Topic: geographic targeting

  • ChatGPT Ads adds conversion bidding, geo exclusions, and bulk tools

    ChatGPT Ads adds conversion bidding, geo exclusions, and bulk tools

    ChatGPT Ads has expanded its advertising toolkit with features like conversion-optimized bidding (oCPC), average daily budgets, geographic exclusions, and mobile measurement integrations with AppsFlyer and Adjust. The updates address key gaps in the platform by improving optimization, measurement...

    Read More »
  • PlushDaemon Hackers Hijack Software Updates in Supply Chain Attacks

    PlushDaemon Hackers Hijack Software Updates in Supply Chain Attacks

    The China-linked hacking group PlushDaemon hijacks legitimate software update channels to deploy custom malware in global cyberespionage campaigns, targeting entities across multiple countries and sectors. Their attack involves compromising routers to install the EdgeStepper implant, which redire...

    Read More »
  • Chinese hackers deploy new Atlas RAT malware in European attacks

    Chinese hackers deploy new Atlas RAT malware in European attacks

    Chinese-speaking cybercrime group TA4922 has expanded from targeting East Asia to hitting organizations in Germany, Italy, the UK, and South Africa, deploying a new remote access trojan called Atlas RAT and several custom loaders. The group uses localized phishing lures via email and messaging ap...

    Read More »
  • Google ads and Claude.ai chats used to spread Mac malware

    Google ads and Claude.ai chats used to spread Mac malware

    Attackers are using Google Ads and Claude.ai shared chats in a malvertising campaign that directs users searching for a Mac download of Claude to malicious installation instructions, which prompt them to paste terminal commands that install malware. The malware uses Base64-encoded shell scripts a...

    Read More »
  • GentleKiller disables 400+ security processes across 48 products

    GentleKiller disables 400+ security processes across 48 products

    The ransomware gang Gentlemen uniquely develops and maintains an in-house framework called GentleKiller, a suite of EDR-killer tools directly supplied to affiliates, rather than delegating this task as other groups do. Gentlemen practices double extortion, targets a wider geographic spread beyond...

    Read More »
  • 42 Million Downloads: Google Apps Infected With Malware

    42 Million Downloads: Google Apps Infected With Malware

    Android malware surged by 67% in the past year, with 239 malicious apps downloaded 42 million times from the Google Play Store. The manufacturing and energy sectors were primary targets, with energy attacks rising 387%, and India led in malicious mobile traffic at 26%. IoT threats were dominated ...

    Read More »
  • Malicious Google Ads Evade Detection via Campaign Platform

    Malicious Google Ads Evade Detection via Campaign Platform

    A cybercrime service called 1Campaign uses advanced cloaking to bypass Google's ad security, showing malicious content only to targeted users while hiding it from security scanners. The service employs real-time visitor filtering based on geography and technical data, aggressively blocking high-r...

    Read More »
  • Notepad++ Supply Chain Attack: Details, Targets, and IoCs Revealed

    Notepad++ Supply Chain Attack: Details, Targets, and IoCs Revealed

    A Chinese state-sponsored group exploited the Notepad++ update mechanism to deliver malware in a targeted supply chain attack, focusing on high-value victims in Southeast Asia and beyond. The attack used malicious installers to deploy sophisticated backdoors like "Chrysalis" and Cobalt Strike, em...

    Read More »
  • Noisy Ransomware Uncovered a Long-Term Espionage Operation

    Noisy Ransomware Uncovered a Long-Term Espionage Operation

    A ransomware group's disruptive attack on two Russian companies inadvertently exposed a long-running, sophisticated cyber espionage operation, highlighting how a visible breach can mask a more insidious threat. The espionage group, QuietCrabs, used a stealthy multi-stage attack with unique malwar...

    Read More »
  • Cisco ASA Devices Face Surge in Network Scans

    Cisco ASA Devices Face Surge in Network Scans

    A significant surge in network scanning activity targeting Cisco ASA devices has been detected, with spikes in late August involving up to 25,000 unique IP addresses, suggesting potential vulnerability exploitation. The scanning was largely driven by a Brazilian botnet and focused heavily on the ...

    Read More »
  • Singapore Officials Impersonated in Sophisticated Investment Scam

    Singapore Officials Impersonated in Sophisticated Investment Scam

    Fraudsters impersonated Singaporean officials using verified Google Ads, fake news sites, and AI-generated deepfake videos to promote a fraudulent forex investment platform targeting local residents. The scam employed advanced evasion techniques like IP filtering and redirect domains, with victim...

    Read More »
  • Ransomware Attacks Rebound in July After Slow Q2

    Ransomware Attacks Rebound in July After Slow Q2

    Ransomware attacks surged 19% month-over-month in July 2026 to 799 claimed incidents, the second-highest total of the year, after a quiet April-June period. Finance was the hardest-hit sector with a 71% jump in attacks, followed by technology (62%), healthcare (46%), and education (44%), while US...

    Read More »
  • Qilin Ransomware Now Leads the Market

    Qilin Ransomware Now Leads the Market

    Qilin ransomware has become the dominant ransomware-as-a-service operation, commanding approximately 16% of the cybercriminal market share after filling the void left by disrupted groups like LockBit and RansomHub. Qilin's success is driven by high affiliate payouts, mature infrastructure, and th...

    Read More »
  • Malicious Rust Packages Target Web3 Developers

    Malicious Rust Packages Target Web3 Developers

    Malicious packages uploaded to the Rust registry (crates.io) impersonated legitimate developer tools, stealing cryptocurrency by executing a stealthy, multi-stage attack after being downloaded thousands of times. The malware specifically checked for and evaded a leading Chinese antivirus program,...

    Read More »
  • GlobalProtect VPN Portals Hit by 2.3 Million Cyber Scans

    GlobalProtect VPN Portals Hit by 2.3 Million Cyber Scans

    A fortyfold surge in malicious scanning targeting Palo Alto Networks GlobalProtect VPN portals began on November 14, 2025, marking the highest volume observed in the past 90 days, with 2.3 million sessions detected over five days. These coordinated scans focus on the login endpoint and are linked...

    Read More »
  • CISA Urges Immediate Patch for Samsung Spyware Zero-Day

    CISA Urges Immediate Patch for Samsung Spyware Zero-Day

    A critical vulnerability (CVE-2025-21042) in Samsung smartphones allows attackers to install LandFall spyware via manipulated DNG images sent through WhatsApp, affecting Android 13 and newer devices. The spyware, exploited since July 2024, can steal sensitive data like contacts, messages, and loc...

    Read More »
  • Ransomware Surge Intensifies the Battle for Cyber Defenders

    Ransomware Surge Intensifies the Battle for Cyber Defenders

    Ransomware attacks have surged dramatically, with a 20% increase in victims in the first half of the year, driven by the widespread Ransomware-as-a-Service model. The threat landscape is increasingly volatile, with 88 active groups and 35 new entities, making it difficult to track threats as atta...

    Read More »
  • DarkSword iOS Exploit Kit Hijacks iPhones with 3 Zero-Days

    DarkSword iOS Exploit Kit Hijacks iPhones with 3 Zero-Days

    A sophisticated new iPhone exploit kit called "DarkSword" has been discovered, using six vulnerabilities including three zero-days to hijack devices and steal extensive personal data from users on iOS 18.4 through 18.7. The kit has been deployed by multiple threat actors, including a suspected ...

    Read More »
  • GentleKiller Framework Bypasses Security Software

    GentleKiller Framework Bypasses Security Software

    The Gentlemen ransomware group uses a proprietary EDR killer suite called GentleKiller, which employs a bring-your-own-vulnerable-driver (BYOVD) technique to terminate over 400 processes across 48 security products at the kernel level. Unlike most ransomware operations, The Gentlemen develops and...

    Read More »
  • Microsoft Office Patch: Urgent Fix for Russian-State Hackers

    Microsoft Office Patch: Urgent Fix for Russian-State Hackers

    A Russian state-linked hacking group (APT28/Fancy Bear) rapidly exploited a critical Microsoft Office vulnerability (CVE-2026-21509) within two days of its patch, compromising diplomatic, transport, and defense organizations in multiple countries. The campaign was exceptionally stealthy, using en...

    Read More »