Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
How a Developer Token Compromise Sparked a Global Pharma Data-Extortion Crisis
Novo Nordisk recent massive data breach: Investigating the impact of a developer token compromise on pharma data security, research, and manufacturing.
WordPress Compromise Fuels Vice Society Ransomware Delivery
A new malware campaign is leveraging compromised WordPress sites and 'ClickFix' tactics to deploy threats linked to the ransomware group Vice Society.
The JDY Botnet: A Malware Network Expanding Its Targeting Scope
The JDY botnet, previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts to include US military networks.
Rokarolla Android Trojan Levels Up to Full Device Control
The malware, spread via fake TikTok and Chrome downloads, demonstrates an evolution by combining banking fraud with surveillance and remote control capabilities.
Chinese Espionage Group UNC5221 Deploys Brickstorm Backdoor to Maintain Persistent Access to Microsoft 365 Environments
Analysis of UNC5221's Brickstorm backdoor campaign targeting Microsoft 365 environments, including technical details, attribution to Chinese APT groups (APT31, APT41), and defensive recommendations for enterprise security teams. Also covers related incidents including the Fortinet credential harvesting campaign affecting 30K devices.