Advertisement
APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers
Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…
Iran-Linked Cyber Attacks Persist Despite Israel-Hezbollah Ceasefire
Iran-affiliated threat actors maintain operational tempo against US critical infrastructure, disregarding kinetic pauses in Middle East regional conflicts.
AI-Led Remediation Crisis: HackerOne Halts Bug Bounties
HackerOne pauses bug bounties due to an AI-driven remediation crisis, highlighting how automated vulnerability discovery overwhelms open-source project capacity to fix…
Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics
Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.
UNC6783 Leverages BPOs to Steal Corporate Zendesk Tickets
New threat actor UNC6783 targets Business Process Outsourcing (BPO) providers to gain access to client Zendesk support tickets, risking sensitive data.
APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware
APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.
Advertisement
Detecting Malicious Web Shells: Analysis of Persistence and TTPs
Discover how attackers use deceptive naming and pre-set credentials in web shells to maintain persistence and how to detect these malicious files on servers.
Windows 11 23H2 Start Menu Search Fix — Microsoft Implementation Guide
Microsoft has resolved a Windows 11 23H2 bug causing Start Menu search failures using a Known Issue Rollback. Discover how this fix impacts system stability.
Iranian Hackers Targeting U.S. Critical Infrastructure via PLCs
U.S. agencies warn of Iran-linked hackers disrupting critical infrastructure by exploiting internet-exposed PLCs to manipulate data and halt operations.
Storm-1175: High-Velocity Medusa Ransomware Campaigns
Runtime Rebel reports on Storm-1175's rapid Medusa ransomware campaigns, exploiting N-day and zero-day vulnerabilities for financial gain.
Iran-Linked Cyber Av3ngers Target US Water Sector PLCs
US federal agencies warn of Iran-linked Cyber Av3ngers targeting Unitronics PLCs in critical infrastructure. Learn how to detect and mitigate these OT attacks.
FBI Reports $21 Billion Cybercrime Loss in US: Key Attack Vectors
The FBI's IC3 report reveals Americans lost a record $21 billion to cybercrime, primarily due to investment scams, BEC, tech support fraud, and data breaches.
Iranian APT Exploits Rockwell Automation PLCs: Securing Critical Infrastructure OT Devices
Iranian-affiliated APT actors are exploiting internet-facing Rockwell Automation PLCs, disrupting US critical infrastructure.
AI's Impact on Software Supply Chain Security and Vulnerability Management
AI is set to revolutionize software development, enabling 'instant software' and advanced vulnerability detection, profoundly reshaping future cybersecurity strategies.
Russian Hackers Exploit Routers to Steal Microsoft Office Tokens
Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…
AI-Enabled Cyber Attacks: Adapting Defenses for Agentic Speed
AI is accelerating cyber attack speed, demanding architectural shifts in defense. Understand nation-state threats and strategize for agentic attack response.
Anthropic Claude Mythos: Dual-Use AI for Cyber Defense and Offense
Anthropic's Claude Mythos AI, part of Project Glasswing, promises to revolutionize software security but also risks enhancing adversary capabilities.
Iranian-Linked Actors Target Rockwell/Allen-Bradley PLCs in U.S. Critical Infrastructure
U.S. critical infrastructure faces threats from Iranian-linked actors targeting internet-exposed Rockwell/Allen-Bradley PLCs. Learn about the risk and mitigations.
APT28 Exploits MikroTik & TP-Link Routers in DNS Hijacking
Russian state-linked APT28 (Forest Blizzard) is compromising insecure SOHO routers globally, employing DNS hijacking for cyber espionage since May 2025.
RSAC 2026: Navigating AI's Strategic Role in Cybersecurity Operations
Explore the cybersecurity debates from RSAC 2026 regarding AI's expanding role, from agentic applications to the critical need for human oversight in defensive…
AI's Rapid Reshaping of Cybersecurity Operations & Future Threats
Analysis from RSAC 2026 on AI's accelerating influence across cybersecurity, detailing its role in threat detection, defense, and emerging attack vectors.
Automated Pentesting Limitations: The PoC Cliff and Validation Gap
Automated pentesting tools often plateau, leaving critical attack surfaces untested. Learn about the 'PoC cliff' and its impact on security validation.
APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins
Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.
ComfyUI Instances Abused by Cryptomining Botnet: Mitigation
Over 1,000 internet-exposed ComfyUI instances are actively targeted by a cryptomining and proxy botnet. Secure your deployments now.