A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Malware developers have successfully bypassed Google's App-Bound Encryption (ABE) in Chrome, allowing infostealers like VoidStealer to access sensitive data such as session cookies and credentials. This new method…
In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
Recent reports reveal that session hijacking techniques are compromising accounts even with two-factor authentication (2FA) enabled. Attackers exploit session cookies, which are stored in browsers post-login, to gain…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
ESET Research participated in Operation Endgame, a coordinated effort to disrupt the Amadey botnet and Stealc infostealer. This operation involved multiple organizations, including Microsoft and Europol, targeting the…