ProBackend
Threats & Attacks

Threats & Attacks

Ransomware, malware, phishing and the actors behind them.

advanced persistent threats apts3 days ago5 min

AI & Cybersecurity Threats: How CrashStealer Uses macOS Trust to Steal Your Wallets

CrashStealer exploits macOS’s built-in trust in system tools to steal crypto wallets and credentials—using Apple’s own infrastructure against users.

agentic ai security risks4 days ago5 min

When Your AI Assistant Becomes a Ransomware Accelerant

How enterprise AI assistants and agents inherit identities and permissions that ransomware operators can exploit—and the six governance controls that actually reduce the risk.

advanced persistent threats apts5 days ago5 min

Operation Olympus Blade: How Germany and the U.S. Brought Down the Kratos Phishing Empire

German and U.S. authorities dismantled Kratos, a phishing-as-a-service platform used by 1,800+ criminal customers to run 15,000 campaigns per month across 35 countries. More than 200 servers were seized and the developer arrested in Indonesia under Operation Olympus Blade.

active vulnerability exploitation6 days ago7 min

OkoBot's 20-Payload Assault on Crypto Wallets Reveals a New Malware Playbook

A new malware framework called OkoBot is delivering over 20 distinct payloads in attacks targeting cryptocurrency wallet seed phrases, browser credentials, and sensitive data. The campaign, tracked by Kaspersky researchers, has been active for over a year and evolved from the TookPS infostealer. OkoBot reaches victims through ClickFix social engineering or malicious GitHub repositories masquerading as legitimate software tools.

cloud security incidents1 week ago3 min

Debian 13.6 and 12.15 Point Releases Mark End of 32-bit Support in Bookworm

Debian 13 'Trixie' and Debian 12 'Bookworm' received point releases in July 2026, with Bookworm's final update ending official 32-bit x86 support and Trixie consolidating its focus on modern architectures.

ransomware attacks1 week ago3 min

AI Cybersecurity Threats: How Coca-Cola’s Fairlife Ransomware Attack Exposes Operational Fragility

Coca-Cola’s Fairlife dairy shutdown reveals how ransomware now targets supply chains not for data, but to cripple physical operations — a new frontier in AI-driven corporate cyberattacks.

active vulnerability exploitation1 week ago5 min

Small Businesses Are Getting Hit by Fake INTERPOL Ransomware — Here's What It Means for Artificial Intelligence Cybersecurity Threats

A new ransomware campaign uses phishing emails impersonating INTERPOL to trick small business employees into downloading malware disguised as evidence of criminal investigations, with attackers tailoring ransom demands to each victim's perceived ability to pay.

active vulnerability exploitation1 week ago3 min

AI Cybersecurity Threats: How Russian Hackers Are Hijacking Autonomous Agents Through Router Flaws

A joint U.S. and allied advisory details how Russian state actors are exploiting legacy router vulnerabilities to steal network configurations and compromise AI-driven critical infrastructure systems.

active vulnerability exploitation1 week ago3 min

GodDamn Ransomware Hijacks Microsoft-Signed Driver to Kill Security Software with PoisonX BYOVD Attack

A deep technical breakdown of how the GodDamn ransomware group abused a Microsoft-signed kernel driver named PoisonX via Bring-Your-Own-Vulnerable-Driver (BYOVD) to disable endpoint protection before encrypting files—plus what defenders can actually do about it.

malware wiper threats1 week ago3 min

GigaWiper: The Modular Malware Letting Attackers Choose Their Own Destruction Path

A sophisticated malware implant that blends persistent backdoor access with multiple destructive payloads, allowing attackers to choose when and how to wipe systems — flipping the traditional wiper model on its head.

active vulnerability exploitation1 week ago4 min

Forg365: How AI Is Turning Microsoft 365 Phishing Into a Self-Sustaining Threat

Forg365 isn't just another phishing tool—it's a platform that automates credential theft, maintains persistent access, and adapts to defenses using AI. Here's how it works, and why it's scarier than anything we've seen before.

active vulnerability exploitation1 week ago3 min

Artificial Intelligence AI Cybersecurity: How Ransomware Groups Are Weaponizing Healthcare Hubs

A deep dive into the 35% surge in cyberattacks on healthcare service providers, analyzing real-world disruptions from Mississippi to Germany—and how AI-native security models can shut down supply chain ransomware loops.