Advertisement
Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys
Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.
CanisterWorm Wiper Attacks Target Iran via Cloud Misconfigurations
Analysis of the CanisterWorm wiper targeting Iranian systems through cloud service vulnerabilities, shifting from financial extortion to destructive operations.
Mandiant M-Trends 2026: Handoff Time Shrinks to 22 Seconds
Mandiant's M-Trends 2026 report reveals a drastic reduction in initial access handoff times to 22 seconds, demanding faster detection and response.
RSAC 2026: Analyzing Pre-Event Cybersecurity Vendor Announcements
Analysis of pre-event announcements for RSAC 2026, detailing the shift toward AI-driven security operations and unified identity-centric defense strategies.
Tycoon 2FA PaaS Recovery: Detecting AitM Phishing Infrastructure
Tycoon 2FA Phishing-as-a-Service has recovered from law enforcement disruption. Learn how this AitM platform bypasses MFA and how to protect your organization.
Iranian Handala Group Leverages Telegram for Malware Delivery and C2
FBI alerts organizations to Handala, an Iranian MOIS-linked group using Telegram APIs for data exfiltration, ransomware, and wiper attacks across sectors.
Advertisement
IRS Phishing Campaign Targets 29,000 Users with RMM Malware
Microsoft warns of a widespread IRS phishing campaign targeting 29,000 users with tax-themed lures to deploy RMM malware and steal enterprise credentials.
Azure Monitor Alert Abuse: Detecting Callback Phishing Campaigns
Threat actors are abusing Microsoft Azure Monitor Action Groups to send legitimate-looking callback phishing emails to bypass traditional security filters.
Google Play Protect Advanced Flow for Android Sideloading
Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.
Russian Intelligence Phishing Targets Signal and WhatsApp Users
The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.
Russian Intelligence Targets Commercial Messaging App Accounts
Russian intelligence services are exploiting commercial messaging applications through phishing to compromise accounts of U.S. government officials, military, and…
Beast Gang OpSec Fail: Ransomware Server Exposes TTPs
Beast Gang's OpSec failure exposes their cloud ransomware server, revealing aggressive tactics against network backups. Defenders gain insight into their TTPs.
Operation Alice Disrupts 373,000 Dark Web Fake CSAM Sites
International law enforcement's Operation Alice has shut down over 373,000 dark web sites offering fake CSAM, impacting criminal infrastructure.
Interlock Ransomware Targets Cisco Firewalls via CVE-2024-20481
Interlock ransomware operators exploited a critical Cisco ASA vulnerability before public disclosure. Learn how to detect and mitigate these targeted attacks.
Smuggling of AI Servers to China: DOJ Indicts Three for Export Violations
Three California residents face charges for allegedly conspiring to smuggle restricted high-performance AI servers to China through deceptive front companies.
Android Security Safeguards and UK Cyber Reporting Mandates
Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.
Mitigating Geopolitical Cyber Threats and Wiper Malware Impacts
Analysis of how geopolitical tensions drive destructive cyberattacks and technical strategies for CISOs to contain lateral movement and build resilience.
Cape Secures $100M to Mitigate Cellular Tracking and Metadata Risks
Cape raises $100 million to build a privacy-first MVNO, addressing critical cellular network vulnerabilities like IMSI catching and location tracking.
AI-Generated Music Fraud: How Bots Siphoned $10M in Royalties
A North Carolina musician pleaded guilty to a $10M fraud scheme using AI bots and automated streaming accounts to exploit major digital music platforms.
How Behavioral Analytics Counters AI-Enabled Phishing and Malware
Discover how AI-driven attacks like deepfakes and automated phishing evade legacy security and why behavioral analytics is essential for modern threat detection.
Google Android Security: 24-Hour Wait for Unverified Sideloading
Google introduces a mandatory 24-hour cooling-off period for sideloading unverified Android applications to mitigate malware and financial scams.
Aisuru and Kimwolf DDoS Botnets Disrupted in International Takedown
International law enforcement agencies have disrupted the infrastructure of the Aisuru, Kimwolf, JackSkid, and Mossad botnets, reducing global DDoS risks.
Global Law Enforcement Action Disrupts Major IoT DDoS Botnets
Authorities from the US, Germany, and Canada dismantled C2 infrastructure for the Aisuru, KimWolf, JackSkid, and Mossad botnets used in global DDoS attacks.
Apple Warns of Coruna and DarkSword Exploit Kits Targeting iOS
Apple warns of Coruna and DarkSword exploit kits targeting older iOS versions via malicious web content to steal sensitive data. Update your devices now.