Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

A July 2026 cyber incident disrupted a small UK gas-fired electricity generator for several days, prompting a government and NCSC response while posing no wider grid threat or customer outage. Public reporting linked the event to Iran, but no technical evidence has confirmed attribution, and the exact intrusion path, affected systems, and responsible actor remain unknown. #NCSC #Iran #UK #ElectricityGenerator

Read More
New Phishing Campaign Against INPS: Fake Refund for Recalculation of Tax Contributions

CERT-AGID identified a phishing campaign using INPS branding to steal personal data, payment card details, and push victims into approving unauthorized banking transactions. The attack lures users with a supposed €730 refund tied to a “tax and contribution recalculation” and directs them to a fake site on feedsafepro[.]com that imitates the INPS portal. #INPS #CERT-AGID #feedsafepro

Read More
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42 analyzed 405 AI-enabled malware samples and found that about 97% existed only in repositories, sandboxes, or testing environments, while just 12 appeared on production endpoints. The samples that reached real environments were detected and blocked by existing defenses, including FunkSec ransomware, a trojanized Recipe Lister installer, the Oyster backdoor,…

Read More

Research on Browser-in-the-Browser recruitment scams shows threat actors impersonating real HR staff from major companies to run highly convincing interview-themed phishing campaigns. The attacks adapt to mobile by swapping the fake browser popup for a full-screen login page, while infrastructure and lookalike domains tied to brands like Amazon, Apple, and FIFA remain active for long periods. #BrowserintheBrowser #Amazon #Apple #FIFA #Zimperium

Read More
5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive

The article analyzes five major 2026 cyber attacks, focusing on network and WHOIS artifacts tied to Ivanti EPMM, Cisco SD-WAN, Stryker, and multiple ShinyHunters-related breaches. It highlights dozens of domains, subdomains, and IPs, including typosquatting clusters, historical DNS resolutions, and newly discovered email-connected infrastructure. #IvantiEPMM #CiscoSDWAN #Stryker #ShinyHunters #oastfun #shinyhuntersrs #azurenetfilesnet

Read More
AI Phishing Attacks Exploit a Fake “Health Ticket Refund” from the Ministry of Health

CERT-AGID identified a phishing campaign using the Ministry of Health’s name and branding to trick victims into revealing personal data and payment card details through a fake €278.26 refund notice. The fraudulent emails spoof the sender [email protected] and direct users to malicious pages that collect identity, contact, and card information for further abuse. #CERT-AGID #MinisteroDellaSalute #fondisanitari.gov.it

Read More
Introducing EchoBench: A Human Calibrated Benchmark for Autonomous Pentesting

EchoBench is a human-calibrated benchmark for autonomous web application pentesting that scores model-and-harness systems against associate pentesters from NetSPI University. It uses four geometric-mean components—finding fidelity, difficulty-reach, OWASP breadth, and repeatability—while publishing cohort, configuration, provenance, and repeatability details alongside every score. #EchoBench #NetSPIUniversity #OWASP2025

Read More
Chinese Malware Delivery Domains Part V

A large-scale Silver Fox-associated delivery network continues to operate after reported arrests, using hundreds of new typosquatted domains, abused legitimate services, and cloud-hosted payloads to target Chinese-speaking users. The campaign mainly delivers obfuscated Gh0stRAT variants through fake installers for tools like DeepSeek, Doubao, AiCoin, and MetaTrader, while using UAC bypass, reflective DLL injection, persistence, and tracking infrastructure to maintain access and evade analysis. #SilverFox #Gh0stRAT #DeepSeek #Doubao #AiCoin #MetaTrader #HuorongSecurity

Read More

zLabs identified ToxicPanda 2.0, an updated Android banking Trojan that greatly expands its command set, targeting scope, and fraud capabilities, including PIN theft, lock-screen credential harvesting, and abuse of Android Wireless Debugging for shell access. The campaign also shifts delivery to Amazon AWS-hosted buckets and targets 349 financial apps and 140+ banking and cryptocurrency apps across 16 countries. #ToxicPanda #AmazonAWS #AndroidAccessibilityService #ADB #SPAKE2

Read More
The invisible passenger in your car

Researchers uncovered a new Android malware campaign targeting Android-based automotive head unit firmware through the legitimate TWCore updater, making this the first documented infection chain of its kind on a car head unit. The multi-stage payload ends in a clicker and the zhima reverse proxy module, and Kaspersky attributes the activity with high confidence to the MoYu Group, an actor linked to BADBOX. #TWCore #JarService #zhima #MoYuGroup #BADBOX #DoFun

Read More