Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
Beyond 'Fire-and-Forget': How Modular Malware Like GigaWiper is Changing AI Cybersecurity Threats
Research on GigaWiper, a novel modular wiper-backdoor malware that allows threat actors to choose their destructive methods flexibly. Analysis reveals functionality beyond traditional 'fire-and-forget' wipers.
Artificial Intelligence AI Cybersecurity: Defeating the Bloated Lampion Trojan
An analysis of the Lampion banking Trojan, a Brazilian-origin threat targeting Portuguese organizations using massive file padding up to 750MB to evade static analysis and modern AI cybersecurity filters.
Logging In, Not Breaking In: How Stolen Identities Became Ransomware's Top Doorway in 2026
Research findings and outline on the Sophos State of Ransomware 2026 report, highlighting the key shift from vulnerability exploits to identity-driven ransomware root causes.
Defying Everest: How Stadler Rail Navigated Its Latest Cyber Extortion Attempt
An analysis of Stadler Rail's firm refusal to pay a $12.3 million (CHF 10M) ransom demand by the Everest group, looking at the third-party data exchange breach and the company's historical stance on cybersecurity extortion.
AI & Cybersecurity Threats: How CrashStealer Uses macOS Trust to Steal Your Wallets
CrashStealer exploits macOS’s built-in trust in system tools to steal crypto wallets and credentials—using Apple’s own infrastructure against users.
When Your AI Assistant Becomes a Ransomware Accelerant
How enterprise AI assistants and agents inherit identities and permissions that ransomware operators can exploit—and the six governance controls that actually reduce the risk.
Operation Olympus Blade: How Germany and the U.S. Brought Down the Kratos Phishing Empire
German and U.S. authorities dismantled Kratos, a phishing-as-a-service platform used by 1,800+ criminal customers to run 15,000 campaigns per month across 35 countries. More than 200 servers were seized and the developer arrested in Indonesia under Operation Olympus Blade.
OkoBot's 20-Payload Assault on Crypto Wallets Reveals a New Malware Playbook
A new malware framework called OkoBot is delivering over 20 distinct payloads in attacks targeting cryptocurrency wallet seed phrases, browser credentials, and sensitive data. The campaign, tracked by Kaspersky researchers, has been active for over a year and evolved from the TookPS infostealer. OkoBot reaches victims through ClickFix social engineering or malicious GitHub repositories masquerading as legitimate software tools.
Debian 13.6 and 12.15 Point Releases Mark End of 32-bit Support in Bookworm
Debian 13 'Trixie' and Debian 12 'Bookworm' received point releases in July 2026, with Bookworm's final update ending official 32-bit x86 support and Trixie consolidating its focus on modern architectures.
AI Cybersecurity Threats: How Coca-Cola’s Fairlife Ransomware Attack Exposes Operational Fragility
Coca-Cola’s Fairlife dairy shutdown reveals how ransomware now targets supply chains not for data, but to cripple physical operations — a new frontier in AI-driven corporate cyberattacks.
Small Businesses Are Getting Hit by Fake INTERPOL Ransomware — Here's What It Means for Artificial Intelligence Cybersecurity Threats
A new ransomware campaign uses phishing emails impersonating INTERPOL to trick small business employees into downloading malware disguised as evidence of criminal investigations, with attackers tailoring ransom demands to each victim's perceived ability to pay.
AI Cybersecurity Threats: How Russian Hackers Are Hijacking Autonomous Agents Through Router Flaws
A joint U.S. and allied advisory details how Russian state actors are exploiting legacy router vulnerabilities to steal network configurations and compromise AI-driven critical infrastructure systems.