Skip to main content

Tag: threat actors

237 articles

Person in dark room surrounded by papers, laptop and phone glow with eerie light.

Adobe Reader Zero-Day Exploits PDFs to Profile Targets

Malicious PDFs are being used to secretly profile targets, leveraging legitimate features to harvest system data and decide which victims are worthy of a second, more invasive attack. This sneaky tactic uses booby-trapped PDFs to quietly gather intel and determine if you're a high-value target.

Analyst 207
Dark cityscape with giant cracked lock and sprawling botnet network of glowing lines and nodes, pulsing with malicious red…

Botnets Revive 13-Year-Old Apache Flaw in Global Campaign

A shocking resurgence of a 13-year-old Apache flaw has been exploited in a global campaign, highlighting the ongoing threat of old vulnerabilities getting new life. A hybrid P2P botnet and 18 other alarming stories have been uncovered, serving as a stark reminder to stay vigilant in the face of evolving cyber threats.

Analyst 207
Person in a dark room clicks on a laptop icon, surrounded by faint screens and wires.

MacOS ClickFix Attack Exploits Script Editor to Evade Apple Warnings

The cat-and-mouse game continues: after Apple added security warnings to Terminal, attackers behind the Atomic Stealer family adapted their ClickFix attack to exploit Script Editor instead. This latest move shows how adversaries constantly evolve to evade detection.

Analyst 207
Cracked laptop screen lock with shadowy figure exploiting vulnerability in dark cityscape background.

Adobe Reader zero-day flaw under active exploitation

Malicious PDF documents have been hiding a nasty secret: a zero-day vulnerability in Adobe Reader that's been exploited by attackers since at least December, allowing them to spread malware and wreak havoc. This stealthy threat highlights the urgent need for better detection and response to these types of attacks.

Analyst 207
Dimly lit call center with scattered desks and eerie glowing screens, a single broken ticket in the center.

UNC6783 Hackers Infiltrate BPOs to Steal Corporate Support Tickets

Hackers known as UNC6783 are exploiting business process outsourcing providers to gain access to sensitive corporate support tickets on platforms like Zendesk, putting high-value companies across multiple sectors at risk. This sneaky tactic opens the door for cybercriminals to infiltrate and wreak havoc on unsuspecting organizations.

Analyst 207
Shadowy figure in a hoodie amidst industrial complex with glowing laptop screens and cables.

TeamPCP Infiltrates Security Infrastructure with Multi-Stage Supply Chain Attack

When security tools meant to safeguard networks become the entry point for attacks, trust is shattered - and that's exactly what's happening with TeamPCP's multi-stage supply chain attacks on security infrastructure. This sinister tactic lets threat actors turn protectors into launchpads for wider compromise.

Analyst 207
Person in shadows hunched over laptop with eerie glow, cityscape blurred in background, ghostly URL pathway trails from…

Hackers Target Asia Pacific with URL-Based Threats

In Asia Pacific, hackers are ditching traditional tactics and using URL-based threats to gain easy access to your digital life - with just one click, your security can be compromised. This emerging threat landscape is redefining how we think about online identity, access, and trust.

Analyst 207
Dark cityscape with cracked clock tower, hooded figure surrounded by papers and broken locks, laptop screen shows countdown…

Akira Ransomware Group Accelerates Attacks, Hits Encryption in Under an Hour

The Akira ransomware group has supercharged its attacks, able to go from gaining a foothold to locking files in under an hour - the time it takes to pour a cup of coffee. This lightning-fast approach drastically shrinks the window for defenders and ups the ante for victims to pay the ransom.

Analyst 207
Fortinet Rushes Patch for Exploited FortiClient EMS Vulnerability

Fortinet Rushes Patch for Exploited FortiClient EMS Vulnerability

Fortinet has rushed out an emergency patch for a zero-day vulnerability in its FortiClient EMS product, which was being exploited by attackers before the fix was even available. This swift response aims to protect businesses from potential security breaches through its endpoint security clients.

Analyst 207
Cracked laptop screen with eerie glow, snake-like cord morphing into menacing stone face.

Microsoft Uncovers Storm-1175's Medusa Ransomware Link

Microsoft just dropped a crucial report linking Storm-1175, a notorious threat actor, to high-velocity Medusa ransomware attacks that exploit flaws in networked systems. This newly uncovered connection raises the alarm for anyone building, defending, or relying on these systems to stay vigilant against Medusa ransomware attacks.

Analyst 207
LiteLLM Exploit Turns Dev Machines into Hacker Credential Hubs

LiteLLM Exploit Turns Dev Machines into Hacker Credential Hubs

Your developer's workstation is the secret Achilles' heel of your enterprise, unwittingly morphing into a credential hub where sensitive authentication material is created, tested, and reused - making it a prime target for hackers. A recent exploit, dubbed LiteLLM, has already shown how these machines can be turned into treasure troves for threat actors.

Analyst 207
Faceless figures huddled around a laptop with a cartoonish self-takedown scene and a giant X marked through it.

Researchers Mock Cybercrime Crews in Unconventional Takedown

In a bold move, researchers fighting cybercrime decided to take a stand against the mystique surrounding digital gangs by roasting them with ridicule, stripping away their legendary status. By mocking notorious crews like Wizard Spider and Velvet Tempest, they're reclaiming the narrative and deflating the glamour often associated with these cybercrime teams.

Analyst 207
Microsoft Uncovers Cookie-Based Web Shells Persisting on Linux Servers

Microsoft Uncovers Cookie-Based Web Shells Persisting on Linux Servers

Microsoft's latest discovery reveals a sneaky new tactic: hackers are hiding malicious commands in browser cookies to secretly control compromised Linux servers. This clever trick forces us to rethink what we consider normal web traffic and take a closer look at the potential threats lurking in plain sight.

Analyst 207
Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion

Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion

Ransomware attacks have taken a sinister turn, now using stolen data to blackmail victims into paying up - not just by encrypting their files, but by threatening to expose sensitive information to the world. This double extortion tactic adds a whole new level of pressure, forcing victims to weigh the cost of a data breach against the cost of a ransom.

Analyst 207
Residential Proxies Bypass IP Reputation Checks in Most Sessions

Residential Proxies Bypass IP Reputation Checks in Most Sessions

Residential proxies are making it increasingly difficult for defenders to block threats, as they bypass IP reputation checks in a staggering 78% of cases, blending in with ordinary home users. This alarming trend is blurring the lines between attackers and legitimate users, making it harder to keep malicious traffic at bay.

Analyst 207
Attackers Exploit Trusted Tools to Evade Cybersecurity Defenses

Attackers Exploit Trusted Tools to Evade Cybersecurity Defenses

When the very tools you trust to keep your network safe are turned against you, who do you turn to? Imagine your familiar admin tools being hijacked by attackers, quietly compromising your defenses and leaving you vulnerable.

Analyst 207
Critical Citrix Flaw Sparks Alarming CISA Warning

Critical Citrix Flaw Sparks Alarming CISA Warning

The Cybersecurity and Infrastructure Security Agency (CISA) is sounding the alarm on a critical Citrix vulnerability that's being actively exploited by threat actors, warning that immediate patching is crucial to prevent severe consequences. Federal agencies and organizations must act fast to protect their systems from this high-risk vulnerability in Citrix NetScaler appliances.

Analyst 207
Critical Threat: Alarming Rise of Scattered Lapsus ShinyHunters Extortion Tactics

Critical Threat: Alarming Rise of Scattered Lapsus ShinyHunters Extortion Tactics

Scattered Lapsus ShinyHunters, a notorious data ransom gang, is taking extortion to a disturbing new level, using aggressive tactics that threaten not just companies, but also the safety and well-being of executives and their families. Their playbook of harassment, intimidation, and manipulation has raised the alarm among experts, who warn that it's only a matter of time before someone gets hurt.

Analyst 207
Critical Telecom Threats Resurface in Alarming New Campaigns

Critical Telecom Threats Resurface in Alarming New Campaigns

Stay vigilant, as the latest telecom threat campaigns are emerging with renewed ferocity, exploiting familiar attack methods in new and sophisticated ways. Are you prepared for the next big threat and equipped to safeguard your digital landscape?

Analyst 207
DeepLoad Malware Poses Critical Threat with Advanced Evasion Tactics

DeepLoad Malware Poses Critical Threat with Advanced Evasion Tactics

A new and highly sophisticated malware threat, DeepLoad, has emerged with advanced evasion tactics that blur the lines between human psychology and digital security, putting sensitive information at risk. This powerful malware loader uses social engineering and AI-assisted obfuscation to evade detection, making it a critical threat that demands immediate attention.

Analyst 207
Threat Actors Ramp Up ToolShell Exploits: Exclusive Danger

Threat Actors Ramp Up ToolShell Exploits: Exclusive Danger

Threat actors are rapidly escalating ToolShell exploits — discover what’s changing, why it matters, and the simple steps you can take to stay protected.

Analyst 207
Threat Actors: Exclusive Surge in Dangerous App Exploits

Threat Actors: Exclusive Surge in Dangerous App Exploits

Exclusive: Threat actors are unleashing a dangerous surge in app exploits—here’s what’s driving the spike and quick, practical steps to keep your apps and users safe.

Analyst 207
BeaverTail and OtterCookie: Stunning Critical Threat

BeaverTail and OtterCookie: Stunning Critical Threat

Cisco Talos warns a North Korean group is fusing BeaverTail’s credential-theft with OtterCookie’s browser persistence into single, stealthier JavaScript malware that’s harder to spot — defenders should start hunting for blended behaviors and tighten basics like MFA, patching, and anomaly detection now.

Analyst 207
threat actors are evolving: Must-Have Best Defenses

threat actors are evolving: Must-Have Best Defenses

Imagine attackers rebuilding siege engines overnight—60% of security leaders say threat actors are evolving too fast, forcing teams into constant catch-up. Learn how automation, AI, and supply‑chain exploits are redefining risk and which practical steps can help organizations move from reactive defense to resilient security.

Analyst 207