2025-10-28 17:01 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks o…
P0
2025-10-22 07:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent Threat (APT) MuddyWater. The attack used a compromised mailbox to distribute Phoenix backdoor malware to international organizations and across the whole Middle East and North Africa region, targeting more than 100 government entities.
P0
2025-10-15 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Beginning in mid-2025, Huntress discovered a new tool being used to facilitate webserver intrusions known as Nezha, which up until now hasn’t been publicly reported on. This was used in tandem with other families of malware and web shell management tools such as Ghost RAT and AntSword.
P0
2025-09-25 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Trace a threat actor's journey from custom Python stealers to a sophisticated commodity RAT. Learn how their tactics evolved and why this shift to .NET matters.
P0
2025-09-17 07:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The blog provides an in-depth look at MuddyWater’s evolution in tooling, targeting, and infrastructure management, suggesting a more mature and capable advanced persistent threat within the META region.
P0
2025-08-29 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how a fake AnyDesk installer led to a unique MetaStealer attack, highlighting how threat actors evolve ClickFix techniques beyond the classic playbook to steal credentials and files.
P0
2025-08-25 09:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The most widely used email security tools still focus on yesterday’s threats. Meanwhile, attackers have moved on. By hijacking legitimate business relationships and embedding infostealers in familiar-sounding, well-written emails, cybercriminals bypass conventional defenses. The only way to keep up is by using a behavioral approach.
P0
2025-07-30 07:46 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Deep dive into UNC2891’s multi‑stage bank intrusion: Raspberry Pi ATM implant, bind mount evasion, Dynamic DNS C2, and a CAKETAP move toward HSM manipulation.
P0
2025-07-21 21:34 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…
P0
2025-07-08 17:36 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most s…
P0
2025-07-02 08:08 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discovered by Group-IB in mid-2024, the Qwizzserial, which was initially not very active, began to spread strongly in Uzbekistan, masquerading as legitimate applications. The malware steals banking information and intercepts 2FA sms, transmitting it to fraudsters via Telegram bots.
P0
2025-06-18 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
P0
2025-06-13 16:03 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…
P0
2025-06-03 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cybercriminals are sitting on a pile of stolen credentials, financial information, and sensitive data, thanks to the success of infostealers. Read more to learn how infostealers have grown to become a scourge to defenders, and how businesses can protect themselves.
P0
2025-04-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Protect your business from malware attacks by fostering a security-first culture. Learn how to defend against cyber threats, establish strategies, and train employees to spot malware before it strikes.
P0
2025-04-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
P0
2025-04-04 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
P15
2025-03-28 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.
P0
2025-03-24 12:47 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how hypothesis-driven threat hunting uncovered stealthy malware. Learn why having a dedicated in-house team or leveraging expert threat hunting services is crucial for modern cybersecurity.
P0
2025-03-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When Celestial Stealer runs in the wild, it looks for Huntress’ own Jai Minton as a potential threat, and this shuts down the infostealer operation if his name is detected.
P20
2025-03-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Stopping malware isn’t about catching one-off alerts. It’s about finding and shutting down the persistence that keeps them in your systems. Here’s how Huntress found, fought, and drop-kicked malware that others missed.
P0
2025-02-06 06:38 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover 5 ways to leverage Malware Reports for daily analysis and improve detection. Perfect for SOC analysts, threat hunters, and reverse engineers.
P0
2024-12-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers identified vulnerabilities in the Azure Data Factory's integration with Apache Airflow. These vulnerabilities include misconfigured Kubernetes Role-Based Access Control (RBAC), improper secret handling in Azure’s internal Geneva service, and weak authentication mechanisms. Exploiting these flaws, attackers could gain shadow admin control over Azure infrastructure by crafting malicious DAG files or compromising service principals, leading to unauthorized access, data exfiltra…
P0
2024-12-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Team Huntress has analyzed Cleo's software vulnerability CVE-2024-55956. Take a look at the technical breakdown of a new family of malware we’ve named Malichus.
P5
2024-11-21 09:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.
P0
2024-11-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the highlights of Huntress Capture the Flag 2024, where teams cracked complex cyber challenges in a month-long journey of reverse engineering and malware analysis.
P0
2024-10-29 08:25 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Stop fraud, RATs, and malware with Group-IB's Fraud Protection AI. Our advanced behavioral analysis uses AI to detect and prevent threats in real-time, safeguarding your business and users.
P0
2024-09-25 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this blog, we look at the DragonForce ransomware group, which poses a severe threat with two variants—a LockBit fork and a customized Conti fork with advanced features and SystemBC malware.
P15
2024-09-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.
P15
2024-09-12 04:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discovered by Group-IB in May 2024, the Ajina.Banker malware is a major cyber threat in the Central Asia region, disguising itself as legitimate apps to steal banking information and intercept 2FA messages.
P0