Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
From Hackers to Hives: Qihoo 360 Deploys Multi-Agent Swarms to Challenge American AI Dominance
As U.S. export restrictions block international access to Anthropic's Mythos, Chinese cybersecurity veteran Qihoo 360 has unveiled 'Tulongfeng,' an autonomous multi-agent vulnerability-discovery swarm designed to bypass China's trailing LLM capabilities and secure technical parity.
Krisp Unveils Unified Voice AI Platform with Full Call-Center Governance and Real-Time Fraud Protection
Krisp launches expanded voice AI capabilities for contact centers, combining speech analytics, real-time agent assistance, and voice security to enforce compliance across 100% of voice interactions while detecting synthetic caller fraud live.
Savi Security Addresses AI-Powered Fraud with New Consumer Protection App
Savi Security has raised $7 million in seed funding and is launching its iOS and Android app, designed to protect consumers from sophisticated AI-generated scams like voice cloning and phishing.
Teams Screen Sharing Abused in Cross-Tenant Vishing Campaigns to Deliver EtherRAT
A forensic analysis of a social engineering campaign targeting Microsoft Teams, where attackers pose as IT support, request screen control, and install EtherRAT via a Node.js runtime installer.
Inside the New Wave of Hospitality-Targeted Phishing Campaigns
Recent phishing campaigns targeting the hospitality sector across Europe and Asia leverage sophisticated social engineering and persistence tactics, focusing on long-term remote access rather than immediate ransomware deployment.
When a Ransomware Gang Turns Out to Be an LLM Running on Its Own
Researchers at Sysdig identified JadePuffer as the first known ransomware campaign conducted entirely by a large language model agent — from initial access via Langflow's CVE-2025-3248 through credential theft, lateral movement to Alibaba Nacos, and encryption of 1,342 service configurations — demonstrating the arrival of autonomous agentic threat actors.
FBI and Google Dismantle NetNut: How a 2-Million-Device Proxy Botnet Was Taken Down
A coordinated operation by the FBI, Google Threat Intelligence Group, Lumen Technologies, and Shadowserver has seized hundreds of NetNut domains and disrupted the Popa botnet — a residential proxy network built on at least 2 million compromised Android devices including smart TVs and streaming boxes, used by hundreds of threat actors for cybercrime and espionage.
PAMStealer Sneaks Into macOS by Hijacking the Login System Itself
A new macOS malware called PAMStealer uses clever techniques to bypass authentication and stay hidden on infected Macs, according to researchers.
Your AI Coding Assistant Just Ran Malware. You Didn't Even Notice.
A clean GitHub repo tricked Claude Code into fetching and executing a reverse shell via a DNS TXT record — no malicious code, no flags, no human approval. Here’s how it worked, and why your security tools are useless against it.
How a Phishing Email Broke Xsolis—and Exposed 1.4 Million Patients
A targeted phishing attack on Xsolis compromised the Dragonfly platform, exposing names, SSNs, and medical records of 1.39 million patients; the HIPAA business associate’s delayed response and lack of transparency left patients vulnerable.
Pastejacking: How Social Engineering Became the Default Malware Delivery Method
Once a rare exploit, pastejacking via ClickFix now drives nearly half of all initial-access attacks, leveraging API-driven payloads, macOS bypasses, and fileless execution to turn user trust into a weaponized vector.
The OS Trap: How Phishing Campaigns Use User-Agent Fingerprinting to Serve the Right Malware for Your Device
Modern phishing kits leverage browser telemetry to deliver OS-specific payloads like FleetDeck, Tiflux RAT, and LummaC2 infostealers—maximizing compromise rates by avoiding wasted clicks on unsupported platforms.