Advertisement
Analyzing the Frequency of Open Redirects in Phishing Campaigns
Examine the technical drivers behind the use of open redirects in phishing delivery and learn strategies for detection and vulnerability remediation.
Google Accelerates Post-Quantum Cryptography Transition for 2029
Google announces a full migration to post-quantum cryptography by 2029 to ensure crypto-agility and defend against future quantum computing threats.
BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks
Germany's BKA unmasks the leadership of the REvil (Sodinokibi) ransomware group, including the representative UNKN, following a major threat intel investigation.
Germany Doxes UNKN: Identity of REvil and GandCrab Leader Revealed
German authorities identify Daniil Maksimovich Shchukin as UNKN, the lead operator behind the notorious GandCrab and REvil ransomware operations.
QR Code Phishing: SMS Traffic Violation Scams Bypass Mobile Filters
Scammers are using QR codes in SMS traffic violation scams to bypass security filters and steal financial data. Learn how to identify and block quishing.
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.
LinkedIn Browser Fingerprinting: Privacy Risks of Extension Scanning
LinkedIn is reportedly scanning users for over 6,000 Chrome extensions using browser fingerprinting techniques, raising significant privacy concerns.
BrowserGate: LinkedIn's Stealthy Chrome Extension Scanning and Data Collection
Analysis of 'BrowserGate' reveals LinkedIn's hidden JavaScript scanning over 6,000 Chrome extensions and collecting user device data. Understand the privacy implications.
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.
TA416 Targets European Govts with PlugX & OAuth Phishing
China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.
Emerging XR Authentication: Skull Vibrations for Identity
Emerging research suggests skull vibration harmonics from vital signs could serve as a novel authentication method for VR, AR, and MR headsets, offering unique identity…
TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting
Runtime Rebel details how TeamPCP's supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos. Learn to defend against these…
Recent Cyber Threats: Data Leaks, Android Malware, Critical Infra Ransomware
Analysis of a ChatGPT data leak, the emergence of an Android rootkit, and a ransomware attack impacting a water facility. Essential insights for defenders.
TrueConf Zero-Day: Exploitation Against Asian Governments
A Chinese threat actor is actively exploiting a TrueConf video conferencing zero-day to conduct reconnaissance and achieve privilege escalation against Asian government…
Multi-Extortion Ransomware Tactics: A Deeper Dive
Analyze the evolution of multi-extortion ransomware, its reliance on data leaks, and strategies for mitigating the impact of exfiltrated data.
WebinarTV Secretly Records Public Zoom Meetings: Privacy Risks
WebinarTV records and publishes public Zoom meetings without consent. Understand the privacy risks and implement immediate mitigations for sensitive data exposure.
Shadow AI & Zero-Click Exploits Expand Enterprise Mobile Attack Surface
Enterprises face a growing mobile attack surface from shadow AI in apps, outdated devices, and zero-click exploits, leading to unseen risks for corporate data.
LAC Cybercrime Trends 2025: Banking Trojans and Ransomware Shifts
Analysis of the 2025 Latin America and Caribbean cybercrime landscape, highlighting banking trojan evolution and regional ransomware operation trends.
TeamPCP Breach of European Commission Affects 30 EU Entities
CERT-EU attributes a major cloud security breach at the European Commission to threat group TeamPCP, impacting data across 30 European Union organizations.
Windows 11 Version 24H2 Force Upgrade for Unmanaged PCs
Microsoft initiates forced upgrades to Windows 11 24H2 for unmanaged Home and Pro devices to maintain security support and critical update delivery.
CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets
Attackers are exploiting the CVE-2025-55182 React2Shell vulnerability in Next.js to harvest AWS secrets, SSH keys, and database credentials from 766 hosts.
Drift Protocol Compromise: Admin Control Seized, $280M Lost
Analysis of the Drift Protocol incident where a threat actor seized Security Council powers, leading to a $280 million loss. Learn about the attack vector and mitigation.
Vite Exposed Installs: Exploitation Attempts & Mitigation for CVE-2025-30208
Runtime Rebel warns of active exploitation attempts targeting exposed Vite development environments. Learn about CVE-2025-30208 and critical mitigation steps.
BRICKSTORM Malware: Hardening vSphere & VCSA Against Advanced Threats
Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…