Lampion’s Portugal-focused phishing campaign delivers multistage malware

Acronis TRU uncovered an active Lampion campaign that uses Portuguese-language phishing emails, fake financial documents, and a staged infection chain to target users in Portugal. The malware delivers oversized, heavily obfuscated HTML and VBS files that ultimately install a RAT via rundll32 and a DLL payload hosted on attacker-controlled infrastructure. #Lampion #SAPO #AlticePortugal

Read More
World Cup Retrospective: Analyzing the Surge in Cyber Threats

The 2026 FIFA World Cup triggered a surge of opportunistic attacks, with Netskope detecting more than 28,000 World Cup-themed threats across over 1,000 organizations worldwide and a peak of nearly 6 times the pre-tournament average in users reaching malicious content. Attackers used phishing job scams, fake streaming sites, and file-based malware to steal credentials, trick users into payment, and deliver commodity infostealers. #FIFAWorldCup #Netskope #WorldCup_Tickets_Viewer

Read More
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

A malicious Packagist development-version campaign tied to the compromised dinushchathurya repositories used GitHub Actions workflows to turn GitHub-hosted runners into disposable infrastructure for scanning and exploiting cPanel and WHM systems, including CVE-2026-41940. The operation also harvested credentials, configuration data, and tokens, with evidence showing the campaign extends far beyond one maintainer and uses infrastructure at 43[.]228[.]157[.]68 and DNSHook callbacks to coordinate exfiltration. #dinushchathurya #cPanel #WHM #CVE-2026-41940 #GitHubActions #DNSHook

Read More
Azure VM Command Execution using Third-Party Extensions – Chef

The article explains how an attacker can abuse legitimate Azure third-party VM extensions, specifically Chef, to achieve undetected code execution and maintain access on Windows or Linux virtual machines. It demonstrates a rogue Chef server attack that uses a malicious cookbook to steal the VM’s Managed Identity token and exfiltrate it to an out-of-band endpoint. #Chef #Azure #ManagedIdentity #chef-zero #oastify

Read More
Security Issues in the Korean & Global Financial Sector in June 2026

June’s financial sector threat analysis shows phishing as the dominant initial attack method, followed by droppers/downloaders and infostealers in multi-stage intrusion chains that end in information theft. The report also highlights HTML-heavy malicious attachments, Telegram-based account leakage, dark web database sales, ransomware extortion, and the trading of access credentials across multiple…

Read More
Four ways AI has fundamentally changed the threat landscape in 2026

Sysdig TRT reports that agentic AI is now carrying out attacks end to end, including rapid exploitation, credential theft, container escapes, and the first documented case of agentic ransomware. The research also shows AI infrastructure and models themselves are now prime targets, while manipulated or stolen models are being used to accelerate offensive operations, including LLMjacking and guardrail-free attacks. #JADEPUFFER #Langflow #Ollama #Llama-3.3-70B #LLMjacking

Read More
Hidden in plain sight: How SVGs carry malicious scripts

Researchers reported a rise in malicious SVG files in early 2026, where attackers abuse embedded JavaScript to build fake login pages, redirect victims, exfiltrate inputs, and deliver malicious downloads. ReversingLabs also found SVG-based spear phishing attachments disguised as voicemail notices and linked to domains such as chx[.]js, pinche[.]php, 01058telecom[.]de, qedhsp[.]cprltdf[.]es, and wihportal[.]sbs. #SVG #ReversingLabs #Wordpress #chxjs #pinchephp #01058telecom #qedhspcprltdfes #wihportalsbs

Read More
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

Kaspersky detailed Project CAV3RN, a modular cyberespionage framework targeting Israel that now uses AzureCommunication.dll and Microsoft Graph Outlook calendar events for C2. When Graph authentication fails, the module can recover TenantId, ClientId, ClientSecret, and UserEmail through DNS AAAA queries against cloudlanecdn[.]com, a capability that reinforces the report’s low-confidence attribution to OilRig (APT34). #ProjectCAV3RN #AzureCommunication.dll #cloudlanecdn.com #OilRig #APT34

Read More

This article describes an adversary-in-the-middle phishing campaign that uses compromised, often aged domains and fake document workflows to steal authenticated sessions from targeted organizations. The actor rotates between Evilginx, EvilProxy, FlowerStorm, and Kali365 while impersonating platforms such as Microsoft, OpenGov, ConstructConnect, and the European Investment Bank to capture credentials, MFA-protected access, cookies, and session tokens. #EvilProxy #FlowerStorm #Kali365 #Evilginx #OpenGov #ConstructConnect #EuropeanInvestmentBank

Read More
Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters

The article argues that Iran-linked cyber activity is driven more by persistent access, trusted administration, service-provider pathways, and persona-led operations than by a single unified threat actor. It also emphasizes that operational technology risk, banking disruptions, and domestic surveillance effects in Iran are real but must be assessed with careful evidence quality rather than claim volume. #Seedworm #MuddyWater #APT42 #Handala #HomelandJustice #Karma #CyberAv3ngers #PredatorySparrow

Read More
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

An exposed server used by attackers functioned as a malware delivery lab, revealing more than 1,000 artifacts for testing WebDAV execution paths, lure generation, and payload staging. The operation appeared to leverage generative AI to rapidly create READMEs, social-engineering lures, and delivery tests, while active campaigns included a CURP-themed phishing flow and the DlrtyGames chain. #WebDAV #CURP #DlrtyGames #PureRAT #StealthFalcon

Read More
JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models

JADEPUFFER returned to a Langflow instance using CVE-2025-3248 and deployed ENCFORGE, a Go-based ransomware built to destroy AI and machine learning assets such as model checkpoints, vector databases, and training datasets. The campaign shows a shift from improvised scripts to purpose-built tooling, with the same extortion contact and new host-escape techniques used to encrypt files and cripple AI recovery. #JADEPUFFER #Langflow #CVE-2025-3248 #ENCFORGE

Read More
Atomic Arch: orphaned AUR packages turned zombie infostealer

Between June 9 and June 17, 2026, attackers abused more than 1,900 orphaned Arch User Repository packages to deliver a fake npm payload called atomic-lockfile that stole developer credentials and could escalate into an eBPF rootkit. The campaign also included bun-based variants, Tor-backed exfiltration, and impersonation of legitimate maintainer identities such as arojas and the herbsobering npm account. #atomic-lockfile #js-digest #nextfile-js #AUR #herbsobering #arojas

Read More