Threat Intelligence — Page 5

From Prison to Cybersecurity Advocate: The Jesse McGraw Story
Once known online as GhostExodus, Jesse McGraw hacked hospital systems as a teenager, went to federal prison, and came out the other side trying to help defenders. His story is a rare look at what radicalises young hackers and what, sometimes, pulls them back.

Five Londoners Charged Over Russian Coms, the Scam-Call Platform Behind 1.8 Million Fake Calls
The UK's National Crime Agency says the platform helped criminals impersonate banks and police, costing an estimated 170,000 victims tens of millions of pounds.

Attacker Uses AI-Written PowerShell Script to Map a Company's Network
Researchers say an unknown intruder ran a script that looks machine-generated to catalogue users, computers and domain controllers inside a Windows network.

Russian FSB hackers are quietly hijacking routers at hospitals, power firms and banks, nine countries warn
A joint advisory from the US, UK, Australia and six allies names FSB Centre 16 as the group scanning the internet for routers with weak passwords and old Cisco flaws.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

RedHook Android Malware Turns Phones Into Their Own Debugging Tool
A new build of the RedHook trojan tricks Android users into switching on Wireless Debugging, then quietly promotes itself to a privilege level normal apps can never reach.

Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say
A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

Booby-trapped jscrambler npm release runs infostealer the moment you install it
Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm
A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

DHS Database Breached, Adobe Speeds Up Patches, and Canada Shuts Down Ransomware Groups
A busy week in security news brought a breach at a US government agency, a faster fix schedule from a major software maker, and a Canadian crackdown on ransomware criminals. Here is what you need to know.

Silver Fox's New MODBEACON Trojan Hides Inside Fake Software Installers
The China-linked group is using booby-trapped downloads to plant a Rust-built remote-control tool that talks to its handlers over encrypted channels.

Cybercrime Crew Leaves Its Own Server Wide Open, Exposing 1.4 Million Website Target List
A misconfigured server ran unprotected for three weeks, handing researchers a rare look inside a mass WordPress hacking operation now tracked as WP-SHELLSTORM.

GigaWiper: The Swiss Army Knife of Destructive Malware
A newly named piece of malicious software has been quietly spreading for over eight months, combining spying tools, file destroyers, and fake-ransomware tricks inside a single package.

Microsoft Exposes GigaWiper, a New Malware That Spies on Victims Before Destroying Them
A newly discovered backdoor called GigaWiper quietly watches infected computers for months, then wipes or encrypts everything on command, with no way to recover the data.