Threat Intelligence — Page 21

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then hoovers up company documents from Microsoft SharePoint.

The Boring Breaches: How Small Config Mistakes Keep Owning Big Companies
This week's roundup of incidents has a common thread: not clever attacks, just loose settings, reused names, and untouched defaults doing enormous damage.

Your Business Is Already a Wartime Target. Here Is What to Do About It.
Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

Eight in Ten Corporate Servers Can Be Reached From Anywhere Inside the Same Network
A study of 54 trillion real-world network events found that most enterprise servers are wide open once an attacker gets past the front door, and many organisations have no clear idea how bad the exposure is.

Fake 7-Zip Downloads Are Quietly Turning Home PCs Into Criminal Middlemen
A group Infoblox calls Lurking Lizard has been running a rogue proxy service from 230+ lookalike sites since 2022, hiding the malware inside fake copies of the popular 7-Zip file compression tool.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets
A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

China-linked hackers hit university email servers to spy on physics and defence researchers
A group tracked as UNK_MassTraction is exploiting two Roundcube flaws at U.S. and Canadian universities to steal logins and plant backdoors, Proofpoint says.

Fake Pirated Software Ads Are Draining Passwords and Hijacking Computers to Mine Crypto
A campaign uncovered by Palo Alto Networks researchers is tricking people into downloading malware disguised as cracked software, stealing saved passwords while quietly running up victims' electricity bills.

Chinese Hacking Group Adds Three New Backdoors to Its Router Attack Kit
The group behind a long-running campaign targeting small office routers has quietly expanded its toolbox, giving it more ways to hide inside a victim's network.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Fake CAPTCHA Pages Are Stealing From Mexican Bank Customers
Elastic Security Labs is tracking a fraud campaign, dubbed REF6045, that tricks people into pasting a malicious command from a bogus 'prove you're human' page.

Blocking Phishing Emails Is Not Enough. Here Is Why the Attack Carries On Anyway.
Filtering a malicious email out of your inbox stops one message, not the criminal behind it. A live webinar on 8 July 2026 sets out what disrupting a phishing campaign at its source actually requires.

Convicted fraudsters are running a US startup offering $7 million for software exploits
IRIS C2 says it pays up to $7 million for zero-day exploits. Its owners are Jacob Wohl and Jack Burkman, best known for felony robocall convictions and a string of political dirty-tricks stunts.

Fake Tax Emails Are Planting Two Separate Spying Tools on Indian Taxpayers' Computers
A campaign timed to India's tax filing season tricks people into downloading what looks like an official government utility. Inside: two hidden programs that give criminals full remote control of the victim's machine.