Threat Intelligence — Page 22

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

Fake DoorDash Calls Are Draining Delivery Drivers' Wallets
Criminals are posing as DoorDash support staff, tricking gig workers into handing over account details, then quietly emptying their earnings. One driver lost $21,000.

Chinese hackers hijack unpatched routers to build a stealth relay network
A group Cisco Talos calls UAT-7810 is breaking into Ruckus and ASUS routers to hide the tracks of other China-linked spying crews.

RedWing: The Rent-a-Fraud Kit Turning Android Phones Into Bank Robberies
A new Android malware sold on Telegram lets almost anyone hijack a victim's phone, steal banking logins and grab the codes meant to keep accounts safe.

Spanish police arrest suspected helper of pro-Russian hacking crews
The man in Palencia allegedly helped a Ukrainian hacker flee toward Russia and supported groups linked to attacks on U.S. water and energy sites.

A Windows Device ID Helped Trace an Alleged Scattered Spider Hacker to a Jewelry Heist
Federal prosecutors say a single hardware identifier tied a May 2025 intrusion at a luxury retailer to the online accounts of a 19-year-old.

Iran-Linked Hackers Hit Israeli IT Firms to Reach High-Value Targets
A group tied to Iran used a flexible, plug-in-style hacking toolkit to break into IT service providers in Israel, then moved through those companies to attack their clients.

Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign
A hacking group tied to China is breaking into Roundcube webmail systems at physics and engineering faculties across US and Canadian universities to steal login details.

German Court Case Exposes Telegram Network That Drugged and Filmed Women in Secret
A phone call from police told a Chinese student in Germany that her ex-boyfriend had taken nude photos of her while she slept. She was one of many victims of an organised online group.

Meet BusySnake: The Stealthy Malware Quietly Raiding Government Networks
A newly discovered hacking group is hitting government offices and critical services in three countries with a cunning piece of spy software. Here is what it does and who is at risk.

Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs
Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins
A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

Iranian Spies Target Israeli IT Firms With a New Custom Toolkit Called Cavern
A hacking crew tied to Iran's intelligence ministry is running a previously unseen command-and-control framework against Israeli government bodies and their IT suppliers.

The Weak Link This Week Wasn't Code. It Was Trust.
From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

North Korean Hackers Poisoned Over 100 Open Source Packages to Spy on Developers
A campaign called PolinRider has quietly corrupted legitimate software building blocks used by developers worldwide, planting tools that steal data and leave a hidden door open for attackers.