Tag: threat
-
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/
-
AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027
AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/aws-waf-anti-ddos-rule-group/
-
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks. Initial samples observed in March 2026…
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…
-
Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed
A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed phishing email delivering a “secure document” lure. Victims are redirected through compromised infrastructur to a…
-
The Case for Human Authority in AI-Driven Cybersecurity
AI Can Detect Threats Fast, but Only Humans Can Judge and Own the Response As AI takes on more of cybersecurity’s workload, from threat detection to automated response, the real question isn’t how much autonomy machines should have; it’s who remains accountable when they act. This piece makes the case for human authority over AI-driven…
-
Insane Castle Hurricane: APT Codename Confusion Proliferates
Google Debuts Yet Another Way to Track State-Sponsored and Cybercrime Actors What do Castle, Ion, Neptune, Relic and Comet have in common? They’re among the codenames Google will begin assigning to threat groups, many of which already have a dozen different codenames assigned to them. In the words of one researcher: There is a massive…
-
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese First seen…
-
27th July Threat Intelligence Report
Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/27th-july-threat-intelligence-report/
-
âš¡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.That is the mood. Here is the full recap.âš¡ Threat of the…
-
Anubis Warum ein Patch allein nicht ausreicht
Bereits Anfang Juli berichtete das Arctic Wolf Labs-Team von wichtigen Erkenntnissen rund um die Anubis-Ransomware. Und die Gefahr, die durch die Cyberkampagne ausgeht, ist noch lange nicht gebannt. Stefan Hostetler, Staff Threat Intelligence Researcher bei Arctic Wolf, gibt seine Einschätzung zum Risiko, das von der Anubis-Ransomware ausgeht und welche Schritte Unternehmen zur Abwehr ergreifen sollten.…
-
Google changes how it names cyber threat actors
Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/google-threat-actors-naming-system/
-
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote First…
-
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift from purely digital exploitation to coordinated physical coercion campaigns. Recent threat intelligence indicates that attackers are systematically profiling cryptocurrency holders using publicly available data across platforms such as Instagram, TikTok, X,…
-
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.…
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Tags: advisory, automation, cisa, cyber, cybersecurity, exploit, hacker, infrastructure, Internet, iran, technology, threatIranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors. A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology…
-
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript…
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 2024, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign, attackers rode SonicWall SMA zero-days to root, a Bluetooth flaw put 2 million cars at […]…
-
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel…
-
Cloud resilience model invalidated by systemic threats
First seen on scworld.com Jump to article: www.scworld.com/brief/cloud-resilience-model-invalidated-by-systemic-threats
-
Cybersecurity threats escalate with ransomware, data breaches and online fraud
First seen on scworld.com Jump to article: www.scworld.com/brief/cybersecurity-threats-escalate-with-ransomware-data-breaches-and-online-fraud
-
Kubernetes Runtime Threats Explained
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/kubernetes-runtime-threats-explained
-
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Tags: authentication, data, data-breach, endpoint, exploit, extortion, flaw, Internet, login, ransomware, rce, remote-code-execution, threatThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.”Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling…
-
Google Launches Unified Cryptonym-Based Naming System for Threat Actors
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams. The initiative follows the integration of Mandiant and Google’s Threat Analysis Group (TAG) into GTIG. Before the merger, both organizations…
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion. The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned…
-
CISOs vs. Boards: Myth or Misunderstanding?
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/cisos-vs-boards-myth-or-misunderstanding-
-
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
-
OpenAI Hugging Face Hack Shows Autonomous Threats Are ‘No Longer Theoretical’: Accenture Exec
An autonomously executed hack carried out by rogue OpenAI frontier models is underscoring the potential risk from deploying AI without appropriate security and governance, executives at two top solution providers told CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/openai-hugging-face-hack-shows-autonomous-threats-are-no-longer-theoretical-accenture-exec

