Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
Phishing Compromises Sensitive Data for 1.4 Million Xsolis Records
A phishing attack on healthcare technology firm Xsolis exposed the sensitive data of nearly 1.4 million individuals, according to recent disclosures regarding a security incident from early 2026.
Stealthy 'CrashStealer' Malware Masquerades as Native Apple Utility to Hijack System Secrets
A detailed breakdown of the recently discovered macOS information-stealing malware, CrashStealer, which employs sophisticated techniques like Apple-notarized installers, impersonation of system tools, and client-side encryption to exfiltrate sensitive data.
Dutch Police Link Odido Breach to Dutch Hackers Using AI-Powered Vishing
The Dutch National Police report strong indications that local hackers used AI voice phishing to trick Odido staff into granting access, leading to a breach exposing 6.2 million customers — a campaign consistent with ShinyHunters' known tactics.
Salesforce OAuth Breach: Icarus Extortion Group Leaks Data from Dozens of Tech Firms via Klue
An OAuth token breach at Klue enabled the Icarus ransomware group to access Salesforce instances and Gong data across tech and cybersecurity firms, with customer contact details and sales records leaked on the dark web.
OFAC Sanctions Ransomware Enablers as AI Cybersecurity Threats Escalate
The Treasury Department's OFAC sanctioned First VPN Service (1VPNS), its Belarusian administrator Dmytro Rashevskyi, and cryptor seller Yegeniy Silayev for supplying infrastructure and malware-evasion tools that enabled ransomware attacks causing billions in losses to U.S. critical infrastructure — a direct response to the escalating artificial intelligence cybersecurity threats landscape.
AI Voice-Cloning Scams: Why Your Brain Can't Trust What It Hears
A University of Cincinnati study reveals that AI voice-cloning scams exploit vocal timbre—a biometric fingerprint—to bypass human skepticism. Scammers need less than 10 seconds of audio to clone a voice and override your critical judgment, making traditional verification essential for 365-day security.
Law Enforcement Unleashes Global Crackdown on Social Engineering Fraud
INTERPOL’s Operation First Light 2026 disrupts a vast fraud ecosystem, arresting over 5,800 suspects and recovering $293 million while exposing 142,000 victims across 97 nations.
Deceptive Voices: Extortion Gangs Pivot to Real-Time Passkey Vishing
A new extortion operation, Pink, is targeting multi-sector organizations by vishing users to register attacker-controlled Microsoft Entra passkeys. This article breaks down the operator-controlled phishing technique, the data exfiltration goal, and mitigation strategies.
Russia's Gamaredon APT Is Rewriting the Rules of Cyber Espionage in Ukraine
Russian state-sponsored cyber espionage group Gamaredon has significantly improved its tactics, techniques, and procedures (TTPs), becoming more effective in Ukraine cyber warfare. The group developed new PowerShell downloaders, advanced C2 infrastructure concealment using Cloudflare tunneling and dead drops, and USB-borne malware vectors. ESET tracked 35 spear-phishing campaigns against Ukraine in 2025, with the group collaborating with Turla APT to provide initial access for exploitation frameworks.
How AI Cybersecurity Threats Evolved: Mount Royal University Breach Shows Ransomware's New Playbook
Mount Royal University confirms hackers stole data from file storage systems and then deleted copies to disrupt recovery, following a breach claimed by the CMD Organization extortion group demanding 30 BTC ransom.
Inside ARToken: How Artificial Intelligence Powers the Next Generation of EvilTokens Phishing
A new phishing-as-a-service platform called ARToken appears to operate as an affiliate of the EvilTokens toolkit, revealing extensive capabilities for stealing Microsoft 365 tokens, establishing persistent access via Primary Refresh Tokens, and automating business email compromise operations with artificial intelligence.
When AI Writes Malware: How DeepSeek's Browser Ransomware Blueprint Changed the Threat Landscape
Check Point researchers uncovered a DeepSeek-generated malware sample that can be weaponized into browser-based ransomware with minimal effort, exposing a new frontier in artificial intelligence cybersecurity threats.