ProBackend
Threats & Attacks

Threats & Attacks

Ransomware, malware, phishing and the actors behind them.

cloud security incidents1 week ago4 min

Phishing Compromises Sensitive Data for 1.4 Million Xsolis Records

A phishing attack on healthcare technology firm Xsolis exposed the sensitive data of nearly 1.4 million individuals, according to recent disclosures regarding a security incident from early 2026.

ai macos malware1 week ago5 min

Stealthy 'CrashStealer' Malware Masquerades as Native Apple Utility to Hijack System Secrets

A detailed breakdown of the recently discovered macOS information-stealing malware, CrashStealer, which employs sophisticated techniques like Apple-notarized installers, impersonation of system tools, and client-side encryption to exfiltrate sensitive data.

cybersecurity incidents1 week ago6 min

Dutch Police Link Odido Breach to Dutch Hackers Using AI-Powered Vishing

The Dutch National Police report strong indications that local hackers used AI voice phishing to trick Odido staff into granting access, leading to a breach exposing 6.2 million customers — a campaign consistent with ShinyHunters' known tactics.

salesforce oauth integration breaches2 weeks ago4 min

Salesforce OAuth Breach: Icarus Extortion Group Leaks Data from Dozens of Tech Firms via Klue

An OAuth token breach at Klue enabled the Icarus ransomware group to access Salesforce instances and Gong data across tech and cybersecurity firms, with customer contact details and sales records leaked on the dark web.

active vulnerability exploitation2 weeks ago7 min

OFAC Sanctions Ransomware Enablers as AI Cybersecurity Threats Escalate

The Treasury Department's OFAC sanctioned First VPN Service (1VPNS), its Belarusian administrator Dmytro Rashevskyi, and cryptor seller Yegeniy Silayev for supplying infrastructure and malware-evasion tools that enabled ransomware attacks causing billions in losses to U.S. critical infrastructure — a direct response to the escalating artificial intelligence cybersecurity threats landscape.

cloud security incidents2 weeks ago4 min

AI Voice-Cloning Scams: Why Your Brain Can't Trust What It Hears

A University of Cincinnati study reveals that AI voice-cloning scams exploit vocal timbre—a biometric fingerprint—to bypass human skepticism. Scammers need less than 10 seconds of audio to clone a voice and override your critical judgment, making traditional verification essential for 365-day security.

cloud security incidents2 weeks ago5 min

Law Enforcement Unleashes Global Crackdown on Social Engineering Fraud

INTERPOL’s Operation First Light 2026 disrupts a vast fraud ecosystem, arresting over 5,800 suspects and recovering $293 million while exposing 142,000 victims across 97 nations.

collaboration vishing impersonation2 weeks ago3 min

Deceptive Voices: Extortion Gangs Pivot to Real-Time Passkey Vishing

A new extortion operation, Pink, is targeting multi-sector organizations by vishing users to register attacker-controlled Microsoft Entra passkeys. This article breaks down the operator-controlled phishing technique, the data exfiltration goal, and mitigation strategies.

active vulnerability exploitation2 weeks ago8 min

Russia's Gamaredon APT Is Rewriting the Rules of Cyber Espionage in Ukraine

Russian state-sponsored cyber espionage group Gamaredon has significantly improved its tactics, techniques, and procedures (TTPs), becoming more effective in Ukraine cyber warfare. The group developed new PowerShell downloaders, advanced C2 infrastructure concealment using Cloudflare tunneling and dead drops, and USB-borne malware vectors. ESET tracked 35 spear-phishing campaigns against Ukraine in 2025, with the group collaborating with Turla APT to provide initial access for exploitation frameworks.

active vulnerability exploitation2 weeks ago3 min

How AI Cybersecurity Threats Evolved: Mount Royal University Breach Shows Ransomware's New Playbook

Mount Royal University confirms hackers stole data from file storage systems and then deleted copies to disrupt recovery, following a breach claimed by the CMD Organization extortion group demanding 30 BTC ransom.

active vulnerability exploitation2 weeks ago4 min

Inside ARToken: How Artificial Intelligence Powers the Next Generation of EvilTokens Phishing

A new phishing-as-a-service platform called ARToken appears to operate as an affiliate of the EvilTokens toolkit, revealing extensive capabilities for stealing Microsoft 365 tokens, establishing persistent access via Primary Refresh Tokens, and automating business email compromise operations with artificial intelligence.

active vulnerability exploitation2 weeks ago5 min

When AI Writes Malware: How DeepSeek's Browser Ransomware Blueprint Changed the Threat Landscape

Check Point researchers uncovered a DeepSeek-generated malware sample that can be weaponized into browser-based ransomware with minimal effort, exposing a new frontier in artificial intelligence cybersecurity threats.