On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
A data breach at Nova Scotia Power, discovered on April 25, 2025, compromised sensitive information of over 900,000 customers. The breach initiated when an employee clicked on a malicious pop-up linked to 'SocGholish'…
The Five Eyes cybersecurity agencies issued a call-to-action regarding the growing threat posed by AI in cyber attacks. They emphasize that AI is lowering barriers for malicious actors and accelerating the exploitation…
Recent reports reveal that session hijacking techniques are compromising accounts even with two-factor authentication (2FA) enabled. Attackers exploit session cookies, which are stored in browsers post-login, to gain…
A malicious campaign named CrashFix has been identified, utilizing a fake ad-blocking browser extension called NexShield to crash users' browsers. This tactic is employed to facilitate ClickFix attacks, delivering a new…
Cybersecurity researchers at Arctic Wolf Labs have identified a cyberattack campaign utilizing fake browser update notifications to distribute SocGholish malware. This campaign is linked to Russian threat actors and…
A series of cyberattacks targeting a US engineering firm has been attributed to Russian cyber groups. The attackers utilized SocGholish and RomCom tools, which are commonly associated with cybercrime, to obscure their…
A U.S.-based civil engineering firm was attacked by the Russia-aligned threat group RomCom, which utilized SocGholish malware in a September attack. The attack is believed to be connected to the firm's work for a U.S.…
Recent guidance has been issued to mitigate risks associated with bulletproof hosting providers, which are often used by cybercriminals to host malicious content. This guidance comes from cybersecurity authorities,…