Topic: threat actors
-
DarkSword iOS Exploit Kit Hijacks iPhones with 3 Zero-Days
A sophisticated new iPhone exploit kit called "DarkSword" has been discovered, using six vulnerabilities including three zero-days to hijack devices and steal extensive personal data from users on iOS 18.4 through 18.7. The kit has been deployed by multiple threat actors, including a suspected ...
Read More » -
Google Admits Fake Law Enforcement Account in Portal
Google confirmed that cybercriminals created a fake law enforcement account in its Law Enforcement Request System but deactivated it before any data was accessed or requests processed. The breach was claimed by a hacking group linked to known cybercrime organizations, which used social engineerin...
Read More » -
iOS Spyware 'Coruna' Powers Financial Crime Wave
The 'Coruna' exploit kit is a sophisticated iOS threat that evolved from a surveillance tool to a weapon for state-sponsored espionage and, most recently, large-scale financial crimes targeting cryptocurrency and sensitive data. It consolidates multiple exploit chains, leveraging both known and u...
Read More » -
Multiple Threat Groups Exploit Active WinRAR Vulnerability
A critical path traversal vulnerability (CVE-2025-6218) in WinRAR for Windows is being actively exploited, allowing attackers to execute arbitrary code by tricking users into opening malicious files. Multiple sophisticated threat groups, including Bitter APT and Gamaredon, are weaponizing the fla...
Read More » -
Beware: Hackers Hijack Calendar Subscriptions for Attacks
Hackers exploit digital calendar subscriptions by using deceptive systems to deliver malicious content like phishing links and malware through third-party feeds. BitSight's investigation revealed that expired or hijacked domains were used in large-scale campaigns, affecting millions of users thro...
Read More » -
ShinyHunters Unleash ShinySp1d3r Ransomware-as-a-Service
A new ransomware-as-a-service platform called ShinySp1d3r is being developed by threat actors linked to ShinyHunters and Scattered Spider, marking a strategic shift from using established gangs' encryptors to building their own bespoke operation. The ransomware features advanced capabilities incl...
Read More » -
How Hackers Weaponize Legitimate Tools for Cyberattacks
Threat actors increasingly use legitimate organizational tools through Living-off-the-Land (LotL) techniques, with 84% of modern cyberattacks exploiting trusted applications to bypass traditional defenses and evade detection. Attackers initiate breaches via social engineering, such as malicious V...
Read More » -
XWorm Malware Returns with Ransomware & 35+ Plugins
XWorm malware has evolved with ransomware capabilities and over 35 plugins, distributed by multiple threat actors through phishing campaigns after the original developer's departure. Initially a versatile remote access trojan, it steals sensitive data, enables DDoS attacks, and has been widely ad...
Read More » -
BRICKSTORM Returns: Why Your Enterprise Must Boost Cyber Defenses
The BRICKSTORM espionage campaign targets legal, technology, SaaS, and BPO firms to steal intellectual property and sensitive data, requiring immediate cybersecurity reassessment. Its stealthy infiltration of overlooked infrastructure like network appliances and virtualization platforms allows at...
Read More » -
Google Warns of New AI-Powered Malware Threat
Google has identified a new generation of AI-powered malware, such as PromptFlux and PromptSteal, that dynamically rewrites its own code to evade detection, using modules like the 'Thinking Robot' to query AI models for new evasion tactics. State-sponsored threat actors from China, Iran, and Nort...
Read More » -
Claude Code Leak Spreads Infostealer Malware via GitHub
Cybercriminals are exploiting interest in the leaked Claude Code by using fraudulent GitHub repositories to distribute the Vidar infostealer malware. The campaign uses social engineering, tricking developers with convincing fake repositories to execute malware that harvests sensitive data like cr...
Read More » -
Telus Digital Confirms Major Data Breach After Hacker Claims
Telus Digital, a Canadian telecom BPO, confirmed a major data breach by the ShinyHunters group, who allegedly stole nearly a petabyte of sensitive client and consumer data over several months. The attackers reportedly used credentials from a prior breach at Salesloft Drift to access Telus systems...
Read More » -
CISA Urges iOS Patch to Stop Crypto-Theft Exploits
U.S. authorities have issued an urgent alert for iPhone users to update their devices, as federal agencies are mandated to patch three actively exploited iOS vulnerabilities used for cryptocurrency theft and espionage. The sophisticated Coruna exploit kit leverages multiple iOS weaknesses to bypa...
Read More » -
ShinyHunters' New MFA Bypass Fuels Data Theft
A sophisticated social engineering campaign is bypassing multi-factor authentication (MFA) using synchronized voice and email phishing attacks, successfully targeting major companies like Panera Bread and Match Group. Attackers, linked to groups like UNC6661 and ShinyHunters, use IT impersonation...
Read More » -
Salesforce Users at Risk From Gainsight Supply Chain Attack
A cybersecurity incident involving Gainsight's Salesforce connector potentially exposed customer data, prompting Salesforce to revoke access and remove Gainsight apps from AppExchange due to unusual activity. The attack, claimed by the Scattered Spider-ShinyHunters-Lapsus$ group, may lead to a de...
Read More » -
Brightspeed Probes Data Breach Claims
Brightspeed, a major US fiber broadband provider, is investigating a potential data breach after the Crimson Collective cybercriminal group claimed responsibility for stealing sensitive customer information. The hackers allege the stolen data includes extensive personal and financial records for ...
Read More » -
CISA: Hackers Actively Exploiting WatchGuard Firewall Flaw
A critical security flaw (CVE-2025-9242) in WatchGuard Firebox firewalls is being actively exploited, prompting CISA to issue an urgent patch directive to federal agencies. The vulnerability stems from an out-of-bounds write weakness in Fireware OS, affecting over 54,000 devices globally, with fe...
Read More » -
Wynn Resorts Employee Data Breached Following Extortion Threat
Wynn Resorts suffered a data breach by the ShinyHunters hacking group, compromising employee data including Social Security numbers, but guest operations were unaffected. The group threatened to leak the data and demanded contact, with the incident listing later removed, though it's unclear if a ...
Read More » -
Coinbase Breach: Insider Leaked Support Tool Screenshots
A Coinbase contractor improperly accessed the personal data of approximately 30 customers last year, a separate incident from a prior breach, prompting user notifications and regulatory reporting. The breach highlights a broader trend where cybercriminals target Business Process Outsourcing (BPO)...
Read More » -
Olympics Cyber Threats: Phishing and Spoofed Sites Still Top Risks
Cybersecurity experts warn that phishing attacks and spoofed websites remain the primary digital threats for the 2026 Winter Games, attracting a wide range of malicious actors due to the event's global scale and high incentive for disruption. Historical analysis shows past Olympic events faced si...
Read More »