Tag: threat
-
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.”The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics,”…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
UK’s small power plants face higher cyber risk into 2030s despite Iran-linked hack
Decision not to improve resilience sooner described as ‘unacceptable gamble with our national security’Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which is understood to have shut…
-
UK’s small power plants face continued cyber risk after Iran-linked hack
Government measures to improve resilience are not due until 2030 and July’s hack has not altered this timeline<br><br> Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which…
-
US lawmakers question CISA workforce cuts amid rising cyber threats
First seen on scworld.com Jump to article: www.scworld.com/brief/us-lawmakers-question-cisa-workforce-cuts-amid-rising-cyber-threats
-
CrowdStrike Flex Model Adapts Deals to Evolving AI Threats
Enterprises Want Visibility Into What AI Agents Access, Spend and Execute. CrowdStrike added a record $333 million in annual recurring revenue as enterprises expanded Falcon Flex to secure AI agents, control non-human identities and track AI spending while consolidating legacy security tools. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/crowdstrike-flex-model-adapts-deals-to-evolving-ai-threats-a-32665
-
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. First seen on cyberscoop.com Jump to article: cyberscoop.com/energy-department-cybersecurity-executive-order-rules/
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (å—京鑫玖维网络科技有é™å…¬å¸).&…
-
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/
-
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead.…
-
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have legitimate uses on Windows systems, making malicious activity harder to distinguish from normal software behavior. According to Cybersecurity News, Iran-linked operators are abusing the legitimate Deno JavaScript…
-
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/
-
The Problem with Hard Coded Cryptography in Modern Applications
Hard-coded cryptography creates long-term security debt. Crypto agility makes algorithms, keys and cryptographic dependencies easier to replace as standards, threats and post-quantum requirements evolve. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-problem-with-hard-coded-cryptography-in-modern-applications/
-
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to render a fake CAPTCHA page and redirect visitors to attacker-controlled infrastructure. The campaign does…
-
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The…
-
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.”The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks such as the Black Axe and other similar groups,”…
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures…
-
Hackers Hide Malware Inside Plain English Words to Infect Windows Users With Amatera Stealer
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The loader disguises executable shellcode as sequences of ordinary English words, helping malware evade static inspection before reconstructing and launching the final payload in memory. Microsoft previously observed ACR Stealer operators using fake verification prompts,…
-
AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/
-
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/
-
Car Infotainment Malware Builds Criminal Proxy Botnet
DoFun Software Updates Exploited to Infect Android Head Units. Attackers are exploiting legitimate software updates to infect Android-based car infotainment systems, or head units, turning them into reverse proxies. Kaspersky linked the malware campaign to the MoYu Group, a threat actor linked to BADBOX and BADBOX 2.0. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/car-infotainment-malware-builds-criminal-proxy-botnet-a-32652
-
Democratic Lawmakers Call for GAO Investigation of CISA Workforce Cuts
A group of Congressional Democrats are asking the GAO to investigate whether the deep cuts to CISA’s workforce under the Trump Administration has hobbled the agency’s abilities at a time when cyber threats against federal networks and critical infrastructure by nation-state actors are growing. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/democratic-lawmakers-call-for-gao-investigation-of-cisa-workforce-cuts/
-
BSidesCharm 2026 Modernize, Vectorize, And Visualize CyberOps Data, Threat Intel With Qdrant
Presenters: Kevin Figueroa & Dickson Kwong Our thanks to BSidesCharm for publishing their Creators, Authors and Presenter’s outstanding BSidesCharm 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidescharm-2026-modernize-vectorize-and-visualize-cyberops-data-threat-intel-with-qdrant/
-
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/
-
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.”While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to…
-
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the…
-
The Key to Resilience in the Age of AI-Driven Attacks: A Leading Analyst’s Take
As you can imagine, concerns about AI-driven threats have come up often in our recent discussions with our clients here at ColorTokens. And for good reason. AI has revolutionized the threat landscape. It can quickly reverse-engineer services, processes, and applications, discover multiple vulnerabilities faster than human attackers ever could, and use automation to chain 30,……

