Browsing Category
Cyber Attacks
1102 posts
FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
FortiBleed attacks continue to target Fortinet FortiGate devices, with SOCRadar reporting more than 86,644 compromised devices across 194…
October 9, 2026
Star Blizzard Targets 100+ Organizations with Phishing and RedFlick Technique
Russian group Star Blizzard expands phishing campaigns with a new malware delivery RedFlick technique, using scheduled tasks to deliver the CosmicPulse backdoor.
October 5, 2026
MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data
CloudSEK uncovered the MALFEX campaign using malicious npm packages to deploy Overlord RAT, steal Discord and browser data,…
September 30, 2026
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
September 30, 2026
Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?
Phishing exposure reached 69.9% across five key US industries, with finance and manufacturing facing the highest levels, according to ANY.RUN data.
September 29, 2026
ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor.
September 26, 2026
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea's Lazarus Group may be involved as investigators examine the breach in detail.
September 25, 2026
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools.
September 21, 2026
Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.
September 14, 2026
Anthropic Finds 4th Claude AI Hacking Incident Missed in Earlier Review
Anthropic reveals a 4th Claude AI hacking incident after Opus 4.6 accessed a real system, leading to a review of 481 million evaluation transcripts.
September 10, 2026