
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
What if the ads you trust were actually a backdoor? A new malvertising campaign is quietly using compromised ad networks to deploy PS1Bot — a modular PowerShell malware that runs in memory, evades traditional defenses, and can turn ordinary browsers into footholds for wider attacks.

The DOJ just dealt a major blow to BlackSuit by seizing domains, servers and roughly $1M — a tactical win that disrupts a ransomware ring preying on hospitals, schools and small businesses while reminding us takedowns help but don’t replace strong prevention and backups.

A new ransomware called Charon is using APT-style stealth—DLL side‑loading and process injection—to strike Middle East public-sector and aviation systems, forcing a rethink of how we protect critical services. Assume attackers are getting smarter: prioritize EDR, MFA, network segmentation and practiced response plans to keep cities and flights safe.

Was the July 2021 Kaseya REvil attack just criminal profit-seeking or something far more dangerous—potentially state-enabled? New evidence presented at DEF CON 33 suggests probable Russian government involvement, a claim that would radically change how governments, businesses, and MSPs respond to future supply-chain cyberattacks.

MITRE’s take on APT28’s LameHug at Black Hat is a wake-up call: while crude now, this testbed shows how AI and automation could quickly turn basic tools into powerful cyber weapons. Defenders, policymakers, and everyday users should sharpen defenses and share intel now—before experiments like this graduate into routine attacks.

TRM Labs revealed the Embargo ransomware gang has siphoned $34.2 million from victims—a stark reminder that our connected world can be exploited for huge profit. It’s time businesses, regulators, and users to boost defenses and work together to stop these crypto-enabled crimes.

In Brazil, a wave of high-tech phishing scams is exploiting AI to swindle unsuspecting victims out of millions in cryptocurrency. As cybercriminals craft near-perfect replicas of government websites, the importance of staying informed and vigilant has never been greater.

Beware: the very tools that simplify our digital lives might be hiding a sinister side! With the discovery of 60 malicious packages in the RubyGems ecosystem, it’s crucial for developers and users alike to stay vigilant and protect their valuable data from these deceptive threats.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
In a shocking twist in the crypto world, the GreedyBear hacking campaign has siphoned over $1 million by exploiting more than 150 deceptive Firefox extensions posing as popular wallets. This eye-opening event not only highlights the vulnerabilities in our digital transactions but also underscores the urgent need for user awareness and robust security measures!

As we dive into 2023, the surge in ransomware attacks is sending shockwaves through the digital landscape, with incidents skyrocketing over 50% compared to last year. This alarming trend not only threatens our personal data but poses a significant risk to businesses, as ransom demands now average a staggering $200,000—are we prepared to face this escalating crisis?

Get ready for a game-changing move in cybersecurity! The UK government is set to ban ransom payments across public sector organizations, including the NHS and schools, aiming to disrupt the business model of cybercriminals and strengthen our defenses against growing threats.

In a chilling twist of innovation, ransomware groups like GLOBAL GROUP are now harnessing AI chatbots to revolutionize their negotiation tactics, applying relentless pressure on victims while raising urgent questions about our cybersecurity defenses. As this high-stakes game of cat and mouse unfolds, it’s clear that the battle against cybercrime is entering a perilous new era.

As digital privacy hangs in the balance, the emergence of DCHSpy—a cunning malware masquerading as a VPN—serves as a chilling reminder of the lengths to which oppressive regimes will go to silence voices of dissent. This insidious spyware, targeting Iranian activists, underscores a growing threat to freedom in an increasingly surveilled world—making us all rethink just how safe our online spaces truly are.

A recent malware attack on a U.S. accounting firm highlights just how crucial our cybersecurity measures are in todays digital landscape. With sophisticated threats like Ghost Crypt and PureRAT on the rise, it’s a wake-up call for businesses to strengthen their defenses and stay one step ahead of cybercriminals.

In a startling turn of events, over 3,500 websites have fallen victim to a cryptojacking resurgence, hijacking users computing power without consent and raising urgent questions about cybersecurity and ethical responsibility. As we navigate this murky digital landscape, its crucial to understand the implications for our rights as online citizens.

In a world where our inboxes are under siege, the UKs alarming discovery of a new Microsoft-targeting malware by the notorious APT28 group raises urgent questions about the safety of our communications. With cyber threats evolving rapidly, it’s time to rethink our digital defenses before its too late!

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
In a world where information equals power, Russia’s latest malware, Authentic Antics, targets Microsoft cloud email accounts, raising the stakes in cyber warfare. This evolving threat calls for a renewed focus on cybersecurity as the digital battlefield becomes more complex and perilous.

Get ready to dive into the alarming world of LameHug malware, where AI-driven commands are reshaping the landscape of cyber threats—especially for Ukraines defense sector. As we rely more on technology, how prepared are we to tackle these sophisticated attacks that blur the line between conventional warfare and digital espionage?

In a chilling twist in the world of cyber warfare, the newly discovered LameHug malware is leveraging AI-generated commands to launch sophisticated attacks, primarily targeting Ukraines security sector. As this digital threat evolves, experts warn that what begins in one country could quickly escalate into a global crisis—highlighting the urgent need for advanced defenses in our increasingly interconnected world.

As the manufacturing sector grapples with a staggering 47% surge in ransomware breaches, its clear that cybercriminals are honing in on our industries, posing a serious threat to productivity and security. With many manufacturers still lagging in cybersecurity, nows the time for a proactive approach to safeguard our digital future!

A new variant of the ZuRu malware is ramping up its attacks on developers using macOS, posing an urgent threat that could compromise sensitive data and entire organizations. As remote work rises, its crucial for developers to bolster their security defenses against this sophisticated cyber menace!

DCHSpy turns trusted VPNs and fake satellite apps into stealthy spy tools, putting Iranian dissidents at real risk of exposure and arrest. Learn how these deceptive apps operate and simple steps you can take to stay safer online.

Imagine your inbox becoming a spying ground — UK officials warn Fancy Bear-linked hackers are using new malware to hijack Microsoft email accounts and siphon private messages and sensitive documents. Take it seriously: enable MFA, tighten access controls, and monitor for unusual logins to stay one step ahead.

Russian state-backed hackers have unleashed stealthy Microsoft-targeted malware to hijack Outlook accounts—exposing how fragile our email defenses can be. Now’s the time to tighten security with phishing-resistant MFA, vigilant monitoring, and smarter user habits to stay one step ahead.