Tag: threat
-
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Tags: access, citrix, credentials, exploit, group, monitoring, ransomware, supply-chain, tactics, threat, vulnerabilityThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.”Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral First seen on thehackernews.com Jump to…
-
Catan and Mouse
What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/catan-and-mouse/
-
This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate
Dark Reading Confidential Episode 15: Interpol relied on Will Thomas and his team at Team Cymru to help break up a sprawling cybercrime ring, leading to the arrest of 574 suspects, the recovery of more than $3 million, and the decryption of six malware variants. Here’s his story. First seen on darkreading.com Jump to article:…
-
Safe Events Start With Threat Intel & Digital Security
Planning ahead to defend against cyber threats is the work that keeps events uneventful. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/safe-events-threat-intel-digital-security
-
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email correspondence via the Google API.”In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targeting access compromise via APIs,” Kaspersky said in a detailed report…
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted phishing campaign delivering the Ousaban banking Trojan to users in Spain and Portugal, notable for its use of geofenced webpages, layered evasion techniques, and a modular delivery chain. The threat actor repurposes a playbook seen previously in Brazil but has refined access controls and server-side checks to ensure malware reaches only the intended…
-
Japan revises AI strategy amid frontier AI threats
Just six months after releasing its national AI framework, Tokyo is updating its guidelines to address the weaponisation of frontier AI models capable of finding and exploiting unknown vulnerabilities First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645374/Japan-revises-AI-strategy-amid-frontier-AI-threats
-
ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth
A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. First named by Proofpoint in 2023, ValleyRAT continues to evolve: LevelBlue’s telemetry shows a marked increase in successful detections beginning May 2025 and accelerating into 2026. The threat now presents through two primary…
-
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Tags: ai, attack, credentials, exploit, jobs, network, ransomware, rce, remote-code-execution, threatSecurity firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a…
-
Filigran-Studie: Unternehmen kämpfen mit Lücke zwischen Threat Intelligence und operativer Umsetzung
Der ‘State of Threat Management Report” zeigt ein zentrales Problem: Viele Unternehmen kennen ihre Schwachstellen, können aber nicht schnell genug entscheiden sie zu schließen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/filigran-studie-unternehmen-kaempfen-mit-luecke-zwischen-threat-intelligence-und-operativer-umsetzung/a45648/
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
Healthcare Cybersecurity Threats Persist in 2026
SonicWall found healthcare remains the top cybersecurity target, with rising malware, ransomware, and medical IoT threats. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/healthcare-cybersecurity-threats-persist-in-2026/
-
MeetingTV Sues Palo Alto Networks Over Koi Threat Report
Tags: ai, china, cybercrime, cybersecurity, infrastructure, intelligence, malware, network, threat, toolMeetingTV Says Koi’s AI Analysis Tool Wrongly Tied it to Malware Infrastructure. MeetingTV alleges an AI-assisted threat intelligence report published by Koi Security falsely linked its infrastructure to a Chinese cybercrime operation, while Koi parent Palo Alto Networks argues the report reflects protected cybersecurity analysis rather than actionable false statements. First seen on govinfosecurity.com Jump…
-
Azure Password-Spraying Attack Bypasses MFA Defenses
Threat Actor Uses Deprecated OAuth 2.0 Authentication Flow. Attackers behind a password-spraying campaign targeting Microsoft Office 365 accounts have amassed dozens of victims by abusing a deprecated feature in OAuth 2.0 to generate access tokens, in some cases sidestepping multifactor authentication controls, warn researchers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/azure-password-spraying-attack-bypasses-mfa-defenses-a-32128
-
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT.Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites.These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others. First seen…
-
Critical flaw in Oracle E-Business Suite is under immediate threat
Researchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-flaw-oracle-e-business-suite-threat/824230/
-
Turning Indicators into Intelligence in OpenCTI with Criminal IP
Torrance, California, USA, July 1st, 2026, CyberNewswire Cyber threat intelligence becomes more valuable when indicators are enriched with context that supports investigation, correlation, and decision-making. Through the Criminal IP integration with OpenCTI, security teams can transform IP addresses, domains, and URLs from isolated indicators into structured intelligence within the OpenCTI knowledge graph. The integration automatically…
-
‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/phantom-squatting-ai-driven-supply-chain-threat
-
Attackers Seize Exposed AI Endpoints to Power Offensive Ops
Threat actors don’t need any special authentication to reach a target endpoint, they just need to know where it is. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops
-
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
A recently disclosed critical security flaw impacting Progress”¯Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire’s Threat Response Unit (TRU).The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-2026-8037 (CVSS score: 9.6), an operating system (OS) command injection flaw that could be exploited to achieve First seen on thehackernews.com Jump…
-
Turning Indicators into Intelligence in OpenCTI with Criminal IP
Threat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/turning-indicators-into-intelligence-in-opencti-with-criminal-ip/
-
84 Prozent der Angriffe treffen vermeidbare Schwachstellen
Filigran, das europäische Open-Source-Unternehmen für Bedrohungsmanagement, hat den Bericht ‘The State of Threat Management Report” veröffentlicht. Die weltweite Studie wurde unter 550 Entscheidungsträgern und Fachleuten im IT-Sicherheitsbereich und vom unabhängigen Marktforschungsunternehmen Vanson Bourne durchgeführt. Dabei deckt die Untersuchung eine auffällige Diskrepanz auf: Während sich das Continuous-Threat-Exposure-Management (CTEM) als Branchenstandard zunehmend durchsetzt, lässt die operative Reife…
-
Safe Events Start With Threat Intel and Digital Security
Planning ahead to defend against cyber threats is the work that keeps events uneventful. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/safe-events-threat-intel-digital-security
-
ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts
ToddyCat, an advanced persistent threat group long associated with targeted espionage against corporate environments, has evolved its toolkit to exploit OAuth-based authorization flows and compromise Gmail accounts without directly stealing credentials. Umbrij is deployed on Windows hosts using DLL sideloading: attackers place a malicious DLL alongside legitimately signed executables known to insecurely load libraries (examples…
-
Martin Lee: Running through the Arctic (and the threat landscape)
Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/martin-lee-running-through-the-arctic-and-the-threat-landscape/
-
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear”‘phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSignal entry from VMRay identified 194[.]156.79.122:55615 as a RedLine-associated host. That solitary indicator, combined with targeted forensic pivots across VirusTotal, FOFA, Censys…
-
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process.The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167).”Between June 12 and June 26, the threat First seen on thehackernews.com…
-
Allianzen Kartelle: So organisieren sich Ransomware-Gruppen heute
Neue Formen der Zusammenarbeit und zunehmende Professionalisierung setzen Unternehmen und Organisationen unter Druck. Die Zeiten opportunistischer Ransomware-Angriffe sind vorbei. Das zeigt der Threat Status Report 2025/2026 von aDvens, einem führenden, unabhängigen europäischen Unternehmen für Cybersicherheit. Angesichts wachsender Konkurrenz schließen sich Ransomware-Gruppen zusammen, teilen Ressourcen und bündeln operative Fähigkeiten. Dabei setzen die Gruppen auf zwei… First…

