
Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
PhantomRaven quietly slipped into the npm registry, turning routine installs into token theft by harvesting credentials during install and letting attackers publish malicious updates without touching your code. One stolen token can cascade through thousands of projects—here’s why supply‑chain hygiene and MFA matter now.

What happens when the person entrusted to build the locks quietly sells the keys? An indictment alleges a former Trenchant manager sold zero‑day exploits and offensive cyber tools to a Russian broker for about $1.3 million, potentially turning U.S. capabilities into weapons against American systems and allies.

Think your npm packages are safe? Recent attacks that slipped malicious code into 126 npm packages — roughly 86,000 downloads — show how invisible dependency changes can cascade into thousands of projects, so token hygiene, 2FA and publish provenance matter more than ever.

Meet GhostCall — a stealthy campaign tied to BlueNoroff that weaponizes low‑profile backdoors and traffic‑manipulation to quietly harvest credentials and hijack Web3 sessions. As blockchain projects scale, GhostCall and its sibling GhostHire show how openness can be turned into an espionage-and-theft platform that technologists, policy makers and users can’t afford to ignore.

Qilin ransomware is surging — over 40 incidents monthly — using double‑extortion leak sites that weaponize stolen files into lasting reputational damage. Is your organization prepared to respond beyond just restoring backups?

MuddyWater turned one trusted inbox and a rented VPN into a battering ram against more than 100 government networks—proving social engineering beats flashy malware every time. Group‑IB’s forensic breakdown shows how stealthy credential theft and patient lateral movement bought months of access to critical diplomatic and government secrets.

The MuddyWater campaign turned a single compromised mailbox and an attacker-controlled VPN into a battering ram, phishing its way into 100+ government networks across the Middle East and North Africa and proving that access and trust beat flashy exploits every time.

Google removed roughly 3,000 malicious YouTube videos, dismantling a “ghost network” that lured users into downloading password‑stealing malware disguised as cheats and cracked software. It’s a practical win for online safety—fewer traps and fewer stolen credentials.

Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Google just wiped about 3,000 seemingly harmless YouTube tutorials after researchers exposed the “Ghost Network” that used those clips to spread password-stealing malware. If a video pushes cracked software or cheats, pause and double-check the source—your passwords and payment info are worth the extra caution.

Think that handy YouTube tutorial is safe? Ghost Network hid password‑stealing malware inside thousands of fake how‑tos and cracked‑software walkthroughs — Google pulled roughly 3,000 videos after researchers traced the campaign funneling victims to trojanized installers.

Google just nuked 3,000 malware YouTube videos that used believable tutorials and “cracked” installers to sneak in a credential‑stealing payload—learn the red flags so curiosity doesn’t cost you your accounts.

LockBit’s latest iteration is back—and meaner: researchers found a cross-platform strain in September that can encrypt Windows, Linux and VMware ESXi in a single strike, shrinking defenders’ response window and multiplying damage. If you haven’t expanded EDR to Linux and hypervisors or tested immutable backups yet, now’s the time.

LockBit keeps changing its playbook—September telemetry uncovered roughly a dozen incidents, about half tied to a new strain that can hit Windows, Linux and hypervisors. That cross‑platform reach broadens the blast radius from a single breach and forces defenders to rethink old assumptions.

Exclusive: Threat actors are unleashing a dangerous surge in app exploits—here’s what’s driving the spike and quick, practical steps to keep your apps and users safe.

An updated LockBit variant—faster, stealthier and able to run native payloads on Windows, Linux and VMware ESXi—has been tied to a dozen recent intrusions, dramatically shrinking the window defenders have to detect and stop catastrophic outages.

A Pakistani-linked hacker group reportedly pulled off a severe, exclusive cyberattack on India — here’s who’s behind it and why the fallout matters for national and regional security.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
A Pakistan-linked group called TransparentTribe quietly deployed the DeskRAT trojan to infiltrate Indian government networks, harvesting credentials and sensitive documents over months. The patient, espionage-focused campaign raises urgent questions about when cyber intrusions become acts of war.

Europe’s drone industry is being stalked by North Korea’s Lazarus Group, which used fake recruitment DreamJob lures to slip malware into engineers’ inboxes and siphon designs, test data and R&D secrets. The campaign shows how porous modern research networks are—and how cyber espionage can become a direct, strategic threat to EU defence and supply‑chain security.

When stolen‑credential marketplaces start to look like legit app stores, everyone loses—Lumma Stealer’s resurgence and the reborn Vidar 2.0 (Vidar 20) are fueling a sustained, hard‑to‑detect threat through Q4 2025. Read our exclusive to learn the practical steps defenders and everyday users need now: validate IOCs, tighten MFA, and sharpen telemetry.

The Lumma Stealer leak has supercharged Vidar 2.0, recycling stolen credentials and exposed code into a stealthier, cheaper toolkit for criminals. Trend Micro warns defenders to brace for rising Vidar 2.0 activity through Q4 2025.

A marketplace leak proves Vidar 2.0 (Vidar 20) is evolving into a commercially sold, regularly updated threat—Trend Micro warns it will surge through Q4 2025, so defenders must choose urgent action over complacency.

From the public doxxing of Lumma Stealer to the resurfacing of Vidar 2.0, the cybercrime scene is behaving more like a ruthless software market — and that escalation puts millions of credentials and finances at risk. Security teams take note: analysts expect a rise in sophisticated stealer activity through Q4 2025.

Imagine lights going out at your hospital or your commute being held hostage — and the alleged architects are teenagers. The newly unsealed indictment accuses Scattered Spider of using social engineering and telecom hacks to extract at least $115M in ransoms, turning account takeovers into real‑world chaos.

The ShinyHunters campaign has escalated from quiet database dumps to brazen public extortion—naming victims, posting timetables, and using voice‑phishing plus massive file thefts that could turn single breaches into a supply‑chain crisis. Corporations now face a stark choice: pay ransoms or risk a public dump of sensitive customer and corporate data.