CISA’s dual red team assessments showed that both organizations could be fully compromised in AD, cloud, and sensitive business systems, but only Organization B detected and contained the activity quickly. The advisory highlights misconfigured ADCS and MAQ settings, excessive permissions, exposed credentials, and weak cloud token and application controls as the…
Category: Threat Research
A July 2026 cyber incident disrupted a small UK gas-fired electricity generator for several days, prompting a government and NCSC response while posing no wider grid threat or customer outage. Public reporting linked the event to Iran, but no technical evidence has confirmed attribution, and the exact intrusion path, affected systems, and responsible actor remain unknown. #NCSC #Iran #UK #ElectricityGenerator
CERT-AGID identified a phishing campaign using INPS branding to steal personal data, payment card details, and push victims into approving unauthorized banking transactions. The attack lures users with a supposed €730 refund tied to a “tax and contribution recalculation” and directs them to a fake site on feedsafepro[.]com that imitates the INPS portal. #INPS #CERT-AGID #feedsafepro
A phishing campaign that starts with fake CRA T4 tax documents is actually a 46-country operation that abuses legitimate remote management software to gain hands-on access to victim machines, with the United States accounting for 45% of observed activity. The kit reuses stable clues like fmtt, font1.woff2, and icons8-microsoft-word-94.png while rotating…
Unit 42 analyzed 405 AI-enabled malware samples and found that about 97% existed only in repositories, sandboxes, or testing environments, while just 12 appeared on production endpoints. The samples that reached real environments were detected and blocked by existing defenses, including FunkSec ransomware, a trojanized Recipe Lister installer, the Oyster backdoor,…
Research on Browser-in-the-Browser recruitment scams shows threat actors impersonating real HR staff from major companies to run highly convincing interview-themed phishing campaigns. The attacks adapt to mobile by swapping the fake browser popup for a full-screen login page, while infrastructure and lookalike domains tied to brands like Amazon, Apple, and FIFA remain active for long periods. #BrowserintheBrowser #Amazon #Apple #FIFA #Zimperium
The CIS CTI team identified KrustyLoader staged in AWS S3 buckets and used by threat actors to deliver an encrypted Sliver payload that injects into Windows Explorer and deletes itself from disk. Investigation linked the activity to multiple compromised or attacker-created cloud storage buckets, with open-source reporting connecting the campaign to…
A group of Microsoft-branded SysScan websites is using fake security scans to falsely claim that third-party antivirus on Windows is causing serious problems and should be uninstalled. The scam funnels victims into a refund call, collects personal and banking details, and sends the data to Telegram while presenting a fake handoff…
The article analyzes five major 2026 cyber attacks, focusing on network and WHOIS artifacts tied to Ivanti EPMM, Cisco SD-WAN, Stryker, and multiple ShinyHunters-related breaches. It highlights dozens of domains, subdomains, and IPs, including typosquatting clusters, historical DNS resolutions, and newly discovered email-connected infrastructure. #IvantiEPMM #CiscoSDWAN #Stryker #ShinyHunters #oastfun #shinyhuntersrs #azurenetfilesnet
Fake Rockstar sites are using hype around GTA 6 leaks and the upcoming Extended Look to push a malicious gta6_installer.exe that installs the Vidar infostealer. The campaign steals saved passwords, session cookies, and browser data from multiple browsers and can bypass the protection of 2FA by reusing stolen authenticated sessions. #GTA6…
CERT-AGID identified a phishing campaign using the Ministry of Health’s name and branding to trick victims into revealing personal data and payment card details through a fake €278.26 refund notice. The fraudulent emails spoof the sender [email protected] and direct users to malicious pages that collect identity, contact, and card information for further abuse. #CERT-AGID #MinisteroDellaSalute #fondisanitari.gov.it
EchoBench is a human-calibrated benchmark for autonomous web application pentesting that scores model-and-harness systems against associate pentesters from NetSPI University. It uses four geometric-mean components—finding fidelity, difficulty-reach, OWASP breadth, and repeatability—while publishing cohort, configuration, provenance, and repeatability details alongside every score. #EchoBench #NetSPIUniversity #OWASP2025
A large-scale Silver Fox-associated delivery network continues to operate after reported arrests, using hundreds of new typosquatted domains, abused legitimate services, and cloud-hosted payloads to target Chinese-speaking users. The campaign mainly delivers obfuscated Gh0stRAT variants through fake installers for tools like DeepSeek, Doubao, AiCoin, and MetaTrader, while using UAC bypass, reflective DLL injection, persistence, and tracking infrastructure to maintain access and evade analysis. #SilverFox #Gh0stRAT #DeepSeek #Doubao #AiCoin #MetaTrader #HuorongSecurity
zLabs identified ToxicPanda 2.0, an updated Android banking Trojan that greatly expands its command set, targeting scope, and fraud capabilities, including PIN theft, lock-screen credential harvesting, and abuse of Android Wireless Debugging for shell access. The campaign also shifts delivery to Amazon AWS-hosted buckets and targets 349 financial apps and 140+ banking and cryptocurrency apps across 16 countries. #ToxicPanda #AmazonAWS #AndroidAccessibilityService #ADB #SPAKE2
Researchers uncovered a new Android malware campaign targeting Android-based automotive head unit firmware through the legitimate TWCore updater, making this the first documented infection chain of its kind on a car head unit. The multi-stage payload ends in a clicker and the zhima reverse proxy module, and Kaspersky attributes the activity with high confidence to the MoYu Group, an actor linked to BADBOX. #TWCore #JarService #zhima #MoYuGroup #BADBOX #DoFun