Threat Intelligence

The Fake IT Call and the Click That Opens the Door
Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

BraZetsu: The Python Toolkit Turning Hacked PCs Into Products for Sale
Researchers say the framework lets access brokers package infected Windows machines as ready-to-sell inventory on criminal marketplaces.

US Now Top Target in Global Phishing Campaign That Hijacks Remote Access Tools
A phishing operation first spotted using fake Canadian tax notices has spread to 46 countries, with nearly half of all sightings hitting American inboxes.

Hackers Are Hiding Malware Inside Node.js, and Windows Sees Nothing Wrong
Symantec says attackers have been abusing the legitimate Node.js runtime since February 2026 to slip past defences at governments, tech firms and hotels.

Pegasus Spyware Hit a Serbian Student Activist's iPhone Through a Silent iMessage Attack
Citizen Lab says a zero-click exploit planted NSO Group's Pegasus on the phone of a member of Serbia's student protest movement, with no tap or click required.

Three Australians Plead Guilty to Helping Overseas Scammers Strip Victims of Life Savings
The trio acted as local foot soldiers for foreign criminals running fake investment schemes that robbed Australians of millions of dollars.

Fake Software Download Sites Push Malware That Turns Off Windows Update
Microsoft says a long-running campaign is pushing rigged installers to Chinese-speaking users and staff at multinationals operating in China, disabling defences on the way in.

Chinese-Speaking Crew Slips Malicious Apache Modules Onto Brazilian .gov and .edu Sites
Check Point tracks the cluster as Gambling Goblin, with medium-confidence links to Chinese-speaking SEO-poisoning operators active since mid-2025.

Fake TV Streaming Ads on Facebook Pushed a New Android Banking Trojan to Spanish Users
StreamRat, spread through Meta ads that reached more than half a million EU accounts, hands attackers near-total control of the phone it lands on.

Russian Hackers Are Phishing EU Officials on WhatsApp and Signal
Eight serious attacks on European government staff have exposed a gap no one planned for: officials trusting consumer messaging apps with sensitive business.

Hackers Stole Nuclear Blueprints From the Philippines Using Flaws Fixed Two Years Ago
Researchers found nearly 1.2 gigabytes of stolen data on a server in Amsterdam, including reactor component databases, fuel records, and passport files belonging to Filipino government scientists.

Criminals Hid a Hacking Network Inside a Cryptocurrency Blockchain. Thirty-One Companies Got Caught.
A new campaign turns blockchain technology into an untraceable instruction relay, letting attackers redirect infected computers to a new server for less than a penny per update.

Russian man charged with infecting 80,000 freelancers through fake Excel attachments
Searzhudin Aktulaev allegedly used 255 fake accounts on a freelance work platform to spread TVRAT and DarkVNC remote-control malware between 2016 and 2017.

The US just seized the servers behind China's hacking-for-hire empire
A private Chinese company quietly ran shared attack tools for state hackers targeting NASA, the Federal Reserve, and US hospitals. The FBI just pulled the plug.

Police Hijack Sality Botnet's Own Network to Kill It Off
A four-country operation used the malware's peer-to-peer design against it, blocking infected computers from receiving fresh criminal payloads.