Threat Intelligence

Fake AI Tools on GitHub Are Hiding Malware, Researchers Find 7,600 Booby-Trapped Repos
A campaign called FakeGit is dressing up malicious code as AI helpers and developer tools to trick programmers into installing SmartLoader.

Fake Font Files Are Hiding Malware That Steals Passwords and Takes Over Windows PCs
A phishing campaign spotted since late March disguises malicious code as font files and runs it entirely in memory, making it nearly invisible to standard antivirus tools. FedEx and other familiar brands are being impersonated to get victims to open the door.

Careless malware crew leaves 1,048-file toolkit exposed on the open web
Rapid7 researchers grabbed the lot after the operators forgot to lock their delivery server. Inside: AI-written lures, dropper experiments and a live infostealer campaign hitting Windows users in Mexico.

HollowGraph: The Spyware That Hides Its Orders in a Fake 2050 Calendar Invite
Researchers at Group-IB link the covert Microsoft 365 tool to Iran-nexus activity targeting Israeli organisations, with medium confidence.

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050
A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

Before Anyone Reaches the Gate: Why Event Security Starts in the Digital World
A major concert, a championship, a political gathering: the real threats often take shape online, days or weeks before the first fan walks through the door.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine
Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes
Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems
Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

Hackers hijack Russian security tool ViPNet to spy on government agencies
A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs
Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

Moroccan Intelligence Insider Blows Whistle on Years of Pegasus Spyware Targeting
A former spy describes how Morocco reportedly used phone-hacking software since 2017 to surveil journalists, human rights workers, and foreign politicians, including cabinet ministers in Spain and officials in France.

Timor-Leste Police Arrest 314 People in Raids on Scam Call Centre Compounds
A country just 700 kilometres from Darwin has become the latest staging ground for international phone fraud, as police crack down on fortified compounds packed with laptops, SIM cards, and satellite internet equipment.

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware
Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.