Threat Intelligence — Page 16

Photoreal news-editorial image, 16:9, full-frame edge-to-edge
Threat Intelligence

HollowGraph: The Spyware That Hides Its Orders in a Fake 2050 Calendar Invite

Researchers at Group-IB link the covert Microsoft 365 tool to Iran-nexus activity targeting Israeli organisations, with medium confidence.

4 min read
Full-frame photoreal news-editorial image of a dimly lit office desk at night, a laptop screen glowing with a blurred calendar grid showing dates far in the fut
Threat Intelligence

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050

A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

3 min read
Photoreal editorial scene of a dimly lit apartment workstation in a generic Eastern European city at night, multiple monitors glowing with abstract code and ter
Threat Intelligence

Before Anyone Reaches the Gate: Why Event Security Starts in the Digital World

A major concert, a championship, a political gathering: the real threats often take shape online, days or weeks before the first fan walks through the door.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of blue-lit rack equipment, one open rack door revealing exposed cabling, warm amber w
Threat Intelligence

A Week When Small Inputs Caused Big Damage

WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

3 min read
Photoreal editorial image, 16:9, full-frame edge to edge
Threat Intelligence

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine

Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

3 min read
Full-frame photoreal editorial image of a dimly lit university physics laboratory at night, glowing computer monitors showing generic webmail interface reflecti
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
Full-frame overhead photograph of a developer workstation at night, glowing terminal window on a matte black laptop screen showing generic package installation
Threat Intelligence

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems

Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

3 min read
Photoreal editorial shot of a dimly lit server room in a Russian government building, rows of network equipment with faint green status lights, a single monitor
Threat Intelligence

Hackers hijack Russian security tool ViPNet to spy on government agencies

A campaign called HelloNet has been slipping malicious files into ViPNet updates since May, hitting Russian ministries, energy firms and transport operators.

3 min read
Full-frame 16:9 photoreal editorial shot of a laptop screen in a dim office, showing a generic fake verification prompt with a highlighted keyboard shortcut ins
Threat Intelligence

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs

Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

3 min read
Aerial view, 16:9 framing, photoreal editorial style, a dense suburban neighbourhood at dusk with hundreds of softly glowing house windows, each window subtly e
Threat Intelligence

Moroccan Intelligence Insider Blows Whistle on Years of Pegasus Spyware Targeting

A former spy describes how Morocco reportedly used phone-hacking software since 2017 to surveil journalists, human rights workers, and foreign politicians, including cabinet ministers in Spain and officials in France.

3 min read
A digital illustration of a globe with highlighted countries targeted by cyber attacks
Threat Intelligence

Timor-Leste Police Arrest 314 People in Raids on Scam Call Centre Compounds

A country just 700 kilometres from Darwin has become the latest staging ground for international phone fraud, as police crack down on fortified compounds packed with laptops, SIM cards, and satellite internet equipment.

3 min read
Full-frame photoreal news-editorial image of a dimly lit developer workstation at night, glowing monitor showing rows of package manager install output in green
Threat Intelligence

Seven booby-trapped npm packages hit Vite developers with blockchain-controlled malware

Researchers at Checkmarx say the ViteVenom campaign hides its command server across four different cryptocurrency networks, making it unusually hard to shut down.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of humming racks, one open cabinet showing a glowing blue cable bundle, subtle red war
Threat Intelligence

Chinese Sub-Crew 'CylindricalCanine' Fingered for DigiCert Break-In

Researchers link the April 2026 intrusion at the certificate giant to an offshoot of a Chinese cybercrime group best known for chasing gambling firms.

3 min read
Full-frame photoreal editorial shot of a laptop screen showing an abstract national flag image rendered in soft focus, with faint hexadecimal code faintly visib
Threat Intelligence

North Korean Job-Interview Scam Hides Malware Inside Flag Images

Fake coding tests planted a four-stage stealer on developers' machines, with the payload smuggled inside SVG picture files.

3 min read
Extreme close-up of a glowing server rack illuminated in cold blue light, with reflected light patterns rippling across a dark polished floor, 16:9 framing, pho
Threat Intelligence

Ransomware Hits Naval Contractor, Lidl Discloses Data Breach, and Iran Tracks US Military Phones

A week of scattered but serious disclosures: a defence shipbuilder confirms a ransomware attack, a major supermarket chain notifies customers of stolen data, and new evidence suggests Iranian operatives tracked phones belonging to US military personnel.

3 min read
© 2026 Threat Vectr