Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
Beijing's Dual-Vector Espionage Push Into Central Europe and East Asia
An examination of dual-method data exfiltration campaigns targeting government and public sector entities in Taiwan and the Czech Republic by Chinese nation-state actors.
Parallel Phishing Operations: How Malicious Zips Target Hospitality Firms in EU and Asia
Analysis of parallel phishing campaigns identified by Microsoft and Trend Micro that use malicious zip files to deliver malware through social engineering tactics targeting EU and Asian hospitality organizations.
Dynamic Malware Targeting: How Modern Phishing Campaigns Adapt to Victim Operating Systems
An analysis of how cybercriminals utilize browser User-Agent fingerprinting and traffic distribution system (TDS) infrastructure to serve OS-specific payloads, increasing phishing campaign efficiency and evasion capabilities.
No Longer the Exception: How the Ingenious 'ClickFix' Hook Became Cybercrime's New Standard
An in-depth analysis of the massive surge in 'ClickFix' clipboard-injection campaigns, tracking its graduation from a novel proof-of-concept to the dominant delivery method utilized by top-tier cybercriminals and nation-state advanced persistent threat (APT) groups.
The 2029 Mandate: How Microsoft Is Racing to Outrun Quantum Hackers
Microsoft accelerates its quantum-safe security roadmap, targeting 2029 for the transition of critical products to post-quantum cryptography (PQC) due to evolving quantum threats.
Operation Navy Ghost: Trojanized Telegram Bot Libraries Compromise Servers
A newly identified PyPI supply chain attack, Operation Navy Ghost, involves malicious forks of the Pyrogram library designed to gain persistent, remote control of Telegram bot infrastructure used by Python developers.
The Poisoned Tenant: How Threat Actors Use Fraudulent OpenAI Organizations to Harvest Corporate Secrets
Push Security has uncovered a "Poisoned Tenant" campaign in which threat actors create fraudulent OpenAI tenants impersonating legitimate companies, then invite employees via platform-originated notifications to trick them into submitting sensitive data through ChatGPT prompts and projects.
macOS ClickFix Attack Silently Mounts DMGs to Deploy AMOS Infostealer
Following the disruption of malicious code-signing provider Fox Tempest, the operators of the Lorem Ipsum malware pivoted from signed installers to compromised WordPress sites executing ClickFix browser lures, with analysts linking the activity to the Vice Society ransomware syndicate. Optimized for SEO and discoverability.
Djinn Stealer: How a SimpleHelp Flaw Unleashed AI Tool Targeting Malware
An investigation into the Djinn Stealer campaign: how attackers exploited CVE-2026-48558 in SimpleHelp to gain administrative access, deployed TaskWeaver payloads, and built a custom stealer targeting AI tool configs, cloud credentials, SSH keys, and developer secrets.
Targeting the Malware Assembly Line: How Coordinated Legal Tactics and AI Disrupt Cybercrime Infrastructure
A global coalition of tech firms and law enforcement agencies disrupted the shared command-and-control infrastructure of the Amadey and Stealc malware operations using a combination of artificial intelligence and organized-crime laws.
ClickFix Malware Campaign: New Analysis Reveals Lorem Ipsum Delivery Technique Linked to Vice Society Ransomware Group
New security research uncovers a sophisticated malware delivery campaign using Lorem Ipsum placeholders as the initial infection vector, with strong indicators linking the operation to the Vice Society ransomware and extortion group.
The Hunt for Protections Against the Next Generation of Adaptive AI Worm Malware
As cybersecurity experts brace for the emergence of adaptive agentic AI worm malware, industry leaders are racing to develop defenses capable of detecting and mitigating these intelligent threats before they can cause widespread damage on the scale of NotPetya or Stuxnet.