In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
A phishing email masquerading as a Bank of America message has been identified, targeting users to install ScreenConnect malware. The email, received by Huntress on July 28, prompts recipients to visit a fake website…
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
Telegram's t.me short-link domain was temporarily blocked after the .me registry placed it under serverHold, affecting access to links for profiles, channels, and bots. This action is linked to US Treasury sanctions…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
The ATT&CK framework has released version 19, which includes significant updates to its structure and coverage. Notably, the Defense Evasion Tactic has been split into two distinct categories: Stealth and Defense…