Ransom Busters Scam Targets Ransomware Victims with Fake Data Deletion Services
A threat actor calling itself 'Ransom Busters' is targeting ransomware victims with a novel extortion scheme, offering to delete stolen data from…
A threat actor calling itself 'Ransom Busters' is targeting ransomware victims with a novel extortion scheme, offering to delete stolen data from…
Cybersecurity researchers have uncovered new components in the Cavern (aka Cav3rn) command-and-control (C2) framework, used by Iranian nation-state hackers in attacks targeting…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365…
Storm-2755 is a financially motivated threat cluster tracked by Microsoft, also known as Payroll Pirates. It hijacks employee accounts to reroute salary…
Storm-2657 is a threat actor tracked by Microsoft, associated with phishing campaigns targeting Microsoft 365 accounts. Documented since early 2025, it shares…
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Security researcher Håkon Måløy disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows hidden instructions in a document…
Iranian state-backed hacking group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to…
German and US law enforcement, in coordination with Indonesian authorities, have dismantled the infrastructure behind Kratos, a sophisticated phishing kit designed to…