On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
Cybernews researchers uncovered an exposed Elasticsearch database containing 24 billion records, including usernames, email addresses, and plaintext passwords. The data is primarily sourced from infostealer malware logs…
The SnappyClient malware implant, first identified in December 2025, poses a significant threat to Windows users, particularly targeting cryptocurrency wallets. This C++-based command-and-control (C2) implant enables…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
Cybercriminals are exploiting a new attack vector called 'phantom squatting,' where large language models (LLMs) generate plausible but nonexistent domains for legitimate brands. These hallucinated domains are then…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
A spear-phishing campaign has been identified targeting the South Korean maritime industry, utilizing RedLine Stealer command-and-control (C2) infrastructure. The campaign was uncovered through a VMRay UniqueSignal feed…
Cybercriminals created a fake remote management vendor that sells a remote access trojan (RAT) disguised as legitimate enterprise software for $300 a month. This scheme exploits the growing trend of using remote…