The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

Since late March 2026, a large-scale campaign has used heavily obfuscated JScript droppers, Lua/AutoIt loaders, and fileless execution to deploy RATs and infostealers such as Agent Tesla, Remcos, XWorm, Snake Keylogger, and Best Private LOGGER. The attackers impersonate trusted companies to deliver phishing lures, then use disguised .ttf files, Donut shellcode, and layered anti-analysis techniques to gain control of infected Windows systems and exfiltrate data. #AgentTesla #Remcos #XWorm #SnakeKeylogger #BestPrivateLOGGER #LuaJIT #AutoIt

Read More
Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive

Check Point Research uncovered a large-scale operation that impersonated open-source and freeware projects to capture search traffic through deceptive sites and click-driven redirects. The traffic was funneled through a CloudFront-hosted JavaScript staging layer and TDS chains that ultimately pointed selected users to RemusStealer, AnimateClipper, and the SessionGate framework. #CheckPointResearch #CloudFront #RemusStealer #AnimateClipper #SessionGate

Read More
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

Zscaler ThreatLabz tracked a threat actor likely acting as an initial access broker for ransomware, using Microsoft Teams vishing, Quick Assist, and PowerShell to deploy the GoGRPC backdoor and related tools. The campaign evolved through four GoGRPC variants—Lep, Giver, Pet, and Kind—and additional tooling such as BlindDoor, RevSocket, PyGRPC, S3Siphon, and RSOX to support reconnaissance, proxying, and data theft. #GoGRPC #MicrosoftTeams #QuickAssist #BlindDoor #RevSocket #PyGRPC #S3Siphon #RSOX

Read More
How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts

Elastic tested ES|QL COMPLETION on noisy curl and wget detection rules in cloud environments to filter benign activity before alerts reached analysts. In a seven-day wget evaluation, only three destinations survived deterministic filtering, all were triaged by the LLM, and none produced analyst-opened alerts, helping preserve trust in detections for cases like ingress tool transfer. #ESQL_COMPLETION #curl #wget #ElasticCloudServerless #Auditbeat

Read More
Email Bombing, IT Impersonation, Quick Assist, and Edgecution: Breaking Down UNC6692’s Tradecraft

eSentire TRU reported a July 2026 phishing campaign attributed to UNC6692 that used email bombing, Microsoft Teams impersonation, Quick Assist, and a phishing site to deliver the Edgecution malicious browser extension to a software industry victim. Edgecution abused a Microsoft Edge extension plus a native messaging host to monitor targeted websites, steal credentials, and execute commands on the host system. #UNC6692 #Edgecution #MicrosoftEdge #MicrosoftTeams

Read More
France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends

CloudSEK telemetry shows a sustained surge in France-targeted data leaks, credential dumps, ransomware advisories, and hacktivist activity, with dark-web volume rising more than 4x over two years and driven mainly by infostealer logs and credential resale. The report also links this underground activity to rising CNIL enforcement, major breaches at Free Mobile/Free and France Travail, and ongoing disruption campaigns by NoName057(16). #CNIL #FreeMobile #FranceTravail #NoName05716

Read More
The SOCI Act, explained: obligations, recent reforms, and where preemptive cyber defense fits

Australia’s SOCI Act imposes expanding security, reporting, and risk-management obligations on critical infrastructure operators across eleven sectors, with recent reforms and proposed changes broadening its reach. The article argues that preemptive cyber defense helps organisations meet these duties earlier by spotting adversary infrastructure before attacks launch and before reporting clocks begin….

Read More

corepack[.]org is impersonating the Corepack Node.js tool to lure developers into downloading malicious executables that install an infostealer and enroll victims in proxyware bandwidth sharing. The fake site also uses a separate redirect chain to deliver adware or trojan activity, while the real Corepack project has no official website at corepack.org. #Corepack #Nodejs #OpenShield #OperaGXSetup

Read More
ta458 roundpress exploits

Proofpoint reports that TA458, a Russia-aligned espionage actor linked to Operation RoundPress, continues to use half-click webmail exploits to steal emails, credentials, and contacts from government and military targets. The campaign has leveraged vulnerabilities in Zimbra, mDaemon, Roundcube, Kerio, and SOGo, while the SpyPress payload has evolved toward long-term access and…

Read More
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Russian state-supported actors tracked as LAUNDRY BEAR have been exploiting CVE-2025-66376 in Zimbra Collaboration Suite to steal email data and sensitive account information from Western organizations. The campaign uses a view-based phishing exploit, custom tooling called Ulej, and Flowerbed/Catcher infrastructure to collect and exfiltrate data via DNS and HTTPS. #LAUNDRYBEAR #ZimbraCollaborationSuite…

Read More
Russian Global Webmail Espionage

Unit 42 tracked CL-STA-1114, a persistent cyberespionage campaign linked to the Russian threat actors Void Blizzard and LAUNDRY BEAR that targets Zimbra webmail in government, defense, transportation, and financial organizations across multiple regions. The attackers used zero-click phishing emails exploiting CVE-2025-66376 in Zimbra Collaboration Suite to inject JavaScript that steals credentials,…

Read More
Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)

Kimsuky continued spear phishing campaigns in 2026 by impersonating diplomatic personnel and using LNK files, PowerShell, and HTA content to deploy tools such as PebbleDash, PrxClient, RDP Wrapper, UACMe, and keyloggers. The attacks targeted education-sector users, enabled remote control and credential theft, and used infrastructure including edcvbgtrf[.]medianewsonline[.]com and IPs such as…

Read More
Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?

SentinelLABS built a multi-stage benchmark around the fast16 sabotage implant to test whether frontier models can sustain a trustworthy malware investigation as new evidence repeatedly overturns earlier conclusions. OpenAI’s GPT-5.6 Sol was the only public model to complete all eight stages, showing project-scale recovery by revising theories, repairing artifacts, and preserving valid evidence while analysts retained final authority. #SentinelLABS #fast16 #GPT-5.6Sol

Read More
Inside a TrickBot Variant Using DNS Tunneling for C2

FortiGuard Labs analyzed a TrickBot variant that uses DNS tunneling instead of HTTP to communicate with its command-and-control servers, while also hiding its behavior with encrypted strings, runtime API resolution, and NTFS Alternate Data Streams. The malware maintains persistence through Windows Task Scheduler and supports modular actions such as command execution, module download, process hollowing, process doppelgänging, and rundll32-based execution. #TrickBot #westurn.in #Wireshark

Read More