Latest Analysis
Cybersecurity intelligence, threat analysis, and national security reporting.

Forg365 Phishing Service Targets Microsoft 365 with Advanced Device Code Theft
Meet Forg365, a sophisticated phishing service that's targeting Microsoft 365 users with advanced device code theft capabilities, offering a disturbingly user-friendly operator panel and a subscription-based model starting at just $400 a month. This illicit toolkit is being sold on Telegram, putting sensitive data at risk with its legitimate email delivery infrastructure and AI-powered email generation.

UK Charges Five in Crackdown on Russian Coms Spoofing Platform
In a major crackdown on cybercrime, five London residents have been charged in connection with Russian Coms, a notorious caller-ID spoofing platform that enabled scammers to swindle tens of millions from an estimated 170,000 victims since 2020. The accused allegedly helped fraudsters pose as trusted institutions to trick people into handing over cash and sensitive information.

Threat Actors Leverage AI-Generated Scripts to Accelerate Active Directory Attacks
Cyber attackers are now using AI-generated scripts to supercharge their Active Directory attacks, allowing them to quickly map and exploit sensitive domains, users, and computers. This alarming trend was uncovered by Huntress researchers, who analyzed a sophisticated PowerShell script that bore hallmarks of AI assistance.

Autonomous AI Transforms SOC with Analyst Copilots
Imagine sitting with a Fortune 50 CISO, witnessing a critical moment of clarity: "This is exactly what is wrong with how most security teams are designing their AI architecture right now." It turns out, current AI designs in the SOC are misguided, asking the wrong part of the decision process to do the wrong work.

Meta's AI Patent Tracks Emotions Through Voice, Biometrics
Meta just filed a patent for an AI system that can track emotions through voice and biometric data, potentially allowing for continuous emotional analysis throughout the day. This innovative technology could revolutionize the way we interact with devices, making it possible for them to respond to our emotional needs.

Cyber-attackers Exploit OAuth Client ID Spoofing in Cloud Environments
Cyber-attackers are increasingly using OAuth Client ID spoofing to infiltrate cloud environments, with multiple campaigns emerging, each with unique tools and infrastructure. This technique allows attackers to cleverly abuse Microsoft Entra ID by mimicking legitimate authentication requests.

Infostealer Infection Enables Argentine FA Breach
A single compromised computer with high-level access likely gave hackers the keys to the Argentine Football Association's database and internal email system, thanks to an infostealer infection that went undetected for months. The breach, traced back to September 8, 2025, highlights the devastating impact of a simple infection on a high-privilege machine.

Progress Software Probes External Threat to ShareFile Storage
Progress Software has alerted ShareFile customers to a credible external security threat targeting its Storage Zone Controllers, and is urging immediate action to protect sensitive data. The company has promised to provide an update within 24 hours and recommends that affected customers disable account access and shut down servers.

EU Targets Russian Hackers with Sanctions Over Europe Cyberattacks
The European Union is cracking down on Russian hackers, imposing sanctions on nine individuals and four entities linked to malicious cyber operations that threaten the continent's security and stability. This move targets those behind a foiled attack on Poland's critical infrastructure, which could have left 500,000 people in the dark during winter.

Australia, India Forge Deeper Security Ties to Counter Regional Threats
Australia and India are taking their defence partnership to the next level with a new Joint Declaration, aiming to boost interoperability and information sharing between their forces to tackle regional threats. This landmark deal marks a significant step towards closer coordination and consultation on defence matters between the two nations.

Germany, Ukraine Partner to Co-Produce BARS Missile-Drone
Ukraine and Germany have joined forces to co-produce the game-changing BARS missile-drone, a powerful jet-powered strike weapon that's proven its mettle in targeting deep into Russian territory, including Moscow. The historic deal, signed on the sidelines of the NATO summit, cements a major boost to Ukraine's defence capabilities.

Sen. Lindsey Graham's Sudden Death Leaves Senate Seat Vacant
Senator Lindsey Graham's sudden passing has left a void in the Senate, with his family seeking comfort in prayers and privacy during this difficult time. The longtime South Carolina senator died late Saturday after a brief illness, with emergency responders rushing to his home in Washington, D.C.

AI Companies Exploit Local Opposition to Data Centers
This year, US companies are pouring a staggering $750 billion into data center infrastructure, sparking a heated debate: are these centers a legitimate target for public resistance to AI, or just a convenient scapegoat for a more complex issue of wealth and power concentration?

Senator Lindsey Graham's Legacy Shapes US Foreign Policy
Senator Lindsey Graham left a lasting mark on US foreign policy, dedicating his life to championing American leadership and freedom worldwide, with a legacy that spanned over 30 years of military service and unwavering advocacy for nations like Ukraine, China, and Iran. His final journey to Ukraine, his 10th trip since Russia's 2022 invasion, was a testament to his tireless commitment to shaping global policies.

Pakistan Eyes New Army Aviation Assets to Bolster Counterinsurgency Push
Pakistan is gearing up to supercharge its counterinsurgency efforts with fresh army aviation assets, as part of a massive and ongoing operation in Balochistan. The move marks a major revival of the Pakistan Army Aviation Corps' large-scale operations after a decade-long hiatus.

Marines Seek Cloudless Networks to Bolster AI Tools in Combat
Imagine a battlefield where phones, radios, and drones can seamlessly share data with each other, even when traditional cloud connections go dark - that's the vision behind Ditto's peer-to-peer mesh technology. By transforming existing devices into a network of connected nodes, Ditto's software-first approach ensures that critical communication stays alive, no matter what.

AI-Generated Code Exposes Governance Gaps in Security Debt
AI-generated code is being produced at alarming rates, but with a catch: nearly half of it contains security flaws, highlighting a pressing need for new approaches to managing security debt. As software creation accelerates, companies must adapt their security strategies to keep pace with the rapid accumulation of vulnerabilities.

Progress Disrupts ShareFile Servers Over External Security Threat
If you're a ShareFile customer, take immediate action: shut down your Storage Zone Controller servers now to protect against a critical external security threat. Progress Software has already disabled access to affected accounts, but manual shutdown is crucial for safeguarding your data.

Russian Hackers Target Routers Globally, Warn Cybersecurity Agencies
A brazen plot by Russian hackers to disrupt global networks was thwarted, but not before cybersecurity agencies warned of a potentially catastrophic attack that could have left 500,000 citizens shivering in the dark. The hackers, linked to Russia's Federal Security Service, targeted vulnerable routers worldwide using simple and easily exploitable passwords.

Ryuk Ransomware Operative Pleads Guilty in US Court
A major player behind the notorious Ryuk Ransomware gang has taken responsibility for their crimes, with Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleading guilty in a US court to conspiracy and computer fraud. As part of his plea deal, Vardanyan will pay over $1.1m in restitution for his role in the massive cyberattack that netted over $15m in bitcoin payments.

Russian Hackers Target Critical Infrastructure via Router Exploits
Russian state-backed hackers have infected 18,000 routers in 120 countries, sparking a multinational warning about the threat to critical infrastructure networks. The alarming campaign is linked to Russia's Federal Security Service (FSB) Centre 16, notorious for exploiting poorly configured routers to gain access to sensitive networks.

Evilginx Phishing Ops Expose Microsoft 365 MFA Weaknesses
A French security firm stumbled upon a live Microsoft 365 phishing operation when a simple Python command was left exposed in a readable file, revealing a treasure trove of sensitive data. This lucky discovery shed light on the alarming weaknesses in Microsoft 365's multi-factor authentication.

Joomla Flaws Exploited as Zero-Days in Active Attacks
A critical vulnerability in the iCagenda extension for Joomla, known as CVE-2026-48939, has been exploited as a zero-day since June 15, 2026, allowing attackers to upload arbitrary files via the component's file attachment feature. This severe flaw, scoring 10.0 on the CVSS scale, has already sparked a wave of automated attacks against popular content-management-system extensions.

24B Credential Exposure Sparks Urgent Calls for Identity Security Overhaul
A massive 24 billion credentials have been exposed in a staggering 8 terabytes of stolen data, sparking urgent calls for a complete identity security overhaul. This alarming breach wasn't just a one-time hack, but a sneakily silent threat from infostealer malware quietly harvesting sensitive info from infected devices.