Threat Intelligence — Page 18

Photoreal editorial shot of a laptop screen showing a generic software installer progress bar in a dim home office, warm desk lamp glow, a small out-of-focus Ru
Threat Intelligence

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers

UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.

4 min read
A high-resolution 16:9 editorial photograph of a dimly lit developer workstation at night, multiple monitors glowing with terminal windows and code editors, a m
Threat Intelligence

How a Spanish Cybercrime Gang Stole €140 Million and Almost Got Away With It

Spanish police, working with partners across Europe and beyond, dismantled a fraud network that used fake boss emails, phony investment sites, and nearly a thousand bank accounts to steal the equivalent of $161 million from ordinary people and businesses.

3 min read
Full-frame photoreal editorial image of a cluttered desk with a small home Wi-Fi router glowing faintly, tangled ethernet cables, a laptop screen showing lines
Threat Intelligence

A Botnet Author Asked an AI for Malware. The AI Left the Warning Label On.

Researchers found TuxBot v3 Evolution, a new IoT botnet whose creator appears to have copy-pasted AI-generated code, safety disclaimer and all.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a small metallic cryptocurrency hardware wallet plugged into a laptop USB port on a dark wooden desk, faint
Threat Intelligence

OkoBot Malware Hijacks Ledger and Trezor Apps to Steal Crypto Recovery Phrases

A Windows malware framework active since April 2025 waits for victims to open their hardware wallet software, then fakes a prompt for the 24 words that unlock everything.

3 min read
Full-frame overhead view of a developer's dark desk, glowing keyboard, terminal windows on a monitor showing package installation progress with faint red warnin
Threat Intelligence

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week

Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

4 min read
Photoreal news-editorial overhead view of a dimly lit operations center with multiple monitors showing abstract network maps of the Asia-Pacific region, glowing
Threat Intelligence

US Charges Three Russians for Running 'Bulletproof' Hosting That Powered Ransomware and Phishing Attacks on 42 American Organisations

A grand jury indictment unsealed this week names Aleksandr Volosovik, Kirill Zatolokin, and Yulia Pankova as the operators behind two companies that rented out hidden, hard-to-shut-down internet infrastructure to criminals worldwide.

3 min read
A digital shield representing cybersecurity with streaming media icons
Threat Intelligence

When 80,000 fans log on at once: the cybersecurity headache facing 2026 World Cup stadiums

Tens of thousands of personal phones on one network, payment terminals, body cameras on referees, and sensors inside match balls. Stadium IT teams face a security puzzle that has no clean solution.

3 min read
Photoreal editorial shot of a developer's darkened desk, an open laptop showing rows of green package names in a terminal, one line highlighted in red, faint bl
Threat Intelligence

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines

Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

3 min read
A dimly lit government briefing room at night, a lone lectern illuminated by a single overhead light, Union Jack flag partially visible in the background, drama
Threat Intelligence

EU, UK and France Sanction Russia Over Coordinated Hacking and Sabotage Campaign Across Europe

France summoned Russia's ambassador on Monday after European governments accused the FSB, Russia's main intelligence service, of running a campaign to spy on and disrupt critical infrastructure across more than a dozen countries.

3 min read
Photoreal editorial image, 16:9, full-frame edge-to-edge composition
Threat Intelligence

Spanish police dismantle €140 million fraud ring that drained company bank accounts

Four arrests across Spain, Portugal and Panama close down a laundering network that pushed nearly €100 million through 800 bank accounts, much of it stolen through fake CEO emails.

4 min read
Full-frame photoreal editorial shot of a laptop screen showing a generic code-hosting website layout with a prominent green download button, glowing faintly, re
Threat Intelligence

Fake GitHub Pages Impersonate 292 Real Brands to Push Password-Stealing Malware

A Russian-speaking crew built hundreds of lookalike project pages for security tools, wallets and dev software. One click on 'Download Secure Content' handed over browser passwords, crypto wallets and chat sessions.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a cluttered office desk at night, glowing keyboard, several browser windows reflected on a dark monitor, a ha
Threat Intelligence

Ransomware Gang Claims Bosch and Synopsys Hacks. Synopsys Says It Sees Nothing.

A criminal group called D1R says it stole sensitive data from two major companies and will publish it unless it gets paid. One of those companies is pushing back.

3 min read
Full-frame photoreal editorial shot of a modern Windows laptop on a dark desk, screen glowing green with a generic abstract graphics-driver style installer wind
Threat Intelligence

LabubaRAT: New Rust Malware Poses as NVIDIA Software to Sneak Onto Windows PCs

Researchers at Blackpoint Cyber say the newly named tool gives attackers a quiet, reusable way back into infected machines.

3 min read
Full-frame edge-to-edge photoreal shot of a darkened office monitor displaying a generic fake CAPTCHA verification page reflected in a glass surface, with faint
Threat Intelligence

ClickFix: The Fake Error Pop-Up That Tricks You Into Hacking Yourself

A scam that launched in 2024 has grown into a thriving criminal marketplace. Researchers say standard antivirus tools are missing it almost entirely, and they have built a new detection method to fill the gap.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Threat Intelligence

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon

Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.

3 min read
© 2026 Threat Vectr