Advertisement
Tycoon2FA Phishing Kit Targets Microsoft 365 via Device Code Flow
Tycoon2FA phishing kit now leverages Microsoft 365 device code flows and Trustifi URL abuse to bypass MFA and hijack enterprise accounts.
Turla Updates Kazuar Backdoor with Modular P2P Botnet Capabilities
Russian threat actor Turla (Secret Blizzard) has upgraded its Kazuar backdoor with peer-to-peer botnet functionality and modular architecture for stealth.
AI-Generated Code and Autonomous Agents: New Risks for Defenders
AI agents are automating vulnerability discovery in AI-generated codebases, forcing a shift in defensive security strategies and response times.
BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion
Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.
Security Brief: Data Breaches, ShinyHunters Activity, and App Flaws
Analyzes recent security events: Nvidia cloud gaming data breach, FBI warning on ShinyHunters hacking Canvas, and critical flaws in Audi mobile applications.
Microsoft Edge: Hardening Against Cleartext Password Exposure
Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.
20 Years of Cybersecurity: Strategic Insights from Industry Pioneers
Leading cybersecurity experts reflect on two decades of evolving threats, bug bounties, and the critical transition toward identity-centric security models.
Weaponized Trust: Analyzing the Abuse of Administrative Utilities
Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.
CrowdStrike 2026 Financial Threat Report: Trends in Identity Exploitation
Analysis of the CrowdStrike 2026 Financial Services Threat Landscape Report, focusing on identity-based attacks, cloud risks, and adversary TTPs.
SecurityScorecard Acquires Driftnet: Boosting Supply Chain Threat Intelligence
SecurityScorecard's acquisition of Driftnet aims to enhance third-party ecosystem visibility, strengthening defenses against supply chain attack vectors.
SDR-Based Disruptions in Taiwan Rail Highlight ICS Security Gaps
An SDR-based interference incident in Taiwan underscores critical vulnerabilities in rail signaling and the need for enhanced OT security protocols.
AI & Threat Intelligence: Reshaping Cyber Defense Efficiency
Explore how artificial intelligence, when fused with robust threat intelligence, redefines efficiency in cyber defense operations, empowering security teams.
Upcoming Cybersecurity Engagements: AI, National Security, Digital Humanism
Stay informed on critical cybersecurity discussions as Bruce Schneier outlines upcoming speaking engagements focusing on AI, national security, and digital ethics.
FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing
Belarussian APT 'FrostyNeighbor' is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…
Cyber-Enabled Cargo Theft: How Phishing and Identity Theft Hijack Freight
Cyber-enabled cargo crime leverages stolen credentials and phishing to reroute freight, replacing traditional hijackings with digital fraud and identity theft.
Ghostwriter Targets Ukraine with Geofenced PDF Phishing & Cobalt Strike
Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.
Nitrogen Ransomware Hits Foxconn: Manufacturing Cyber Crisis
Nitrogen ransomware targets Foxconn's North American plants, highlighting a critical trend of cyberattacks against the manufacturing sector's low downtime tolerance.
Salt Typhoon and Twill Typhoon Expand Operations via Updated Backdoors
Chinese APTs Salt Typhoon and Twill Typhoon target Azerbaijan's energy sector and Asian entities using updated backdoors and SparrowDoor variants.
KongTuke Exploits Microsoft Teams for Rapid Corporate Breaches
Initial access broker KongTuke leverages Microsoft Teams to deploy DarkGate malware, achieving network persistence in under five minutes via social engineering.
Addressing AI Hallucinations in Critical Infrastructure Security
Explore how AI hallucinations create systemic risks in critical infrastructure and learn strategies to detect and mitigate these non-deterministic threats.
US Indicts Linus Baumbach: Key Lessons from the Dream Market Takedown
US authorities indict alleged Dream Market administrator Linus Baumbach for drug trafficking and money laundering following his arrest in Germany.
MuddyWater Targets South Korean Electronics Maker in Espionage Campaign
Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities. Learn TTPs and…
Two Decades of Cybersecurity Evolution: Reflecting on Threat Intelligence
Dark Reading's 20th anniversary highlights the dynamic cybersecurity landscape. We analyze two decades of evolving threats and the critical role of intelligence in…
FamousSparrow APT: China-Linked Group Targets Caucasus Energy Sector
China-linked FamousSparrow APT expands targeting to include Azerbaijani energy infrastructure, signaling a shift in strategic objectives for the threat group.