Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
AI & Cybersecurity Threats: How CrashStealer Uses macOS Trust to Steal Your Wallets
CrashStealer exploits macOS’s built-in trust in system tools to steal crypto wallets and credentials—using Apple’s own infrastructure against users.
When Your AI Assistant Becomes a Ransomware Accelerant
How enterprise AI assistants and agents inherit identities and permissions that ransomware operators can exploit—and the six governance controls that actually reduce the risk.
Operation Olympus Blade: How Germany and the U.S. Brought Down the Kratos Phishing Empire
German and U.S. authorities dismantled Kratos, a phishing-as-a-service platform used by 1,800+ criminal customers to run 15,000 campaigns per month across 35 countries. More than 200 servers were seized and the developer arrested in Indonesia under Operation Olympus Blade.
OkoBot's 20-Payload Assault on Crypto Wallets Reveals a New Malware Playbook
A new malware framework called OkoBot is delivering over 20 distinct payloads in attacks targeting cryptocurrency wallet seed phrases, browser credentials, and sensitive data. The campaign, tracked by Kaspersky researchers, has been active for over a year and evolved from the TookPS infostealer. OkoBot reaches victims through ClickFix social engineering or malicious GitHub repositories masquerading as legitimate software tools.
Debian 13.6 and 12.15 Point Releases Mark End of 32-bit Support in Bookworm
Debian 13 'Trixie' and Debian 12 'Bookworm' received point releases in July 2026, with Bookworm's final update ending official 32-bit x86 support and Trixie consolidating its focus on modern architectures.
AI Cybersecurity Threats: How Coca-Cola’s Fairlife Ransomware Attack Exposes Operational Fragility
Coca-Cola’s Fairlife dairy shutdown reveals how ransomware now targets supply chains not for data, but to cripple physical operations — a new frontier in AI-driven corporate cyberattacks.
Small Businesses Are Getting Hit by Fake INTERPOL Ransomware — Here's What It Means for Artificial Intelligence Cybersecurity Threats
A new ransomware campaign uses phishing emails impersonating INTERPOL to trick small business employees into downloading malware disguised as evidence of criminal investigations, with attackers tailoring ransom demands to each victim's perceived ability to pay.
AI Cybersecurity Threats: How Russian Hackers Are Hijacking Autonomous Agents Through Router Flaws
A joint U.S. and allied advisory details how Russian state actors are exploiting legacy router vulnerabilities to steal network configurations and compromise AI-driven critical infrastructure systems.
GodDamn Ransomware Hijacks Microsoft-Signed Driver to Kill Security Software with PoisonX BYOVD Attack
A deep technical breakdown of how the GodDamn ransomware group abused a Microsoft-signed kernel driver named PoisonX via Bring-Your-Own-Vulnerable-Driver (BYOVD) to disable endpoint protection before encrypting files—plus what defenders can actually do about it.
GigaWiper: The Modular Malware Letting Attackers Choose Their Own Destruction Path
A sophisticated malware implant that blends persistent backdoor access with multiple destructive payloads, allowing attackers to choose when and how to wipe systems — flipping the traditional wiper model on its head.
Forg365: How AI Is Turning Microsoft 365 Phishing Into a Self-Sustaining Threat
Forg365 isn't just another phishing tool—it's a platform that automates credential theft, maintains persistent access, and adapts to defenses using AI. Here's how it works, and why it's scarier than anything we've seen before.
Artificial Intelligence AI Cybersecurity: How Ransomware Groups Are Weaponizing Healthcare Hubs
A deep dive into the 35% surge in cyberattacks on healthcare service providers, analyzing real-world disruptions from Mississippi to Germany—and how AI-native security models can shut down supply chain ransomware loops.