Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
Undocumented SprySOCKS Windows Backdoors Reveal FishMonger's Expanded Espionage Reach
FishMonger expands operations by deploying undocumented Windows variants of the SprySOCKS backdoor against government targets using kernel stealth and spooler abuse.
When Malware Wears a Halo: The New Era of Reputation Hijacking in Crypto Attacks
How attackers weaponize GitHub, YouTube, and VirusTotal to build false trust for crypto clipboard hijackers — and what defenders can do about it.
Ghost-Sender: How a Common Exchange Setup Lets Attackers Impersonate Anyone
A widespread Microsoft Exchange misconfiguration allows attackers to spoof any email address—bypassing SPF, DKIM, and DMARC protections—and evidence suggests the flaw is being actively exploited in the wild.
Autonomous Defenders: Reframing the Phishing Threat for AI-Native Operating Systems
With the rise of AI-native operating systems and autonomous agentic workflows, the frontline against social engineering cyberattacks is migrating away from the individual employee. Instead of training humans to spot deceptive lures, the security burden is shifting to the OS and AI assistants themselves, exposing new architectural vulnerabilities like prompt injection, dynamic skill hijacking, and untrusted execution contexts.
Legacy D-Link Routers Harnessed by Undocumented AryStinger Botnet for Malicious Proxy Operations
Qianxin researchers discovered AryStinger, a botnet exploiting CVE-2013-3307 and CVE-2016-5681 to turn outdated D-Link routers into proxy executors for scanning, DNS hijacking, and traffic interception.
The ChatGPT Outage Scam That Actually Lives Inside ChatGPT
Malicious actors exploit ChatGPT's content-sharing feature to host fake OpenAI outage pages, tricking users into downloading malware disguised as the ChatGPT desktop app in a campaign dubbed LLMShare.
No-Code Android RAT Lets Cybercriminals Build Custom Phishing Payloads for Device Takeover
BTMOB is a malware-as-a-service Android remote access trojan evolved from the SpySolr family, sold with an APK builder that lets buyers generate custom payloads and localized phishing lures without coding. Priced at $5,000 for a lifetime license plus monthly support, the RAT abuses Android Accessibility Services to escalate privileges and exfiltrate data, capture screenshots, record audio, and take full remote control of infected devices. First documented by Cyble in February 2025 and analyzed extensively by ESET in May 2026, BTMOB is primarily active across Brazil and Latin America but poses a growing regional threat.
Ransomware Ecosystem Realigns as European Markets Become Prime Targets
Ransomware gangs, once focused heavily on the US, are increasingly shifting their attention to European organizations and their broader supply chains, leveraging automation and exploiting new vulnerabilities in the region.
AI Built This Ransomware Toolkit—And It’s Learning Faster Than Your EDR
Sophos researchers uncovered a ransomware attack framework whose tool and payload development was assisted by Cursor and Claude Opus AI agents — generating nearly 80 evasion modules tested against Sophos, CrowdStrike, and Microsoft Defender EDR solutions.
Kodak Brings in Cyber Experts After Extortion Gang Says It Stole 2.2 Million Records
Kodak has confirmed a security breach and brought in external cybersecurity experts to investigate after the ShinyHunters extortion gang claimed responsibility for stealing over 2.2 million customer and corporate records, threatening to publish the data.
AryStinger Botnet Hijacks 4,000+ Routers as Malicious Proxy Network
Previously undocumented malware botnet AryStinger has compromised thousands of outdated D-Link routers worldwide, converting them into remotely controlled 'executors' for scanning, proxying, and command execution activities.
AI Voice-Cloning Scams: How Vocal Timbre Bypasses Human Skepticism
A new study reveals that AI voice-cloning scams are highly persuasive because they weaponize vocal timbre to bypass human critical skepticism and force compliance.