Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
GodDamn Ransomware Hijacks Microsoft-Signed Driver to Kill Security Software with PoisonX BYOVD Attack
A deep technical breakdown of how the GodDamn ransomware group abused a Microsoft-signed kernel driver named PoisonX via Bring-Your-Own-Vulnerable-Driver (BYOVD) to disable endpoint protection before encrypting files—plus what defenders can actually do about it.
GigaWiper: The Modular Malware Letting Attackers Choose Their Own Destruction Path
A sophisticated malware implant that blends persistent backdoor access with multiple destructive payloads, allowing attackers to choose when and how to wipe systems — flipping the traditional wiper model on its head.
Forg365: How AI Is Turning Microsoft 365 Phishing Into a Self-Sustaining Threat
Forg365 isn't just another phishing tool—it's a platform that automates credential theft, maintains persistent access, and adapts to defenses using AI. Here's how it works, and why it's scarier than anything we've seen before.
Artificial Intelligence AI Cybersecurity: How Ransomware Groups Are Weaponizing Healthcare Hubs
A deep dive into the 35% surge in cyberattacks on healthcare service providers, analyzing real-world disruptions from Mississippi to Germany—and how AI-native security models can shut down supply chain ransomware loops.
Phishing Compromises Sensitive Data for 1.4 Million Xsolis Records
A phishing attack on healthcare technology firm Xsolis exposed the sensitive data of nearly 1.4 million individuals, according to recent disclosures regarding a security incident from early 2026.
Stealthy 'CrashStealer' Malware Masquerades as Native Apple Utility to Hijack System Secrets
A detailed breakdown of the recently discovered macOS information-stealing malware, CrashStealer, which employs sophisticated techniques like Apple-notarized installers, impersonation of system tools, and client-side encryption to exfiltrate sensitive data.
Dutch Police Link Odido Breach to Dutch Hackers Using AI-Powered Vishing
The Dutch National Police report strong indications that local hackers used AI voice phishing to trick Odido staff into granting access, leading to a breach exposing 6.2 million customers — a campaign consistent with ShinyHunters' known tactics.
Salesforce OAuth Breach: Icarus Extortion Group Leaks Data from Dozens of Tech Firms via Klue
An OAuth token breach at Klue enabled the Icarus ransomware group to access Salesforce instances and Gong data across tech and cybersecurity firms, with customer contact details and sales records leaked on the dark web.
OFAC Sanctions Ransomware Enablers as AI Cybersecurity Threats Escalate
The Treasury Department's OFAC sanctioned First VPN Service (1VPNS), its Belarusian administrator Dmytro Rashevskyi, and cryptor seller Yegeniy Silayev for supplying infrastructure and malware-evasion tools that enabled ransomware attacks causing billions in losses to U.S. critical infrastructure — a direct response to the escalating artificial intelligence cybersecurity threats landscape.
AI Voice-Cloning Scams: Why Your Brain Can't Trust What It Hears
A University of Cincinnati study reveals that AI voice-cloning scams exploit vocal timbre—a biometric fingerprint—to bypass human skepticism. Scammers need less than 10 seconds of audio to clone a voice and override your critical judgment, making traditional verification essential for 365-day security.
Law Enforcement Unleashes Global Crackdown on Social Engineering Fraud
INTERPOL’s Operation First Light 2026 disrupts a vast fraud ecosystem, arresting over 5,800 suspects and recovering $293 million while exposing 142,000 victims across 97 nations.
Deceptive Voices: Extortion Gangs Pivot to Real-Time Passkey Vishing
A new extortion operation, Pink, is targeting multi-sector organizations by vishing users to register attacker-controlled Microsoft Entra passkeys. This article breaks down the operator-controlled phishing technique, the data exfiltration goal, and mitigation strategies.