Advertisement
UAT-10147: Agentic AI Enhances Post-Compromise Operations
Chinese-speaking adversary UAT-10147 leverages agentic AI for scaled exploitation, reconnaissance, and persistence on Windows and Linux web servers.
CVE-2026-12569: Clop Exploits Windchill with Custom Web Shell
Clop ransomware group exploited CVE-2026-12569 in PTC Windchill and FlexPLM servers, deploying a custom web shell for deep data theft. Patch immediately.
Clop Ransomware Exploits CVE-2026-12569 in PTC Products
Shell investigates potential data theft by Clop gang after exploitation of critical CVE-2026-12569 in PTC Windchill and FlexPLM instances.
UNC6671 Targets Financial Sector via Vishing and AiTM Phishing
UNC6671, linked to BlackFile, exploits vishing and AiTM phishing against financial firms for cloud data theft and extortion.
ShinyHunters Targeting Healthcare: Data Theft Surges, Health-ISAC Warns
Health-ISAC warns of increasing ShinyHunters data theft attacks on healthcare and med-tech organizations. Learn about TTPs and critical mitigations.
Mount Royal University Data Breach: Network Intrusion, Data Theft, and Deletion
Mount Royal University confirms a significant data breach involving network intrusion, data theft, and subsequent deletion of files from storage systems.
Advertisement
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…
Kairos Group Extorts $1M from US Government in Data-Theft Campaign
A US government entity paid $1M to the Kairos group to prevent a data leak, signaling a shift from traditional ransomware to pure data-theft extortion.
FBI Warns: Russian APTs Target Signal Backup Keys via Phishing
FBI and CISA warn of Russian intelligence targeting Signal users. Attackers phish for backup recovery keys, enabling full account takeover and message history access.
CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft
CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.
Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft
Analysis of the critical Microsoft Copilot 'SearchLeak' attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.
UNC3753 Targets US Law Firms with Vishing & Physical Intrusions
UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.
China's Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil
Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft.
Radiology Associates of Richmond Breach Affects 266,000 Patients
A data breach at Radiology Associates of Richmond has exposed the sensitive health and personal information of over 266,000 individuals.
Ukraine Identifies Odesa-Based Infostealer Operator
Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.
MacSync Stealer Distributed via Malicious Homebrew Ad Campaign
Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.
OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks
Analysis of 38 security flaws in OpenEMR, an EHR platform used by over 100,000 healthcare providers, enabling database compromise, RCE, and data theft.
Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments
A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.
UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware
UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.
Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft
AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.
ShinyHunters Breach: European Commission Cloud Data Theft
ShinyHunters claimed responsibility for a cyber intrusion and 350GB data theft from European Commission cloud systems. Understand the TTPs and mitigation.
Apple Warns of Coruna and DarkSword Exploit Kits Targeting iOS
Apple warns of Coruna and DarkSword exploit kits targeting older iOS versions via malicious web content to steal sensitive data. Update your devices now.