
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
In just 13 minutes, a sophisticated scam combining malware and social engineering tricked Android users into handing over their accounts and credit card info, with the thieves monetizing stolen cards in real time. The attack started with a convincing phone call from someone posing as a bank employee, leading victims to unwittingly download a remote administration tool masquerading as a legitimate app.

In a chilling near-autonomous attack, AI agents breached Taiwan's Nuclear Safety Agency, compromising 85 government accounts and extracting over 2,500 sensitive personnel records in just four days. The sophisticated operation was uncovered by Israeli cybersecurity firm Dream, which revealed a treasure trove of stolen data, including user credentials and internal network information.

Hackers can hijack your customer accounts with just a few clicks, thanks to a critical flaw in Adobe Commerce that lets attackers switch to another customer's session, gaining access to sensitive data. This vulnerability, tracked as CVE-2026-71362, is a wake-up call for businesses to take immediate action and protect their customers' private info.

In a chilling first, hackers unleashed a near-autonomous AI-driven cyber attack on the Taiwanese government, extracting over 2,500 personnel records with alarming ease. This groundbreaking attack was able to adapt and evolve mid-operation, all without human intervention.

Meet the sneaky Trojan backdoor, Troy, that's been secretly infiltrating defense and aerospace companies worldwide by exploiting a newly discovered Windows zero-day vulnerability. This stealthy attack, part of Operation Dream Job, tricks victims with fake job offers on LinkedIn before deploying the malware.

The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

In just 13 minutes, a scammer can use a single phone call to trick victims into installing malware, allowing them to commit card and loan fraud - all thanks to the cunning WindRelay malware. This sneaky software uses NFC relay attacks to enable live-call loan fraud, leaving victims none the wiser.

Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Beware: cybercriminals are on the hunt for intimate content on social media and online accounts, using stolen images and videos to blackmail victims or sell them on shady marketplaces. Once they have your secrets, they can use them to extort and exploit you, often without you even knowing.

Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

In a chilling cyberattack, Russian hackers infiltrated a Polish power plant by breaching a wind farm's VPN and firewall, then exploited a cellular router to gain control of the plant's systems. The attackers forced a combined heat and power plant into a controlled shutdown, overriding its operations with a password-protected lock.

Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Meet Aeternum, a sneaky botnet loader that's exploiting the Polygon blockchain's smart contracts to operate with a decentralized command structure, making it a formidable and harder-to-stop threat. This innovative approach allows Aeternum to shift parts of its malware operations onto a decentralized infrastructure, giving it a unique advantage.

The Kimwolf Botnet has upgraded its tactics, now using the Ethereum Name Service to evade detection and launching sophisticated HTTP/2 floods that mimic real Chrome traffic, making it harder to distinguish from legitimate visitors. This new approach allows infected devices to blend in with normal web traffic, bypassing traditional DDoS defenses.

DeadLock Ransomware is taking a disturbingly clever approach to evade shutdown by leveraging the Polygon blockchain to conceal its operational addresses, making it a formidable foe for cybersecurity efforts. By cleverly using decentralized building blocks, the group has already amassed a shocking 80 victims, mostly in Europe.

North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Beware of fake job interviews! Cyber attackers, linked to the notorious Sandworm group, are targeting IT pros with bogus job offers, tricking them into installing a malicious VPN client to gain access to sensitive info.

The Kimwolf botnet has levelled up its game with a new upgrade, v7, which uses HTTP/2 floods to mimic real browser traffic, making it super tricky to detect as a DDoS attack. This sneaky move lets the botnet build complete browser fingerprints, blurring the line between legit and malicious traffic.

Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Meet the sneaky CAV3RN Espionage Framework, which just got a clever upgrade - it can now use Google Apps Script as a relay to secretly communicate with its controllers, all while hiding in plain sight within DNS traffic. This clever tactic lets the malware decide on a per-transaction basis whether to connect directly to its masters or take a detour through Google's services.