An exposed attack server led Lexfo to three Microsoft 365 phishing operations using Evilginx and device code abuse to capture ...
The agentic operator documented as the first ransomware campaign run end-to-end by a large language model (LLM) has returned ...
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to ...
The Armored Likho APT is targeting government and electric power organizations with modular RATs and information stealers.
A single misconfigured server has exposed the complete toolkit of an active a three-actor phishing ecosystem. According to ...
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer ...
A threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in ...
An exposed WP-SHELLSTORM server revealed tools, logs, cloud credentials, and thousands of webshells used in a large website ...
According to Socket, malicious payment SDK packages on npm and PyPI are harvesting developer credentials and CI/CD ...
Discover how the Rogue Agent vulnerability in Google Dialogflow CX enabled persistent AI agent compromise, data exfiltration, ...
New Helix extortion group steals SharePoint data after compromising Microsoft 365 accounts through voice phishing and MFA ...