Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
UNC7005, also known as Storm-2945, is a suspected Russian threat actor identified in February 2026. It targets academia, diplomatic, and nonprofit personnel…
CornFlake RAT is a Go-based remote access trojan deployed via adversary-in-the-middle (AitM) attacks, often disguised as browser or OS updates. It performs…
Lumen Black Lotus Labs, the threat research arm of Lumen Technologies, tracked the CaptiveCrunch campaign and raised the possibility of MSP compromise,…
Black Lotus LabsCaptiveCrunchLumenLumen Black Lotus Labs
Microsoft has disclosed a cyber espionage campaign, tracked as CaptiveCrunch, that abuses hijacked hotel Wi-Fi captive portals to deliver a remote access…