Skip to main content

Tag: threat actors

237 articles

Blurred office workers in background, phone on desk in focus, with cityscape visible through window.

Real Estate Giant Hit by Vishing Incident from ShinyHunters, Qilin Gang

Cushman & Wakefield, a real estate giant, has confirmed a vishing incident at the hands of notorious threat actors ShinyHunters and Qilin Gang, highlighting the growing threat of social engineering attacks. This recent breach serves as a stark reminder of the importance of robust security measures.

Analyst 207
Computer screen displays OAuth integration interface in a CRM workspace.

OAuth Grants Expose Hidden Attack Vector in Enterprise Workspaces

Unmanaged OAuth grants are a ticking time bomb in enterprise workspaces, with 80% of security leaders recognizing them as a critical or significant risk. A recent attack by threat actor UNC6395 exploited valid OAuth refresh tokens to breach Salesforce environments of over 700 organizations, highlighting the devastating consequences of neglecting OAuth security.

Analyst 207
Rows of computer servers in a dimly-lit data center represent a vulnerable cybersecurity setting.

Trellix Breach Exposes Source Code to Threat Actors

Trellix has confirmed a breach of its internal development assets, revealing that threat actors gained unauthorized access to a portion of its source code repository. The company is working with experts to investigate and has found no evidence that its source code has been exploited so far.

Analyst 207
Cloud-based email service dashboard on laptop screen with blurred interface, surrounded by a brightly-lit institutional…

Phishing Attacks Exploit Amazon SES to Evade Detection

Kaspersky researchers have uncovered a surge in phishing attacks that cleverly exploit Amazon's trusted email service to evade detection. By using valid Amazon SES credentials, attackers can send convincing phishing messages that slip past standard security checks.

Analyst 207
Blurred computer screen in a bright office setting with a suspicious email message on screen.

Attackers Exploit Amazon SES to Bypass Email Security in Phishing Campaigns

Phishing campaigns are now using Amazon's Simple Email Service to make malicious messages look legit, bypassing standard email security checks and putting victims at risk of revealing sensitive data. By exploiting Amazon SES's trusted reputation and authentication features, attackers are making it harder to spot phishing emails.

Analyst 207
Brightly-lit network operations center with multiple workstations and natural light from floor-to-ceiling windows.

Threat Actors Exploit Blind Spots Beyond Endpoint Defenses

Attackers are now moving at an alarming pace, taking data four times faster than in 2025, and exploiting the blind spots that an over-reliance on endpoint defenses creates. They're striking across multiple surfaces, from cloud services to remote users, to evade detection and get in and out quickly.

Analyst 207
People work on computers in a dimly lit internet cafe or office surrounded by networking equipment.

Threat Actors Formalize Operational Security Playbook

Cybercrime players are now treating operational security as a sophisticated game-changer, and it's time for you to level up your security strategy beyond just using VPNs. A battle-tested three-tier infrastructure model has emerged, separating exposure, execution, and monetization to safeguard high-stakes operations.

Analyst 207
Cluttered developer workstation with laptop, monitors, and notes in a bright office setting.

Supply-Chain Attack Targets Security, Dev Tools with Credential Theft

Malicious hackers are exploiting the very tools developers rely on, including security scanners and password managers, to steal sensitive credentials and gain unauthorized access. This latest supply-chain attack has already hit major players like Checkmarx, compromising their GitHub repository and potentially putting customer data at risk.

Analyst 207
Blurred smart home device on a table amidst a residential setting hints at a security breach.

ADT Breach Exposes Customer Data, ShinyHunters Claim Responsibility

ADT confirmed a data breach on April 20, after discovering unauthorized access to sensitive customer and prospective-customer information, which was swiftly shut down and investigated. The breach exposed key personal details, but thankfully, payment information and customer security systems remained unaffected.

Analyst 207
Broken lock on a door with scattered ID cards, passports, and a smartphone, with a subtle shadow of a person in the…

Stolen Credentials Empower Attackers in Identity-Based Breaches

While security teams obsess over complex threats, attackers often find it easier to simply walk in with stolen credentials - the quickest and most reliable way into networks. By focusing on sophisticated threats, we might be overlooking the front door, which is wide open with a copy of the keys in the wrong hands.

Analyst 207
Helpdesk worker surrounded by screens with a masked figure lurking in shadows.

Microsoft Teams Targeted in Rising Helpdesk Impersonation Attacks

Microsoft is sounding the alarm on a growing threat: hackers are exploiting Microsoft Teams' external collaboration features to impersonate helpdesk teams and gain access to enterprise networks. They're using the platform's own tools to move undetected, posing a major challenge for defenders.

Analyst 207
Darkened office with eerie shadows, a laptop displaying ominous code and a cracked smartphone, with a ghostly figure in the…

Malware Campaigns Exploit Trusted Channels for Internal Access

Instead of smashing down the front door, attackers are now sneaking in by exploiting trusted channels and misdirecting trust - a subtle yet effective tactic that's leaving defenders, regulators, and users scrambling to respond. This quiet approach to breaching security is a growing concern, with multiple incidents revealing a common pattern of adversaries using third-party components to gain internal access.

Analyst 207
Dark underground market stall with stolen devices and a laptop screen displaying sensitive data.

Vercel Breach Exposes Stolen Data for Sale

A security breach at Vercel has put sensitive data at risk, with hackers claiming to have stolen information and now trying to sell it - but where does the buck stop, and what's next for the internet? The incident raises crucial questions about responsibility and response in the face of cyber threats.

Analyst 207
Smartphone screen with notification, fishing hook hovering above, and shadowy figure lurking in corner.

Hackers Exploit Apple Alerts to Fuel Phishing Scams

Scammers are exploiting Apple's own notification system to send fake emails that look legit, tricking you into divulging sensitive info with phishing scams disguised as iPhone purchase alerts. Be cautious when receiving Apple account change notifications - even if they come from Apple's servers!

Analyst 207
Dimly lit underground bunker with a wooden table, chair, and scattered papers.

The Bunker Talk Rundown Unfolds

I personally can't wait to take you down, Mr. Bond.

Analyst 207
Dark cityscape with glowing laptop, broken shields, and exposed circuits.

Microsoft Defender Zero-Days Exploited in Active Attacks

Microsoft's top security tool, Defender, has been turned against itself: hackers are exploiting three newly discovered flaws to gain elevated access to already compromised systems, forcing a major rethink of what we thought was safe. This alarming development has defenders, users, and policymakers scrambling to reassess their security assumptions.

Analyst 207
Dark parking garage with locked car, shattered windows, and eerie glow of code and circuit boards, with menacing hacker…

Ransomware Targets Carmakers with Growing Ferocity

Ransomware attacks on carmakers have doubled in just one year, now accounting for over two-fifths of all cyber-attacks targeting the industry, signaling a significant shift in the threat landscape. This rapid escalation demands a new level of resilience from firms that design, build, and sell motor vehicles.

Analyst 207
Ominous gate with open section, tangled wires and circuitry in foreground, laptop nearby.

Freight Hackers Exploit Code-Signing Service to Bypass Security Defenses

Thieves have found a sneaky way to disguise their malicious tools as trusted software by using a third-party code-signing service, making it harder for defenders to spot the threat. This new tactic allows them to cloak their malware in legitimacy, complicating the work of security teams trying to keep cargo safe from theft.

Analyst 207
Robotic arm in a dark industrial setting with a glowing laptop screen showing a phishing email and a nearby smartphone with…

n8n Workflow Automation Platform Exploited to Deliver Malware via Phishing Emails

Imagine a tool designed to streamline your work being turned against you - that's what happened when threat actors exploited the popular n8n workflow automation platform to deliver malware via phishing emails, starting as early as October 2025. This clever tactic uses trusted infrastructure to evade defenses, turning productivity tools into a conduit for harm.

Analyst 207

Ransomware Gang 0APT Targets Rival Krybit with Exposure Threat

Ransomware gangs are turning on each other, and the gloves are off - 0APT has publicly threatened to expose individuals tied to rival gang Krybit, escalating their rivalry to a whole new level of personal and public. This shocking move reveals the cutthroat world of cybercrime, where even thieves don't always agree.

Analyst 207
Dark cityscape with cracked window, shattered padlock, and eerie glows of devices, symbolizing vulnerability and cyber…

Microsoft Vulnerabilities Resurface, Fueling Cybercrime and Ransomware

Beware: long-dead Microsoft vulnerabilities are coming back to haunt networks, fueling cybercrime and ransomware attacks. Even a 14-year-old software flaw is being exploited by crooks, putting your network at risk.

Analyst 207
Dark laptop screen with eerie glow, cracked CPU chip, tangled wires, and silhouette of person holding mysterious device.

CPUID Compromised, Trojanized Software Deploys STX RAT

For one day in April, unsuspecting users who visited CPUID.com, a trusted site for hardware-monitoring tools, unknowingly downloaded trojanized software that deployed a malicious remote access trojan called STX RAT. The compromised software, including CPU-Z and HWMonitor, turned a trusted resource into a malware delivery vehicle.

Analyst 207
Factory assembly line with computer motherboards on a conveyor belt, shadowy figure tampering with one board in the…

CPUID Compromised in Supply Chain Attack

A recent supply chain attack on the CPUID project has raised alarming questions about trust in software downloads, after hackers manipulated the official website to serve malware-infected versions of popular tools like CPU-Z and HWMonitor. Can users, defenders, and policymakers be certain that their software sources are safe?

Analyst 207

Ransomware Gangs Consolidate Power with Surge in Attacks

Alarming new data from cybersecurity firm Check Point reveals that just three ransomware gangs - Qilin, Akira, and Dragonforce - accounted for a staggering 40% of all ransomware incidents in March, with a whopping 269 attacks attributed to these groups alone. This concentration of power raises serious concerns about the growing threat of ransomware attacks.

Analyst 207