FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays
TL;DR: Cookie protections have made traditional session theft harder, but they do not eliminate the value of an authenticated browser session to adve…
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.
In Parts 1 and 2, every command targeted port 9200. Every exploit, every reconnaissance query, every credential test hit the Elasticsearch REST API d…
Sable Squirrel spends millions on expired domains to deliver illegal gambling, streaming, RAT malware, and ransomware in a massive cybercriminal ente…
Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware. Infob…
Read also: Ukraine shuts down over 90 fraudulent call centers; US police officers arrested over misuse of surveillance data; and more.
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, a…
Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time t…
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate chec…
China-based hackers-for-hire group is breaking into government ministries across the Middle East and Asia from the same control panel it uses to run …
A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battl…
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interes…
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals …
More than a quarter of stolen funds are gone within fifteen minutes of the fraudulent transfer. That number ends the case-file era — and points to wh…
Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom pro…
VulnCheck's Initial Access Intelligence team details an OS command injection in FileRun's thumbnail generation, where the extractors pass user-contro…