Hijacked Hotel Wi-Fi Serves Fake Updates to Deploy CornFlake RAT in CaptiveCrunch Campaign
Microsoft has disclosed a cyber espionage campaign, tracked as CaptiveCrunch, that abuses hijacked hotel Wi-Fi captive portals to deliver a remote access…
Microsoft has disclosed a cyber espionage campaign, tracked as CaptiveCrunch, that abuses hijacked hotel Wi-Fi captive portals to deliver a remote access…
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
Seqrite, a cybersecurity firm, analyzed a January 2026 incident at a Ukrainian state hydrology agency involving the Zimbra zero-day. It attributed the…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
Security researcher Bert-Jan Pals analyzed roughly 3,000 live ClickFix payloads and presented findings at OrangeCon in early June, publishing details on June…
Canada's spy service, the Canadian Security Intelligence Service (CSIS), obtained a judge's permission to remotely clean botnet-infected devices on Canadian soil, marking…
Russian GRU-linked group whose tradecraft overlaps with CaptiveCrunch, but attribution was not made due to lack of direct technical linkage.
Ubiquiti routers are used in enterprise and home networks. They were targeted by APT28 for espionage relay operations.