Advertisement
TOAD Emails: The 'Call This Number' Gateway Bypass Threat
Attackers use Telephone-Oriented Attack Delivery (TOAD) with 'call this number' emails to bypass gateways, relying on social engineering post-call.
Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms
Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.
Stolen Credentials and the Escalation of Agentic AI Attacks
IBM X-Force reports 56% of 2025 vulnerabilities require no authentication, enabling agentic AI to weaponize stolen credentials and expand attack blast radius.
OpenClaw Underground Trends: Assessing Hype vs. Operational Risk
Flare telemetry reveals a gap between high OpenClaw chatter on Telegram and actual exploitation, highlighting the need to distinguish hype from threat.
Optimizing Incident Triage to Mitigate Enterprise Business Risk
Examine how inefficient security incident triage increases business risk, escalates operational costs, and leads to missed SLAs in the modern SOC.
SLH Recruits Women for $1,000 IT Help Desk Vishing Attacks
Scattered LAPSUS$ Hunters (SLH) are offering financial incentives to recruit women for vishing campaigns targeting corporate IT help desks and IAM systems.
Data Poisoning Risks in Real-Time AI Search and Ingestion
A recent experiment highlights how rapid web scraping for AI models like Gemini and ChatGPT enables data poisoning attacks through unverified web content.
Quantitative Scoring for OT Incidents: The Richter Scale Model
Analysis of a new logarithmic scoring system designed to quantify the physical magnitude and technical severity of operational technology (OT) cyberattacks.
Cybersecurity M&A Trends 2025: Analysis of 426 Industry Deals
SecurityWeek reports 426 cybersecurity M&A deals in 2025, highlighting a disciplined market shift toward GRC, data protection, and identity management.
Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia
Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.
US Treasury Sanctions Russian Broker for Stolen Zero-Day Exploits
The US sanctions Artem Kruglov and associated firms for brokering stolen hacking tools and zero-day exploits for Russian intelligence services.
L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker
Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.
National Security Risks of Manual Data Transfer Processes
Report reveals 50% of national security organizations rely on manual data transfers, creating systemic risks and critical intelligence latency.
Interpol’s Operation Red Card 2.0: 651 Arrests Targeting Cybercrime
INTERPOL and AFRIPOL's Operation Red Card 2.0 disrupts West African cybercrime syndicates, leading to 651 arrests and $4.3 million in seized funds.
Windows 11 KB5077241: Native Sysmon Integration and BitLocker Updates
Microsoft integrates native Sysmon and enhances BitLocker management in the Windows 11 KB5077241 optional update, providing advanced telemetry for defenders.
Russia's Escalating New Generation Hybrid Warfare in Europe
Analysis of Russia's coordinated New Generation Warfare against NATO, blending cyber attacks, sabotage, and influence operations. Understand the threat.
AI-Enabled Threats: Model Extraction, APT Phishing, & Malware Evolution
GTIG reports on Q4 2025 AI threats: rising model extraction, APTs using AI for reconnaissance and phishing, and new AI-integrated malware families like HONESTCUE and…
UNC6201 Exploits Dell RecoverPoint Zero-Day CVE-2026-22769
Mandiant and GTIG detail UNC6201's exploitation of CVE-2026-22769 in Dell RecoverPoint for VMs, deploying GRIMBOLT backdoor and novel VMware TTPs.
Typosquatting: Deceptive Domains for Credential Theft & Malware
Analysis of typosquatting campaigns leveraging deceptive domain names for phishing, credential harvesting, and malware delivery, bypassing traditional detections.
CrowdStrike 2026 Report: Evasive Adversaries & AI Threat Landscape
Analysis of the CrowdStrike 2026 Global Threat Report, detailing adversaries' shift to evasive tactics, AI integration, and critical identity security needs.
Lazarus Group Shifts to Medusa Ransomware & Multi-Tool Attacks
North Korea's Lazarus Group now employs Medusa ransomware, Comebacker backdoor, Blindingcan RAT, and Infohook info stealer in recent attacks, signaling an evolving…
Attackers Halve Breakout Time to 29 Minutes, CrowdStrike Reports
CrowdStrike research indicates attackers now achieve lateral movement in just 29 minutes, driven by credential misuse, AI, and blind spots.
Diesel Vortex Phishing Campaign Targets Logistics Sector
Financially motivated Diesel Vortex group targets US & European freight and logistics with extensive phishing campaign, using 52 domains to steal credentials.
UAC-0050 Targets European Financial Institutions with RMS Malware
Russia-aligned actor UAC-0050 expands operations beyond Ukraine, targeting European financial entities with spoofed domains and RMS malware for espionage.