Advertisement
BadeSaba Calendar App Compromised in State-Linked Propaganda Campaign
An analysis of the BadeSaba Calendar hack, where five million Iranian users received propaganda notifications during kinetic strikes, highlighting PsyOps risks.
Phobos Ransomware Admin Evgenii Ptitsyn Pleads Guilty to Fraud
Russian national Evgenii Ptitsyn pleaded guilty for his role in administering the Phobos ransomware-as-a-service operation that extorted $16 million.
Dust Specter Targets Iraqi Officials with SPLITDROP and GHOSTFORM
An Iran-nexus actor, Dust Specter, targets the Iraqi Ministry of Foreign Affairs using two new malware strains, SPLITDROP and GHOSTFORM, for espionage.
FBI and Europol Dismantle LeakBase Cybercrime Forum — Operation Update
International law enforcement agencies seize LeakBase forum, a major marketplace for stolen credentials and cybercrime tools with 142,000 members.
Tycoon 2FA PhaaS Infrastructure Dismantled in Europol-Led Operation
Europol and global law enforcement dismantle Tycoon 2FA, a Phishing-as-a-Service kit used in 64,000 attacks to bypass MFA via AitM techniques.
Targeted vs. Opportunistic: Differentiating Cyber Intrusions
Learn to distinguish targeted cyber intrusions from automated opportunistic scanning.
Advertisement
Russian Coruna iOS Exploit Kit Targets Global Users — Analysis
Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.
Iran-US/Israel Cyber Conflict: Geopolitical & Cyber Threat Analysis
Analysis of the ongoing US-Israeli strikes on Iran, covering cyber, physical, and geopolitical dimensions.
Cybersecurity 'Hive Mind': Collective Defense Against Emerging Threats
Explore how 'hive mind' principles can enhance enterprise cybersecurity defenses through collective intelligence, shared threat awareness, and unified response…
Tycoon 2FA PhaaS Platform Dismantled in Global Law Enforcement Takedown
International law enforcement dismantled Tycoon 2FA, a Phishing-as-a-Service platform used to bypass MFA and target 500,000 organizations monthly.
Hacktivist DDoS Surge: Keymous+ and DieNet Target Middle East
Post-conflict, hacktivist groups Keymous+ and DieNet launched 149 DDoS attacks against 110 organizations across 16 countries in the Middle East.
AI Recommendation Poisoning: Manipulating Summarization Features
Discovery of hidden prompt injection in AI summarization buttons allows companies to bias AI memory and manipulate future user recommendations.
LastPass Phishing Campaign Targets Master Passwords via Fake Alerts
LastPass warns of a new phishing campaign using fraudulent security alerts to steal master passwords. Learn how to identify and mitigate these vault threats.
APT41-Linked Silver Dragon Targets Governments via Google Drive C2
APT41 sub-group Silver Dragon targets European and Southeast Asian governments using public-facing server exploits and Google Drive for C2 operations.
LATAM Cyber Threat Evolution: Proactive Intelligence Imperative
Latin America's cybersecurity landscape demands a shift from reactive defense to proactive threat intelligence to counter escalating PIX fraud, ransomware, and targeted…
TPMS Data Leakage: Silent Vehicle Tracking via RF Sensors
Unencrypted Tire Pressure Monitoring System signals allow for passive vehicle tracking. Learn how attackers exploit unique sensor IDs to monitor movement.
Intelligence-Led Takedown of African Cybercrime Syndicate
Runtime Rebel details how a threat intelligence team supported Interpol in dismantling a major African cybercrime syndicate, leading to 574 arrests and $3M+ recovered.
Moltbook's 'AI Theater': Unmasking Human Control in Autonomous Platforms
Runtime Rebel investigates Moltbook's 'AI-only' facade, revealing extensive human involvement.
Mitigating Shadow AI Risks: Data Leaks from AI Browsers
Banning AI browsers leads to 'Shadow AI' and uncontrolled data exposure. Learn to implement controlled enablement and robust governance to prevent data leakage.
Fake IT Support Campaigns Deploy Customized Havoc C2 Payloads
Huntress identifies a new campaign using fake IT support lures and vishing to deploy Havoc C2 for data exfiltration and ransomware delivery.
CrushFTP Bruteforce Scans: Protecting Against RCE & Auth Bypass
Ongoing bruteforce scans are targeting CrushFTP servers, likely attempting to exploit past critical vulnerabilities like CVE-2024-4040 (RCE) and CVE-2025-31161 (auth…
Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs
Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for…
Pro-Iranian Cyber Operations Escalate Amidst Middle East Conflict
Analysis of escalating pro-Iranian cyberattacks targeting economic and physical infrastructure in retaliation for US-Israeli military actions.
SecOps Resilience: Addressing Critical Security Operations Challenges
Fig Security launches with $38M to enhance SecOps resilience. This analysis details modern security operations challenges and strategies for improving security posture.