Skip to main content

Tag: threat actors

236 articles

GitHub repository on laptop in home office with papers and smartphone nearby.

Malicious npm Package Targets Claude AI User Files via GitHub

Disguising itself as a harmless archive deployment sync tool, the malicious npm package mouse5212-super-formatter secretly synced local workspace files to a remote tracking tree, allowing attackers to target user files on GitHub.

Analyst 207
Office worker sits at desk with laptop and printer in background.

FortiGuard Labs Exposes Sophisticated Phishing Campaign Targeting Windows Users

Beware of a sneaky phishing campaign that's targeting Windows users with a multi-stage attack chain, starting with a seemingly harmless email attachment that unleashes a powerful malware. This stealthy threat uses clever tactics like process hollowing to inject malicious code into trusted Windows processes.

Analyst 207
Crowded stadium exterior at night with subtle shadows hinting at online threats.

Fraudsters Target World Cup Fans with 4300 Fake FIFA Domains

Scammers are gearing up to target FIFA World Cup fans with a massive network of over 4,300 fake domains, a recent analysis revealed. These fraudulent sites, linked to six distinct scams and four threat actors, are currently dormant but ready to be activated as the 2026 tournament approaches.

Analyst 207
Dimly lit workspace with scattered screens and keyboards, featuring empty and blurred computer terminals.

GitHub Megalodon Attack Targets Repos with Malicious CI/CD Workflows

In a shocking six-hour blitz on May 18, 2026, attackers unleashed a massive supply-chain campaign dubbed "Megalodon," pushing 5,718 malicious commits to 5,561 GitHub repositories. The sneaky assault mimicked routine CI maintenance, using fake author names and convincing commit messages to deceive victims.

Analyst 207
Brightly-lit network operations room with equipment racks and cables, laptop screen blurred in foreground.

Hackers Exploit SonicWall VPN Flaw to Bypass MFA

In a shocking exploit, hackers have successfully bypassed multi-factor authentication on SonicWall VPN devices, breaching security in as little as 30 minutes. ReliaQuest researchers detected the first in-the-wild exploitation of CVE-2024-12802, warning of a swift and stealthy threat.

Analyst 207
Software development workspace with laptop, notes, and monitor displaying lines of code in a neutral-colored room with…

Mini Shai-Hulud Worm Targets AntV Ecosystem with Coordinated npm Package Attack

In a shocking one-hour surge, 639 malicious versions were pushed across 323 unique npm packages, crippling the AntV ecosystem with a massive coordinated attack linked to the Mini Shai-Hulud worm. This brazen move was designed not only to spread chaos but also to slow down analysis and detection efforts.

Analyst 207
Laptop screen blurred, a software update is applied in a quiet, well-lit workspace.

Drupal Rushes Security Fix to Plug High-Risk Bug

Drupal is rushing out a critical security update today to fix a high-risk bug that could be exploited by hackers within hours of the patch being released. The update is a core security release aimed at plugging a vulnerability that poses a significant threat to users.

Analyst 207
Rows of equipment racks and patch panels in a modern network closet with a technician's workbench in the foreground.

Vulnerability Exploits Overtake Credentials as Top Breach Entry Point

For the first time in nearly two decades, exploiting vulnerabilities has surpassed compromised credentials as the top breach entry point, accounting for 31% of data breaches over the past year. This significant shift suggests that threat actors are adapting their tactics, and defenders must follow suit.

Analyst 207
Person holding smartphone surrounded by fake software update prompts and alerts.

Malicious Android Apps Fuel 659M Daily Ad Fraud Bid Requests

Meet Trapdoor, a massive ad fraud scam driven by 455 malicious Android apps that generated a whopping 659 million daily bid requests at its peak, all while hiding in plain sight as harmless utilities like PDF viewers and file managers. These fake apps tricked users into installing malware, unleashing a hidden ad fraud operation controlled by 183 threat actor-owned domains.

Analyst 207
Law enforcement operation room with a large, dismantled computer setup symbolizing disrupted malware signing service.

Microsoft Disrupts Malware Signing Service Used by Ransomware Groups

Microsoft cracked down on a sophisticated malware signing service run by a group called Fox Tempest, which helped ransomware gangs disguise their malicious programs as legitimate software. This service was like a master forgery operation, creating counterfeit digital signatures that even experts struggled to spot.

Analyst 207
Laptop screen displays blurred code in a coding environment on a plain surface with papers and a notebook nearby.

Grafana Labs Discloses Source Code Theft by Hackers

Hackers recently breached Grafana Labs' security, gaining unauthorized access to a GitHub token that allowed them to download the company's source code, and subsequently attempting to extort payment to keep it under wraps. The incident was swiftly investigated, and the compromised token was promptly invalidated.

Analyst 207
Blurred computer terminal surrounded by development notes and empty coffee cups in a brightly-lit coding environment.

GitHub Actions Supply Chain Attack Exfiltrates CI/CD Credentials

A sneaky supply chain attack on GitHub Actions has led to the theft of CI/CD credentials, with hackers using a clever trick to redirect tags to fake commits that hide malicious code. By masquerading as legitimate commits, attackers were able to execute arbitrary code and evade pull request reviews.

Analyst 207
Dimly lit Apple laptop on cluttered desk with crypto wallet and password notes nearby, hint of backdoor vulnerability in…

Reaper Stealer Targets macOS Users with Password, Wallet Theft and Backdoor Attacks

macOS users beware: Reaper Stealer malware is on the loose, stealing passwords, crypto-wallets, and installing backdoors on infected machines. This triple-threat attack puts Apple platform users and their defenders on high alert.

Analyst 207
Brightly-lit computer lab with laptops and computers, hinting at disruption.

SaaS Breaches Expose Gaps in Enterprise Security Thinking

In a shocking display of vulnerability, ShinyHunters breached Instructure's Canvas platform not once, but twice in a single week, siphoning off a staggering 3.65 terabytes of data from 275 million users across 8,000 institutions. The brazen attacks left hundreds of schools reeling during final exams, forcing Canvas offline and lining the attackers' pockets with a ransom payment.

Analyst 207
Office worker looks concerned at laptop screen displaying Microsoft device login page.

Tycoon2FA Exploits Microsoft 365 with Device-Code Phishing

Beware of Tycoon2FA's sneaky phishing tactics: victims are tricked into granting OAuth tokens to attackers through Microsoft's own device-login flow after clicking a malicious link. This comeback kid of a phishing kit has bounced back from a March disruption, now with added layers of obfuscation to evade detection.

Analyst 207
A coding workstation with a computer screen displaying lines of code in a neutral setting.

Grafana Breach Exposes Codebase, Sparks Extortion Attempt

Grafana recently experienced a security breach, where an unauthorized party gained access to its GitHub environment, downloading its codebase, but fortunately, no customer data or personal info was compromised. The company swiftly responded, taking measures to prevent further unauthorized access and thwarting an attempted extortion by the attacker.

Analyst 207
Person sitting at desk with laptop showing Microsoft Teams, surrounded by office equipment and cityscape through window.

KongTuke Hackers Exploit Microsoft Teams for Rapid Corporate Breaches

KongTuke hackers have found a lightning-fast way to breach corporations, exploiting Microsoft Teams to go from initial contact to persistent foothold in under five minutes. This alarming new tactic is part of KongTuke's evolving social engineering toolkit, complementing its previous web-based attacks.

Analyst 207
Dimly lit server room with rows of computer servers and a single unoccupied workstation.

Fragnesia Exploits Linux Systems, Grants Attackers Root Access

Linux systems are under attack by Fragnesia, a malicious actor that's exploiting vulnerabilities to grant attackers root-level access - a digital equivalent of handing over the keys to the kingdom. This latest incident is a disturbing sequel to the earlier Dirty Frag episode, highlighting a growing threat to Linux users.

Analyst 207
Person in business casual outfit working intently at a laptop in a brightly-lit office security area.

Organizations Fortify Defenses Against Evolving Scattered Spider Threats

As Scattered Spider threats evolve, organizations across finance, healthcare, and telecom are bolstering their defenses against sophisticated identity-driven attacks. They're facing an adaptable adversary that's changing tactics, putting pressure on institutions to respond.

Analyst 207
Empty college corridor with students and faculty showing subtle concern.

Instructure Discloses Double Breach Amid ShinyHunters' Data Leak Threat

In a shocking security breach, Instructure, the creator of Canvas, revealed not one, but two separate intrusions into its system, leaving thousands of schools and students scrambling for access to crucial course materials during final exams. The breaches come as an extortion group, ShinyHunters, threatens to leak a massive 3.65 TB of stolen data.

Analyst 207
Mac laptop on a desk with a Terminal window open, in a blurred office setting.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware

Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

Analyst 207
Laptop on a minimalist desk shows a suspicious sign-in page with subtle anomalies.

Phishing Campaigns Exploit Vercel's AI Tools

Scammers are using Vercel's AI tools to create super-realistic phishing sites that mimic popular brands, making it easier for them to trick victims into handing over sensitive info. This clever tactic allows attackers to quickly recreate malicious pages, even if they're taken down.

Analyst 207
Darkened server room with damaged server rack and scattered cables, backup storage system blurred in background.

Ransomware Attacks Expose Backup Vulnerabilities

Ransomware attackers often destroy backup systems before encrypting data, rendering your recovery plan useless. This deliberate tactic follows a predictable sequence, allowing attackers to systematically dismantle your defenses and leave you with limited options.

Analyst 207
Blurred office workers in background, phone on desk in focus, with cityscape visible through window.

Real Estate Giant Hit by Vishing Incident from ShinyHunters, Qilin Gang

Cushman & Wakefield, a real estate giant, has confirmed a vishing incident at the hands of notorious threat actors ShinyHunters and Qilin Gang, highlighting the growing threat of social engineering attacks. This recent breach serves as a stark reminder of the importance of robust security measures.

Analyst 207