Tag: threat
-
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes First seen on securityonline.info Jump to article: securityonline.info/goserpent-backdoor/
-
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing…
-
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential First seen…
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed…
-
Top 10 Best 24/7 Security Monitoring Companies in 2026
A comprehensive and proactive security posture is non-negotiable for organizations in 2026. With a rapidly evolving threat landscape and a global shortage of cybersecurity talent, relying on an internal team alone to provide round-the-clock protection is often unfeasible. 24/7 security monitoring companies fill this critical gap by serving as an extension of an organization’s security…
-
Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional email phishing volumes tied to major platforms like Tycoon2FA decline. Microsoft’s recent email threat landscape data for Q2 2026 shows a sharp downstream impact from the March disruption of the…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
InfoGuard Threat Intelligence Insights 2025 – Bei 68 Prozent der unsicheren VPN-Zugänge dringt Ransomware ein
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-vpn-zugaenge-cyberangriffe-2025-a-f9aebac63f3383f7d23e8fec9f44326c/
-
Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems
CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights…
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed Laundry Bear, sends half-click phishing emails that require a victim only to open or preview the message. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
-
Top 10 Best Physical Security Penetration Testing Firms 2026
In an era dominated by cyber threats, the importance of physical security penetration testing often gets overshadowed. However, a robust security posture requires a holistic approach that addresses vulnerabilities in both the digital and physical realms. A determined attacker can bypass sophisticated cyber defenses simply by walking through an unlocked door, exploiting weak physical controls,…
-
Unprivilegierte lokale Nutzer erlangen Root-Rechte durch Linux-Kernel-Schwachstelle ‘RefluXFS”
Da in Unternehmen, Behörden und KRITIS-Umgebungen im DACH-Raum Linux und davon abgeleitete Distributionen in großem Umfang im Einsatz haben vielfach in Standardkonfiguration mit XFS-Dateisystem , betrifft die Linux-Kernel-Schwachstelle ‘RefluXFS” (CVE-2026-64600) einen erheblichen Teil der hiesigen Linux-Serverlandschaft unmittelbar. Qualys Threat Research Unit (TRU) veröffentlicht Details Patchen und Neustart sind die einzigen verlässliche Gegenmaßnahmen. […] First seen…
-
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week’s trouble came dressed as something useful.A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert you…
-
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/russia-threat-actor-western-organizations-Zimbra-phishing/826029/
-
CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
The agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-fbi-iran-hackers-target-water-energy/826025/
-
‘State of Threat Management Report” von Filigran – Wenn Threat Intelligence ohne Wirkung bleibt
First seen on security-insider.de Jump to article: www.security-insider.de/ctem-exposure-gap-threat-intelligence-studie-deutschland-a-bdfe967a5f0ee03e15fac69fa6001ffc/
-
How attackers hosted a fake Claude download page on the claude.ai domain
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/
-
AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-agents-attack-surface/
-
Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse, where usernames and passwords exposed in unrelated third-party breaches are automatically tested against consumer platforms.…
-
Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation
Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Google’s AI Threat Defense offering. This launch comes as…
-
New TrickBot Malware Variant Uses DNS Tunneling for CommandControl
A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a…
-
Arista Networks enhances SD-WAN with AI-infused edge threat management
First seen on scworld.com Jump to article: www.scworld.com/brief/arista-networks-enhances-sd-wan-with-ai-infused-edge-threat-management
-
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
-
New Kimsuky campaign compromised South Korean software vendors
A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said. First seen on therecord.media Jump to article: therecord.media/kimsuky-north-korea-espionage-groupware-companies
-
Threat group claims credit for ransomware attack on Coca-Cola’s dairy unit
The attackers previously exploited vulnerabilities or used stolen credentials for initial access.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/
-
Bridewell Launches Dedicated Threat Intelligence Practice BCON Collective
Bridewell has launched BCON Collective, a dedicated Threat Research and Cyber Threat Intelligence (CTI) practice designed to help organisations better understand, prioritise and respond to today’s rapidly changing cyber threat landscape. The new practice brings together Bridewell’s existing intelligence-led services, original threat research and specialist analysts under a single identity, reflecting growing customer demand for…
-
Singapore to hold CII boards accountable as AI reshapes OT threat landscape
The Cyber Security Agency’s first update to its critical infrastructure code of practice since 2022 will make boards directly answerable for cyber resilience First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646154/Singapore-to-hold-CII-boards-accountable-as-AI-reshapes-OT-threat-landscape

