
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Cronos is back online after a swift restart, restoring its chain state to before the $74 million Tectonic exploit and resuming block production from block 90,896,189. The network had temporarily halted activity to protect users from a rapid price-manipulation attack on a major DeFi lending protocol.

Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

North Korean workers are pulling off a clever scam, tricking companies into hiring them remotely and often doing legitimate work, all while hiding their true identities. Huntress has uncovered alarming cases of this employment fraud expanding into healthcare, sales, marketing, and medical fields.

Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Big news for ChatGPT Work users: OpenAI is currently working to resolve an outage that's leaving many unable to start or continue tasks across multiple subscription plans, including ChatGPT Work and Plus. The company is racing to find a fix and get things back up and running smoothly.

Microsoft is investigating an outage that's disrupting email delivery and sign-in across Exchange Online, citing a common failure pattern linked to authentication and protocol connectivity issues. The company is actively troubleshooting and working to resolve the problem, which was first acknowledged at 5:30 PM UTC.

The ATF's response to the Qilin ransomware gang's claim of a breach reveals how prepared - or unprepared - the agency was to tackle the incident. A cyber breach at the ATF potentially puts sensitive investigative targets at risk, but details on the incident remain scarce.

Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
A single compromised employee account led to a massive data breach at Hasbro, exposing sensitive employee information, including Social Security numbers and financial data. The alarming incident highlights the importance of robust cybersecurity measures to prevent such breaches.

Chinese hackers have cleverly exploited Cisco routers, transforming them from mere transit devices to covert surveillance platforms, as discovered by incident responders at Sygnia. This sinister manipulation allows hackers to secretly collect data, with one of the first clues being an unexplained GRE tunnel interface on a Cisco IOS XR router.

The FBI has struck a major blow against Chinese cyber espionage, disrupting a proxy network used to sell reconnaissance and operational routing capabilities to malicious actors. This key takedown targeted a technical quartermaster tied to Nanjing Xinjiuwei Network Technology Company, a company linked to the notorious QTYF spy-proxy network.

PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

Berlin's administrative network has been hit by a massive Rhysida ransomware attack, with hackers claiming to have stolen a whopping 5.79 TB of sensitive data, including 1.44 million files, and are now threatening to publish it unless paid a ransom. The breach exposes a vast array of confidential records, from government and financial data to personal info like names, email addresses, and phone numbers.

Aurora ransomware operators are using AI tool Cursor to plan and execute targeted attacks, even going so far as to instruct it in Russian to exclude certain regions and domains. This sophisticated approach has enabled the group to breach over 20 organizations across nine countries in just a few months.

Meet Silver Fox, a sneaky threat actor that's been using adware to disguise a powerful backdoor called ValleyRAT, which can give attackers full control over your computer. They've even hijacked a legitimate Chinese desktop wallpaper tool to spread their malicious software.

Meet ValleyRAT, a sneaky backdoor that's been evading detection with the help of adware, infecting over 1500 users in China and India with a staggering 100,000 detections in 2026 alone. Its clever disguise was uncovered when researchers dug deeper into a suspicious installer initially labeled as ordinary adware.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

When hackers take control of routers like Cisco's IOS XR, they don't just gain access - they gain a bird's-eye view of the entire network, allowing them to harvest sensitive credentials and fly under the radar. The notorious Fire Ant group recently exploited these routers to turn them into intelligence collection platforms, putting countless networks at risk.

The FBI and DOJ have brought two Nigerian men, Adebola Festus Adekunle and Mudasiru Afeez Olawale, back to the US to face charges for their roles in a sextortion scheme that tragically led to the deaths of two young victims. This case is a stark reminder that sextortion is a heinous crime that the FBI is committed to stopping, no matter where the perpetrators hide.

The US Department of Justice made a telling edit to their recent press release, quietly changing the wording from "victims" to "among the targets" of a China-linked hacking group that hit several high-profile US agencies. This subtle shift highlights the scope of a brazen cyber espionage operation that compromised sensitive government networks.

Manchester Airports Group swiftly sprang into action after a hack, reassuring customers that they've taken robust measures to safeguard their info and reaching out to those affected, including those with upcoming bookings, to offer extra support. Meanwhile, hackers FulcrumSec claimed responsibility, boasting of swiping 86 GB of sensitive data.

Beware of infostealer malware that's hijacking Claude sessions! Anthropic is taking swift action to protect users, including signing them out of compromised accounts, removing saved payment methods, and offering refunds for unauthorized charges.

Malicious Chrome extensions have been caught stealing cryptocurrency and browser data, with a recent investigation uncovering a sophisticated malware campaign that may have been active since early 2024. The attack used 16 distinct modules to deliver a modular malware framework to unsuspecting Chrome and Edge users.

Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.