AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee…
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and…
Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national…
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment…
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy…
arXiv:2609.23405v1 Announce Type: new Abstract: Address-Poisoning Transfer (APT) is a prevalent blockchain phishing scam in which a scammer poisons a victim's address book by generating a transfer…
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
October is Cybersecurity Awareness Month, a global effort to promote online safety and digital security. Launched in 2024 by the National Cybersecurity Alliance and the Cybersecurity and…
Dominican Republic Leak, Celestial Malware, Money Network Sale, CVV Auction, and US VPN Access SOCRadar Dark Web Team identified several new underground posts, including an alleged Dominican Republic…
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex…
A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based…
Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the…
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know…
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address…
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company Ambry Genetics Corporation…
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to…
EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight September 17, 2026 Jean-Pierre Mouton BLOG 15 min. This is our deep dive into how we tracked cybercriminals…
AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with…