Advertisement
Google Reports 90 Zero-Day Exploits in 2025: Enterprise Focus
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited throughout 2025, with nearly half targeting enterprise software and appliances.
Harvest Now, Decrypt Later: Preparing for Quantum-Era Threats
Understand the 'harvest now, decrypt later' threat. Learn how attackers store encrypted data today for future quantum decryption and how to mitigate risks with PQC.
Redis RCE Threats Amidst Broader Cyber Landscape
A new wave of cyber threats emerges, headlined by potential Redis RCE vulnerabilities, sophisticated DDR5 bot scalping operations, and escalating privacy concerns.
BadeSaba Calendar App Compromised in State-Linked Propaganda Campaign
An analysis of the BadeSaba Calendar hack, where five million Iranian users received propaganda notifications during kinetic strikes, highlighting PsyOps risks.
Phobos Ransomware Admin Evgenii Ptitsyn Pleads Guilty to Fraud
Russian national Evgenii Ptitsyn pleaded guilty for his role in administering the Phobos ransomware-as-a-service operation that extorted $16 million.
Dust Specter Targets Iraqi Officials with SPLITDROP and GHOSTFORM
An Iran-nexus actor, Dust Specter, targets the Iraqi Ministry of Foreign Affairs using two new malware strains, SPLITDROP and GHOSTFORM, for espionage.
FBI and Europol Dismantle LeakBase Cybercrime Forum — Operation Update
International law enforcement agencies seize LeakBase forum, a major marketplace for stolen credentials and cybercrime tools with 142,000 members.
Tycoon 2FA PhaaS Infrastructure Dismantled in Europol-Led Operation
Europol and global law enforcement dismantle Tycoon 2FA, a Phishing-as-a-Service kit used in 64,000 attacks to bypass MFA via AitM techniques.
Targeted vs. Opportunistic: Differentiating Cyber Intrusions
Learn to distinguish targeted cyber intrusions from automated opportunistic scanning. This guide details key indicators for accurate threat classification and resource…
Russian Coruna iOS Exploit Kit Targets Global Users — Analysis
Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.
Iran-US/Israel Cyber Conflict: Geopolitical & Cyber Threat Analysis
Analysis of the ongoing US-Israeli strikes on Iran, covering cyber, physical, and geopolitical dimensions. Understand the evolving threat landscape and defender…
Cybersecurity 'Hive Mind': Collective Defense Against Emerging Threats
Explore how 'hive mind' principles can enhance enterprise cybersecurity defenses through collective intelligence, shared threat awareness, and unified response…
Tycoon 2FA PhaaS Platform Dismantled in Global Law Enforcement Takedown
International law enforcement dismantled Tycoon 2FA, a Phishing-as-a-Service platform used to bypass MFA and target 500,000 organizations monthly.
Hacktivist DDoS Surge: Keymous+ and DieNet Target Middle East
Post-conflict, hacktivist groups Keymous+ and DieNet launched 149 DDoS attacks against 110 organizations across 16 countries in the Middle East.
AI Recommendation Poisoning: Manipulating Summarization Features
Discovery of hidden prompt injection in AI summarization buttons allows companies to bias AI memory and manipulate future user recommendations.
Operational Technology SOC Design: Prioritizing Industrial Reliability
Learn the core principles for designing an OT SOC that balances cybersecurity with industrial safety, reliability, and continuous business operations.
LastPass Phishing Campaign Targets Master Passwords via Fake Alerts
LastPass warns of a new phishing campaign using fraudulent security alerts to steal master passwords. Learn how to identify and mitigate these vault threats.
APT41-Linked Silver Dragon Targets Governments via Google Drive C2
APT41 sub-group Silver Dragon targets European and Southeast Asian governments using public-facing server exploits and Google Drive for C2 operations.
LATAM Cyber Threat Evolution: Proactive Intelligence Imperative
Latin America's cybersecurity landscape demands a shift from reactive defense to proactive threat intelligence to counter escalating PIX fraud, ransomware, and targeted…
TPMS Data Leakage: Silent Vehicle Tracking via RF Sensors
Unencrypted Tire Pressure Monitoring System signals allow for passive vehicle tracking. Learn how attackers exploit unique sensor IDs to monitor movement.
Intelligence-Led Takedown of African Cybercrime Syndicate
Runtime Rebel details how a threat intelligence team supported Interpol in dismantling a major African cybercrime syndicate, leading to 574 arrests and $3M+ recovered.
Moltbook's 'AI Theater': Unmasking Human Control in Autonomous Platforms
Runtime Rebel investigates Moltbook's 'AI-only' facade, revealing extensive human involvement. Understand the cybersecurity implications of deceptive AI for trust and…
Mitigating Shadow AI Risks: Data Leaks from AI Browsers
Banning AI browsers leads to 'Shadow AI' and uncontrolled data exposure. Learn to implement controlled enablement and robust governance to prevent data leakage.
Fake IT Support Campaigns Deploy Customized Havoc C2 Payloads
Huntress identifies a new campaign using fake IT support lures and vishing to deploy Havoc C2 for data exfiltration and ransomware delivery.