Tag: threat
-
Torq and Criminal IP Partner to Deliver Decision-Ready Threat Intelligence for Autonomous SOC Operations
Torrance, California, USA, 13th July 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/torq-and-criminal-ip-partner-to-deliver-decision-ready-threat-intelligence-for-autonomous-soc-operations/
-
Progress Urges ShareFile Shutdown Over ‘Credible’ Threat
Honeypot Records Exploitation Attempt Against Flaw Patched Earlier This Year. Progress Software has issued a security alert to all organizations using self-managed instances of ShareFile Storage Zone Controller, advising them to immediately power down their servers in light of a credible external security threat to their data. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210
-
13th July Threat Intelligence Report
U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/13th-july-threat-intelligence-report/
-
Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
A >>credible external security threat<< targeting Progress Software's ShareFile Storage Zone Controllers (SZC) the on-premises, customer-managed server … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/progress-sharefile-security-threat/
-
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.”The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of…
-
Progress Software Warns of External Security Threat to ShareFile
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/progress-warns-security-threat/
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across Russia, Brazil, and Kazakhstan with a new Python-based infostealer named BusySnake. The group’s activity reflects an unusual overlap between cyber-espionage and financially motivated operations. Armored Likho targets organizations for intelligence collection…
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
Progress Software warns ShareFile users of external security threat
First seen on scworld.com Jump to article: www.scworld.com/brief/progress-software-warns-sharefile-users-of-external-security-threat
-
Vibe-Coded Malware Caught in Active Directory Attack
Huntress found a threat actor using vibe-coded PowerShell to map an Active Directory network First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/
-
Advens Threat Status Report 2025/2026 – So organisieren sich Ransomware-Gruppen
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-gruppen-allianzen-advens-report-2025-2026-a-87658a8cd400e3b7102f7f489fedf60d/
-
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy.According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It’s assessed to…
-
Nike Alleged Breach: Threat Actors Claim Leak of Millions of Customer Records
A threat actor on a prominent cybercrime forum has claimed responsibility for leaking data allegedly belonging to Nike and Alcon, posting the purported datasets for download. The claims, currently unverified, suggest a significant breach affecting millions of records across both organizations. Nike Alleged Breach According to the forum post, the threat actor alleges the Nike-related…
-
Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
Fake apps like WireVPN and a trojanized 7-Zip turn victims’ devices into residential proxies, letting criminals route traffic through their IPs. Infoblox’s threat research team started pulling on a single thread in early 2026: a fake version of the 7-Zip archive utility hosted at 7zip[.]com instead of the real site, 7-zip[.]org. The researchers uncovered a…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
ESET Threat Report H1 2026: Cyberkriminelle machen bekannte Angriffe effizienter
Cyberkriminelle erfinden Angriffe nicht neu, sie machen sie effizienter. Der aktuelle ESET-Bedrohungsbericht zeigt, wie KI, QR-Code-Betrug und Angriffe auf Schutzsoftware die Bedrohungslage verändern. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/eset-research/eset-threat-report-h1-2026-cyberkriminelle-machen-bekannte-angriffe-effizienter/
-
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved…
-
A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Accenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle >>888<>Today […] First seen on securityaffairs.com Jump to article: securityaffairs.com/194962/data-breach/a-hacker-claims-35-gb-of-accenture-source-code-the-company-discloses-the-data-breach.html
-
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers/
-
Entra passkey enrollment vishing targets Microsoft 365 users
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
-
Accenture faces massive data breach that could put clients at risk
The threat actor claiming responsibility says it stole source code, encryption keys and more. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/accenture-data-breach-access-keys-source-code/824694/
-
Sophisticated threat campaign pushes Cisco to the very edge
A monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/sophisticated-threat-campaign-pushes-cisco-to-the-very-edge/824569/
-
Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools
RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family. It comes with documentation, tutorial videos, a referral…
-
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
Sygnia report details how agentic AI accelerated weeks-long attack to just 72 hours First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/threat-actor-agentic-ai-cloud/
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
-
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
Cyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-campaign-vidar-stealer-monero/
-
European Central Bank demands AI security ‘action plan’
European Central Bank gives banks deadline to outline their plans to defend against artificial intelligence-based security threats First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645712/European-Central-Bank-demands-AI-security-action-plan

