurposes the Google Drive API as its command-and-control (C2) channel. Rather than communicating with attacker-owned servers, the malware abuses Google's trusted cloud infrastructure to exchange commands, upload stolen data, and retrieve additional payloads. This approach allows malicious traffic to blend with legitimate enterprise cloud activity, making detection significantly more challenging for traditional network-based security controls. The discovery also provides another example of a growing trend in [...]

  • Microsoft fixed 56 vulnerabilities with one actively exploited

Microsoft Fixes 56 Vulnerabilities, Including One Under Active Attack

December 19th, 2025|

As part of its December 2025 Patch Tuesday release—the final security update of the year—Microsoft addressed 56 vulnerabilities affecting Windows and related components. Notably, one of these flaws is confirmed to be actively exploited in the wild. Vulnerability Overview Total vulnerabilities patched: 56 Severity ratings: 3 Critical, 53 Important Publicly disclosed prior to patching: 2 Vulnerability categories: 29 elevation-of-privilege 18 remote code execution 4 information disclosure 3 denial-of-service 2 spoofing issues Patch Activity in 2025 Across 2025, Microsoft remediated [...]

Silver Fox Runs False-Flag Ghost ValleyRAT Campaign

December 18th, 2025|

The threat actor tracked as Silver Fox1 is running a false-flag cyber campaign against Chinese organizations, deliberately posing as a Russian-linked threat group. Active since November 2025, the operation relies on SEO poisoning and counterfeit Microsoft Teams installers to distribute the ValleyRAT malware. Key Findings Attack Vector: victims are redirected via poisoned search results to a fake Microsoft Teams download page. The hosted archive, “MSTчamsSetup.zip,” is stored on Alibaba Cloud and embeds Russian-language artifacts intended to mislead attribution efforts. [...]

  • UnpackDNA in action

How UnpackDNA Fixes Unstructured Data Chaos for AI Datasets

December 18th, 2025|

The success of modern AI initiatives depends heavily on the quality of training and test datasets. Yet many organizations still feed their models large volumes of unstructured, inconsistent, and sometimes malicious content—such as documents, PDFs, archives, images with embedded objects, and third-party files never designed for AI datasets use. This data chaos quietly degrades model performance, increases security risk, and drives up operational costs. UnpackDNA, a software solution from CyberQuay, Inc., addresses these challenges by extracting, decoding, and structuring embedded [...]

  • Flow of Webjack SEO fraud

Malware World: The WEBJACK Campaign

December 17th, 2025|

 OverviewA cybercrime operation designated WEBJACK is compromising Microsoft IIS web servers by deploying malicious modules (BadIIS1 malware). The attackers leverage these hijacked servers to conduct widespread SEO manipulation, corrupting search engine results to funnel users toward gambling and casino websites.Primary Findings(credits to WithSecure)Victims: Prestigious organizations worldwide—spanning government agencies, educational institutions, and technology companies—with Vietnam seeing the highest concentration of attacks.Initial Compromise: The entry vector remains unclear, though evidence points to either web application exploitation or credential theft.Threat Actor Indicators: Technical [...]

  • malicious rust packages

Malicious Rust Package Spreads Cross-Platform Malware to Web3 Developers

December 16th, 2025|

Open-source software supply chain attacks continue to evolve, and the latest example demonstrates how threat actors are increasingly targeting developers rather than end users. Security researchers have uncovered a malicious Rust package published on the official crates.io repository that masqueraded as a legitimate Ethereum Virtual Machine (EVM) utility while silently deploying malware across Windows, macOS, and Linux systems. Unlike traditional malware campaigns that rely on phishing emails or malicious attachments, this operation abused the trust developers place in public package repositories. [...]

  • Mobile application threats

Active Threats Targeting Mobile Messaging Applications

December 15th, 2025|

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively abusing commercial spyware and remote access trojans (RATs) to compromise mobile messaging platforms. Rather than attacking the encryption protecting modern messaging services, adversaries focus on the endpoints where messages are created, decrypted, and stored. Once a device is compromised, attackers can monitor conversations in real time, steal credentials, harvest contacts, and impersonate victims regardless of the strength of the underlying encryption. These operations have become increasingly [...]

  • Brickstorm malware

BRICKSTORM: A Long-Lived Backdoor Linked to Chinese State-Sponsored Threat Actors

December 15th, 2025|

The U.S. Cybersecurity and Infrastructure Security Agency1 has released new technical details about BRICKSTORM, a sophisticated backdoor used by state-aligned threat actors associated with the People's Republic of China to establish persistent, covert access within enterprise environments. The malware has been observed during long-running espionage operations targeting critical infrastructure, government agencies, technology providers, and organizations that provide access to downstream customers, emphasizing the strategic focus of Chinese advanced persistent threat (APT) campaigns on long-term intelligence collection rather than immediate disruption. BRICKSTORM [...]

  • Federal Agencies Warn of Pro-Russian Hacktivist Threats

Federal Agencies Warn of Pro-Russian Hacktivist Threats to Critical Infrastructure

December 15th, 2025|

U.S. federal authorities have issued a renewed warning about ongoing cyber activity by pro-Russian hacktivist groups targeting critical infrastructure, alongside the announcement of new criminal charges tied to those operations. This week, prosecutors disclosed that Victoria Dubranova1 , 33, pleaded not guilty in federal court in Los Angeles to an additional set of hacking-related charges linked to the group NoName057(16)2 . Dubranova was extradited to the United States earlier in 2025 and had already faced separate charges connected to CyberArmyofRussia_Reborn3 [...]

  • new phishing kits

New Phishing Kits: BlackForce, GhostFrame, InboxPrime AI, and Spiderman

December 14th, 2025|

Cybersecurity researchers have identified several new phishing kits - BlackForce, GhostFrame, InboxPrime AI, and Spiderman - that significantly lower the barrier for large-scale credential theft and MFA bypass attacks. These platforms combine advanced evasion techniques, real-time data exfiltration, automated campaign management, and phishing-as-a-service capabilities to target popular consumer brands, Microsoft 365 and Google Workspace accounts, enterprise cloud environments, and European financial institutions. Rather than requiring advanced technical expertise, many of these kits package sophisticated attack techniques into turnkey offerings that [...]

State AI Laws in Push for Unified Federal Oversight

December 14th, 2025|

The Trump administration has announced plans to pursue legal action against states that adopt artificial intelligence regulations exceeding what it defines as a “minimally burdensome” federal standard. President Donald Trump has framed the initiative as a strategic necessity to prevent China from gaining a competitive edge in the global AI landscape. AI Laws Push An executive order signed Thursday instructs the Department of Justice to establish a dedicated task force within 30 days to challenge state-level AI laws. The administration [...]