Cybersecurity researchers have uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the…
Cybersecurity researchers have uncovered a phishing-as-a-service (PhaaS) platform called AnonyMousKIT that uses AI voice agents to trick owners of stolen Apple devices…
Meta has announced new WhatsApp account security features, including support for multiple passkeys per account on both iOS and Android, enhancing phishing-resistant…
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Phishing has evolved from malicious content (Phishing 1.0) to malicious intent (Phishing 2.0) and now to AI-powered, multi-channel attacks (Phishing 3.0). In…
Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
Backdoor.TurnBroadcomC2 infrastructureCarbon Black
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
account takeoverAmazon Web ServicesAWS EC2Browser-in-the-Browser
Cybersecurity researchers have uncovered a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that hijacks Chromium web browsers to steal session data and…
Cybersecurity researchers at Group-IB have uncovered a new Android malware family called WindRelay that turns victims' smartphones into NFC relays for contactless…