Palo Alto Networks Unit 42 has uncovered the TinyRCT backdoor used by Chinese speaking threat actor CL STA 1062 to target government organizations and critical infrastructure across Southeast Asia.
Operation Endgame has disrupted the Amadey and StealC malware ecosystem, resulting in the takedown of 326 servers, 142 domains, recovery of 27 million stolen credentials, and restriction of more than $47 million in criminal cryptocurrency assets.
Google owned Mandiant reveals attackers exploited Cisco Catalyst SD WAN vulnerability CVE 2026 20245 as a zero day, using anti forensic techniques to gain root access and conceal malicious activity.
BeyondTrust outlines why identity security, privilege management, and assume breach strategies have become essential as enterprises face growing risks from AI driven attacks, machine identities, and trusted access abuse.
CISA has warned that attackers are actively exploiting the critical Lantronix EDS5000 vulnerability CVE 2025 67038 while researchers also report ongoing attacks targeting OpenWRT LuCI devices and UniFi OS flaws.
Researchers have uncovered FortiBleed, a large scale credential harvesting campaign targeting FortiGate firewalls and other internet facing systems, resulting in the collection of more than 110 million credentials worldwide.
Researchers have uncovered a new malware campaign using malicious Google Ads to distribute CastleStealer through a newly identified loader called OXLOADER, employing advanced obfuscation and evasion techniques.
Cybersecurity experts warn that AI powered social engineering campaigns are evolving beyond traditional phishing, prompting organizations to adopt proactive disruption strategies across multiple communication channels.
CISA has added the critical Joomla JCE vulnerability CVE 2026 48907 to its Known Exploited Vulnerabilities catalog following reports of active exploitation, while researchers also uncover large scale attacks targeting WordPress websites through supply chain compromises and malicious plugins.
Cybersecurity researchers have identified multiple ClickFix campaigns distributing malware loaders including BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, highlighting evolving attack techniques that leverage social engineering, compromised websites, and fake software updates.
Cybersecurity researchers uncover new Windows variants of China linked SprySOCKS malware featuring driver based stealth, TCP traffic diversion, and targeting organizations across multiple countries including Pakistan.
Palo Alto Networks confirms active exploitation of PAN OS vulnerability CVE 2026 0257 affecting GlobalProtect VPN portals, urging customers to review logs and mitigate risks.