2026-05-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform,…
P55
2026-05-11 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Device code phishing doesn't need stolen passwords or malware—just a legitimate auth flow. Learn how EvilTokens weaponized AI to run this attack across 344 organizations.
P0
2026-05-11 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a so…
P60
2026-05-05 08:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
P0
2026-04-30 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Your background is gone, but malware is here. Huntress breaks down BackgroundFix, a new ClickFix social engineering tactic involving CastleLoader, NetSupport RAT, and CastleStealer. Read the analysis.
P0
2026-04-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress found threat actors using the Komari monitoring agent as a SYSTEM-level backdoor. Learn how they abused GitHub and what defenders should hunt for.
P0
2026-04-27 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how Huntress EDR/ITDR Correlations stop infostealer-driven attacks before stolen credentials can be reused, linking endpoint compromise to cloud identities for one coordinated response.
P0
2026-04-23 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…
P0
2026-04-23 08:59 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
P0
2026-04-21 08:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI
P0
2026-04-14 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress uncovered a malware operation using signed PUP to deploy AV killers with SYSTEM privileges. Learn how this adware crosses the line into malware territory and how anyone could have hijacked their update mechanism.
P0
2026-04-09 17:07 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft t…
P0
2026-03-31 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB shows how Business Email Protection blocked Phantom Stealer phishing emails across different campaign waves.
P0
2026-03-18 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress’ AI-Centric SOC recently stopped a MacSync infostealer attack on a macOS device. The malware attempted to scrape credentials, browser cookies, and crypto wallets, but Huntress contained the threat before any data was sent to the attacker. Learn how we did it.
P0
2026-03-04 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress warns of fake OpenClaw installers on GitHub deploying malware. Learn how these attacks happen, identify signs of infection, and stay protected.
P0
2026-02-20 10:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
MuddyWater APT has launched a new cyber offensive operation, dubbed Operation Olalampo, deploying new malware variants and leveraging Telegram bots for command-and-control. Analysis of the campaign provides a glimpse into the group’s post-exploitation tactics, which largely align with their historical operations.
P0
2026-02-19 17:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that trust, we’re focused on ensuring that apps do not cause real-world harm, such as malware, financial fraud, hidden subscriptions, and privacy invasions. As bad actors leverage AI to change their tactics and launch increasingly sophisticated attacks, we’ve deepened our investments…
P0
2026-02-19 10:30 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow
P0
2026-02-19 10:29 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
It’s tax season in Indonesia and fraudsters are observed to be ramping up the fraud campaign involving fake Coretax apps, but behind it lies an industrialized MaaS infrastructure ready to strike anywhere.
P0
2026-01-23 16:58 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper
P0
2026-01-07 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers detail the inner workings of Chinese tap-to-pay schemes on Telegram and examine the NFC-enabled Android apps fraudsters are using to steal money from victim’s bank cards and mobile wallets remotely.
P0
2025-12-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Think all threat actors are pros? This post reveals how 'unsophisticated' malware and attacker errors help defenders stop attacks before damage is done.
P0
2025-12-19 07:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analyzes the evolution of Android malware in Uzbekistan, revealing advanced droppers, encrypted payload delivery, anti-analysis techniques, and Wonderland’s bidirectional SMS-stealing capabilities driving large-scale financial fraud.
P0
2025-12-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is seeing threat actors exploit React2Shell (CVE-2025-55182) to deploy a Linux backdoor, a reverse proxy tunnel, and a Go-based post-exploitation implant.
P5
2025-12-09 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Attackers are exploiting user trust in AI and aggressive SEO to deliver an evolved Atomic macOS Stealer. Learn why this social engineering tradecraft bypasses traditional network controls and the future of macOS infostealer defense.
P0
2025-12-03 06:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A deep dive into GoldFactory’s evolving mobile fraud campaigns across APAC, including modified banking apps, new malware variants such as Gigaflower, shared criminal infrastructure, and insights from the Group-IB Fraud Matrix, with recommendations for organizations and end users.
P0
2025-12-02 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook
P0
2025-11-28 13:46 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month's cybersecurity news
P15
2025-11-25 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.
P0
2025-11-24 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress uncovered an attack utilizing a ClickFix lure to initiate a multi-stage malware execution chain. This analysis reveals how threat actors use steganography to conceal infostealers like LummaC2 and Rhadamanthys within seemingly harmless PNGs.
P0