Threat Intelligence

Photoreal news-editorial overhead shot of a developer's dark wooden desk, glowing laptop screen showing an abstract green-on-black code repository interface wit
Threat Intelligence

Fake AI Tools on GitHub Are Hiding Malware, Researchers Find 7,600 Booby-Trapped Repos

A campaign called FakeGit is dressing up malicious code as AI helpers and developer tools to trick programmers into installing SmartLoader.

3 min read
Photoreal editorial shot of a laptop screen showing a generic software installer progress bar in a dim home office, warm desk lamp glow, a small out-of-focus Ru
Threat Intelligence

Fake Font Files Are Hiding Malware That Steals Passwords and Takes Over Windows PCs

A phishing campaign spotted since late March disguises malicious code as font files and runs it entirely in memory, making it nearly invisible to standard antivirus tools. FedEx and other familiar brands are being impersonated to get victims to open the door.

3 min read
Full-frame photoreal editorial shot of a dimly lit server rack in a small unmarked room, one door left ajar with light spilling into a corridor, cables slightly
Threat Intelligence

Careless malware crew leaves 1,048-file toolkit exposed on the open web

Rapid7 researchers grabbed the lot after the operators forgot to lock their delivery server. Inside: AI-written lures, dropper experiments and a live infostealer campaign hitting Windows users in Mexico.

3 min read
Photoreal news-editorial image, 16:9, full-frame edge-to-edge
Threat Intelligence

HollowGraph: The Spyware That Hides Its Orders in a Fake 2050 Calendar Invite

Researchers at Group-IB link the covert Microsoft 365 tool to Iran-nexus activity targeting Israeli organisations, with medium confidence.

4 min read
Full-frame photoreal news-editorial image of a dimly lit office desk at night, a laptop screen glowing with a blurred calendar grid showing dates far in the fut
Threat Intelligence

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050

A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

3 min read
Photoreal editorial scene of a dimly lit apartment workstation in a generic Eastern European city at night, multiple monitors glowing with abstract code and ter
Threat Intelligence

Before Anyone Reaches the Gate: Why Event Security Starts in the Digital World

A major concert, a championship, a political gathering: the real threats often take shape online, days or weeks before the first fan walks through the door.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of blue-lit rack equipment, one open rack door revealing exposed cabling, warm amber w
Threat Intelligence

A Week When Small Inputs Caused Big Damage

WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

3 min read
Photoreal editorial image, 16:9, full-frame edge to edge
Threat Intelligence

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine

Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

3 min read
Full-frame photoreal editorial image of a dimly lit university physics laboratory at night, glowing computer monitors showing generic webmail interface reflecti
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
Full-frame overhead photograph of a developer workstation at night, glowing terminal window on a matte black laptop screen showing generic package installation
Threat Intelligence

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems

Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

3 min read
Photoreal editorial shot of a dimly lit server room in a Russian government building, rows of network equipment with faint green status lights, a single monitor
Threat Intelligence

Hackers hijack Russian security tool ViPNet to spy on government agencies

A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

3 min read
Full-frame 16:9 photoreal editorial shot of a laptop screen in a dim office, showing a generic fake verification prompt with a highlighted keyboard shortcut ins
Threat Intelligence

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs

Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

3 min read
Aerial view, 16:9 framing, photoreal editorial style, a dense suburban neighbourhood at dusk with hundreds of softly glowing house windows, each window subtly e
Threat Intelligence

Moroccan Intelligence Insider Blows Whistle on Years of Pegasus Spyware Targeting

A former spy describes how Morocco reportedly used phone-hacking software since 2017 to surveil journalists, human rights workers, and foreign politicians, including cabinet ministers in Spain and officials in France.

3 min read
A digital illustration of a globe with highlighted countries targeted by cyber attacks
Threat Intelligence

Timor-Leste Police Arrest 314 People in Raids on Scam Call Centre Compounds

A country just 700 kilometres from Darwin has become the latest staging ground for international phone fraud, as police crack down on fortified compounds packed with laptops, SIM cards, and satellite internet equipment.

3 min read
Full-frame photoreal news-editorial image of a dimly lit developer workstation at night, glowing monitor showing rows of package manager install output in green
Threat Intelligence

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware

Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

3 min read
© 2026 Threat Vectr