Tag: threat
-
Shattering the Dream When a Job Offer Becomes a Zero-Day Attack
ey Points Introduction Since early 2026, Check Point Research has tracked a wave of theOperation Dream Jobcampaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially…
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. First seen on cyberscoop.com Jump to article: cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/
-
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/
-
Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant
Threat actors used a private cellular access-point-name (APN) network to pivot from a compromised wind farm into the operational technology environment. A Polish combined heat and power plant, where they disrupted Siemens programmable logic controllers and briefly interrupted cogeneration operations. The December 29, 2025 intrusion affected a CHP facility serving approximately 50,000 residents, forcing a…
-
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
-
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate/
-
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.The use of StormEncryptor marks a shift from the adversary’s previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.”StormEncryptor is written in C++ and appends the file name extension .encrypted First seen…
-
AI Threat Intelligence vs. Traditional Threat Intelligence: A Practical Guide for CISOs
Most CTI programs aren’t failing because analysts lack skill. They’re failing because signal volumes have outpaced what any manual workflow can process. Thousands of newly registered domains, phishing kit variants, and brand impersonation attempts surface daily. Human teams can’t triage all of it. Threat intelligence automation addresses the throughput problem by automating collection, enrichment and..…
-
UK man tied to The Com sentenced for abusing 117 victims
Justin Swaddle, who was a minor when he committed the crimes, coerced children across multiple countries into self-harm and sexual abuse using threats tied to their personal information, authorities said. First seen on cyberscoop.com Jump to article: cyberscoop.com/uk-justin-swaddle-the-com-sentenced/
-
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
Tags: china, cybersecurity, exploit, hacker, microsoft, ransomware, software, threat, tool, vulnerabilityA China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able. First seen on therecord.media Jump to article: therecord.media/china-hackers-ransomware-microsoft
-
10th August Threat Intelligence Report
North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/10th-august-threat-intelligence-report/
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Tags: attack, cybersecurity, exploit, flaw, kaspersky, programming, russia, software, threat, vulnerabilityThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.The activity involves exploiting a vulnerability chain First seen on thehackernews.com…
-
Huntress CEO: The Autonomous Adversary Is Here And ‘We’ve All Been Drafted’
The autonomous compromise recently disclosed by OpenAI shows clearly that the AI-powered threats that security experts have been warning about are moving from theory into reality, Huntress CEO Kyle Hanslovan said during the latest episode of CRN’s Security or Else! First seen on crn.com Jump to article: www.crn.com/news/security/2026/huntress-ceo-the-autonomous-adversary-is-here-and-we-ve-all-been-drafted
-
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo’s handling of URL-supplied prompts, enabling attackers to inject malicious instructions into an authenticated user’s AI session. The attack does not require traditional…
-
Suisun City Declares Emergency After Cyberattack Disrupts Systems
The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services. First seen on thecyberexpress.com Jump to…
-
UK manufacturers face rising hacking risk as survey shows 30% were hit last year
Big companies describe being under constant threat but only half have a plan in place to respond to an attackNearly a third of British manufacturers have been hit by a cyber-attack on them or a company in their supply chain, according to a survey that highlighted the growing hacking risk to companies.The findings come almost…
-
Urlaubszeit Sommerzeit Vorfallzeit: Sechs Ratschläge für Zeiten mit geringer Personalstärke
Management Summary Urlaubszeit ist Risikobetrieb: Reduzierte Personalstärke, höhere Abhängigkeit von IT-Systemen und wachsende Angriffsflächen machen die Sommermonate zu einer Phase mit erhöhtem Kontrollbedarf. KI verändert das Schwachstellenmanagement: Frontier-KI-Modelle beschleunigen die Entdeckung und Veröffentlichung von Verwundbarkeiten; Patch-, CERT- und Threat-Feed-Prozesse müssen deshalb auch in Ferienzeiten aktiv bleiben. Klare Rollen verhindern Wissensmonopole: Ein offiziell definierter Reduced Staff……
-
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released a fresh round of hotfixes for N”‘central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.”We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said.”This is not…
-
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hours. Researcher Paul McCarty documented the campaign, tracked as WEL1DROPPER, and the package count has since grown past 1,000. WEL1DROPPER marks an evolution in AI slopsquatting, where attackers register randomly…
-
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain, StormEncryptor, on August 2, 2026. The activity represents Storm-1175’s first observed operation since April 2026 and signals a notable shift in its ransomware tooling. The group was previously associated with…
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…
-
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.”UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their…
-
Water utilities group partners with DEF CON offshoot for Water Watch Center
The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems. First seen on therecord.media Jump to article: therecord.media/water-watch-center-utilities-def-con-franklin-nrwa
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…

