
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Microsoft disrupted an AI-powered phishing campaign that used SVG files disguised as PDFs to trick email and cloud preview viewers into stealing credentials, showing attackers can now auto-generate convincing scams at scale. Treat unexpected document previews and credential prompts with caution, enable MFA, and verify senders to stay one step ahead.

Researchers uncovered a clever phishing campaign weaponizing innocent-looking SVG images to deliver a chain of malware — including PureRAT — that’s been targeting ministries, aid groups, and civilians in Ukraine and Vietnam. Stay wary of unexpected attachments and verify senders before you click, because even an image can be the gateway to credential theft and hidden cryptomining.

Singapore is sounding the alarm after a spike in Facebook impersonation scams that have cheated residents and strained law enforcement, and officials are now publicly pressing Meta to act faster to protect users. If platforms don’t step up with better detection, verification and takedowns, trust — and people’s money and privacy — will keep eroding.

A new online tool can turn any ordinary link into a convincingly “malicious”-looking URL, blurring the line between prank and peril and making it harder to tell real threats from harmless links. That dual-use risk means we need better detection, clearer browser cues, and smarter user education before trust on the web starts to erode.

Got an email asking you to verify your PyPI credentials? Change your password and enable MFA right away — attackers are running a convincing fake PyPI site to harvest logins and could use stolen accounts to push malicious packages or compromise your supply chain.

If a familiar voice can be faked, you can’t rely on phone calls alone—recent research shows deepfake calls are already hitting nearly half of businesses. Start using multi‑channel verification, stronger technical checks, and regular staff training now to stop convincing scams before they cost you money and trust.

When familiar voices and faces can be perfectly faked, trust — and your business — is suddenly vulnerable. With Gartner reporting 62% of organizations hit by a deepfake attack in the past year, now’s the time to tighten verification, train teams, and plan responses before reputations and finances are damaged.

Scattered Spider is skipping the fences and walking through the front door by exploiting weak identity controls, help‑desk processes, and third‑party trust. Tightening phishing‑resistant authentication, enforcing least privilege, and hardening vendor and support workflows are the urgent, practical steps every organization must take.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
From a biotech lab in Minsk to a tour operator in Almaty, dozens of organizations across Belarus, Kazakhstan and Russia were targeted by a tailored phishing campaign that deployed the notorious Formbook trojan—now linked by researchers to a new actor called ComicForm and possibly tied to SectorJ149. The case is a sharp reminder that proven malware plus savvy social engineering lets small groups steal credentials across sectors, so adding MFA, least‑privilege controls and behavioral monitoring is more important than ever.

Scammers are cloning the FBI’s IC3 complaint portal, turning the place victims go for help into a data‑harvesting trap. Before you report, verify fbi.gov links, use bookmarks, and follow official contact methods to keep your information safe.

DPRK-linked hackers are swapping code-focused bait for ClickFix-style tickets that trick marketing and trading teams into installing BeaverTail and InvisibleFerret malware, putting funds and customer systems at risk. It’s a wake-up call to treat phishing as a financial-security issue—tighten email defenses, role-based access, and training beyond engineering.

What looks like a friendly LinkedIn job pitch was actually a backdoor: UNC1549 (Subtle Snail) used recruitment lures to compromise 34 devices across 11 European telecoms, proving how state-linked spies weaponize professional networking to hit critical infrastructure. Telecoms, employees, and policymakers need better authentication, platform-aware training, and faster threat-sharing to stop trust from becoming an attack vector.

Phishing-as-a-service has exploded into a business — Netcraft found over 17,500 phishing domains spoofing 316 brands — turning credential theft into an off‑the‑shelf operation. Security teams and policymakers must act fast: harden authentication, automate detection, and disrupt the cross‑border plumbing that powers these disposable scams.

U.K. police arrested 17‑year‑old Thalha Jubair after tracing gift‑card purchases back to the same crypto wallets used in Scattered Spider’s alleged $115M extortion campaign. It’s a striking reminder that sloppy opsec and smart crypto forensics can crack sophisticated social‑engineering rings — and that businesses must tighten people‑centric defenses.

Think twice before clicking that checkbox — attackers are using AI to spin up lifelike fake CAPTCHAs that harvest credentials and turn a trusted security step into an easy phishing trap.

China-backed hackers impersonated a U.S. congressman to snoop on trade deliberations, using tailored spear-phishing to harvest credentials and gain persistent access to policymakers, think tanks and law firms. Proofpoint warns this stealthy campaign undermines trust in policymaking and shows why stronger email defenses, MFA and tighter operational security are urgently needed.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Microsoft just dismantled RaccoonO365, seizing 338 fake login sites that had harvested at least 5,000 Microsoft credentials — a big win that cuts off a major phishing operation and a wake-up call to harden your accounts.

Beware: a fast-moving campaign called FileFix fakes Facebook security alerts to trick users into downloading tools that actually install the StealC infostealer and follow-on downloaders. Stay cautious—verify alerts inside the official app, never run executables from links, and enable phishing-resistant MFA.

Good news: HMRC-branded email phishing fell sharply in early 2025, suggesting tech fixes and public awareness are having an impact — but don’t relax yet. Scammers are pivoting to SMS, social and AI-enhanced tricks, so stay sceptical, verify contacts and report anything suspicious.

Search results are being weaponized: lookalike download pages boosted by SEO are tricking Chinese Windows users into installing trojanized installers carrying Hiddengh0st and Winos. Always grab updates from vendor channels, verify installer signatures, and be suspicious of search results that look “too convenient.”

North Korean-linked hackers are using ChatGPT and image AI to forge photorealistic military IDs and craft highly convincing spear-phishing lures that can fool even seasoned professionals. It’s a wake-up call: stronger verification, cryptographic signing and vigilant cyber-hygiene are now essential to stop AI-enabled deception.

Researchers say North Korean operatives used ChatGPT to craft a convincing fake South Korean military ID, showing how generative AI can supercharge social-engineering and produce forgeries that easily fool human reviewers. It’s a wake-up call: organizations need stronger cryptographic identity checks, smarter detection tools, and better staff training so polished prose no longer equals trust.

Imagine downloading what looks like legitimate software only to find your PC compromised — attackers are using SEO tricks and GitHub Pages to push kkRAT to Chinese-speaking users by creating convincing fake download pages and hijacking search rankings. Fortinet warns this weaponized trust turns routine searches into infection vectors, so stick to vendor sites and double-check every download.

Think a school outage means a shadowy hacker? More often it’s curious teens — the ICO says students cause over half of school cyberattacks — so parents can steer curiosity into clubs, supervised learning, and clear conversations about ethics before experimentation becomes real harm.