Security · Top stories
New Helix vishing group targets SharePoint for data theft
A new cybercriminal group named Helix is using vishing and MFA abuse to steal data from SharePoint environments. The group impersonates employees to trick victims into giving up sensitive information, leading to data extortion practices similar to those of previous groups like ShinyHunters and BlackFile.
Global Fraud Operation Arrests 5,811, Targets Social Engineering Scams
A global anti-fraud operation led to the arrest of 5,811 individuals across 97 countries and the interception of $293 million in illicit assets. This effort highlights the rising threat from social engineering scams, which have increasingly impacted individuals, businesses, and governments worldwide.
EU files court cases against four countries over cybersecurity law delays
The European Commission has initiated legal action against Ireland, Spain, France, and the Netherlands for not implementing the NIS2 Directive, which sets standards for cybersecurity across critical sectors. The action signals the EU's commitment to bolster cybersecurity, particularly as threats to infrastructure grow.
GodDamn Ransomware Employs PoisonX Driver to Bypass Security Defenses
A new ransomware family named GodDamn uses the PoisonX kernel driver to disable endpoint security software, enhancing its evasion capabilities. This malware, traced back to previous variants, poses a significant threat due to its sophisticated attack methods and reliance on signed drivers.
Global anti-fraud operation leads to 5,800 arrests and $293M seized
Law enforcement agencies arrested 5,811 suspects and seized $293 million in a worldwide anti-fraud initiative named "Operation First Light 2026." This operation targeted various forms of social engineering fraud and money laundering, and revealed over 142,000 victims across 97 countries.
Lurking Lizard Uses Fake 7-Zip Installers for Malicious Proxy Operations
Cybersecurity researchers identified Lurking Lizard, a malicious entity using fake 7-Zip installers to recruit devices into a residential proxy network. Operating since at least August 2022, it exploits expired domains and other major proxy providers to generate traffic and evade detection.
Greek victims sue Intellexa over Predator spyware allegations
Eight Greek victims of Predator spyware have filed a lawsuit against Intellexa and 13 affiliated individuals, seeking approximately €7.6 million in damages. This case aims to address the violations of privacy and data confidentiality resulting from the unauthorized surveillance activities tied to the spyware, which have already led to significant political repercussions in Greece.
Malicious SDKs on npm and PyPI Target Paysafe, Skrill, and Neteller Users
At least 17 malicious packages on npm and PyPI masqueraded as legitimate Paysafe, Skrill, and Neteller SDKs, deploying credential-stealing malware. This attack could compromise sensitive user data, impacting developers and businesses relying on these payment services.
IBM and Red Hat launch Lightwell to protect open-source from AI attacks
IBM and Red Hat launched Lightwell, a service aimed at defending open-source software from AI-driven attacks. The initiative includes two offerings: Lightwell Network and Lightwell Clearinghouse Premier, both designed to secure open-source components at scale, addressing vulnerabilities identified by AI.
Taiwan charges two businessmen in Chinese espionage scheme
Taiwan has charged two businessmen for aiding Chinese hackers in an espionage campaign targeting political and journalistic figures. The duo reportedly provided accounts used to impersonate journalists, facilitating malware deployment against Taiwanese individuals.
New Ghost Phishing Technique Targets Microsoft 365 Users
The EvilTokens campaign is exploiting a new phishing method that leaves malicious pages hidden until they are activated in the browser. This bypasses traditional URL checks, increasing the risk of unauthorized access to Microsoft 365 accounts and sensitive data.
AI-Driven Cyber Attacks Accelerate Response Needs for Enterprises
AI models enable cyber attacks to escalate within 27 seconds, outpacing human response capabilities. This shift necessitates a focus on cyber resilience, emphasizing automated recovery and contextual threat detection.
2026 Sees Shift in Account Takeover Tactics Focusing on Verification Steps
Account takeover (ATO) strategies are evolving as 75% of consumers now use passkeys, making traditional credential stuffing less effective. Attackers are shifting their focus to identity verification processes, which remain less secure, as outlined in the 2026 Veriff reports.
RedWing Android Malware Sold on Telegram for Bank Fraud Operations
A new malware service called RedWing is being rented on Telegram, enabling low-skilled criminals to perform bank fraud by taking over victims' phones. The service includes features like fake login overlays, interception of one-time codes, and remote control of devices, making it a substantial threat to security.
2026 Reports Major Cybersecurity Breaches Impacting Social Security Data
In 2026, significant cybersecurity breaches have emerged, notably involving the Department of Government Efficiency (DOGE) and the Social Security Administration. A potential leak of sensitive personal data, including Social Security numbers, raises concerns about misuse and marks a potentially historic data breach in the U.S.
Microsoft 365 Device Code Phishing Targeting Using DEBULL Tooling Identified
A new phishing campaign targeting Microsoft 365 accounts employs collaboration-themed lures and a reusable tool called DEBULL, exploiting the Microsoft device code authentication flow. This technique allows attackers to bypass multi-factor authentication by tricking users into entering device codes, effectively hijacking their accounts.
Mandiant Identifies Vulnerability in ADFS Certificate Management
Mandiant discovered that improper manual rotation of ADFS certificates can expose active signing keys in Machine DPAPI. This vulnerability allows attackers to forge SAML tokens and bypass authentication mechanisms, posing significant risks to enterprise security.
Critical Vulnerability in Writer AI Could Allow Account Hijacking
Researchers disclosed a critical session isolation vulnerability in Writer, an enterprise AI platform, allowing attackers to gain unauthorized access to accounts across different organizations. The flaw, codenamed WriteOut, could enable outsiders to exploit a shared link to hijack a victim's session, potentially compromising sensitive data and control over accounts.
Savi launches app to combat AI-generated scams after personal incident
Savi Security has launched an app aimed at protecting consumers from AI-generated scams, following a personal experience of one founder's family. The company raised $7 million in seed funding and is addressing the rising threat of realistic scams prevalent due to advancements in generative AI technology.
NSA Influence on IETF Standards Raises Security Concerns
NSA documents reveal past influence on cryptographic standards, indicating potential security risks from proposed IETF RFC for solo ML-KEM. The push for solo ML-KEM and ML-DSA raises alarms about increased vulnerabilities in deployed systems.
$20 million drained from BONK cryptocurrency in governance attack
Attackers exploited a governance proposal to drain $20 million from the BONK cryptocurrency. BonkDAO is collaborating with law enforcement to recover the funds and has temporarily suspended activities with the coin on South Korean exchange Upbit.
Phishing Campaign Impersonates Major Brands to Steal Google Credentials
A phishing campaign is impersonating over 30 prominent brands, including Adobe and Netflix, targeting marketing professionals to steal Google account credentials. By using legitimate HR platforms and real recruiter names, the threat actor enhances the phishing attempt's credibility, making it a significant security threat.
EtherRAT malware spreads via fake IT support calls on Microsoft Teams
Threat actors are using Microsoft Teams to impersonate IT support and deliver EtherRAT malware to corporate networks. This strategy combines phishing emails and remote access tools to compromise systems and gain control.
Ukrainian media outlets targeted by Russian hackers amid military pressures
Ukrainian media organizations are increasingly becoming priority targets for Russian hackers, according to the SBU. This escalation in cyber warfare aims to disrupt media operations and spread disinformation, impacting public trust during the ongoing conflict.
Prompt Injection Attacks Target AI Agents for Fraudulent Crypto Payments
Threat actors are using prompt injection attacks to deceive AI agents into making cryptocurrency payments. Zscaler identified two tactics, including a payment scam disguised as API documentation and a typosquatting operation impersonating a crypto service, which could significantly undermine trust in AI-integrated financial transactions.
Chinese Hackers Target India’s Taxpayers with DcRAT via Phishing Scheme
A suspected group of Chinese hackers has launched Operation DragonReturn, targeting Indian taxpayers with sophisticated phishing emails disguised as communications from the Income Tax Department. The campaign utilizes fake tax filing utilities to deploy a remote access trojan (DcRAT), aimed at stealing sensitive financial data.
TrojPix Enables Data Leakage from Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University developed TrojPix, a technique that exploits video cable emissions to leak data from air-gapped computers. This method can transmit data at a high rate of 8.1 Mbps over distances of up to 208 meters, posing significant security risks for sensitive systems.
QuimaRAT: New Java-Based Remote Access Trojan Targets Windows, Linux, and macOS
Researchers have identified QuimaRAT, a Java-based remote access trojan available as malware-as-a-service. Its cross-platform capabilities and modular design, including a builder for environmental customization, pose significant security threats.
Malware found hidden in TailwindCSS config file
A developer discovered obfuscated malware in their tailwind.config.js file, which was not expected to contain malicious code. This incident raises concerns about security in Node projects and the potential for similar compromises in configuration files across other projects.
Severe vulnerability in MSI Center allows SYSTEM privileges escalation
A vulnerability in the MSI Center, prevalent on MSI laptops, allows authenticated users to gain SYSTEM privileges. This could lead to significant security risks across numerous devices globally due to the software's widespread installations.
Seven Unpatched Vulnerabilities Found in Widely-Used FatFs Filesystem
Security firm runZero has revealed seven vulnerabilities in the FatFs filesystem library, which is integral to many embedded devices. The flaws allow for potential memory corruption and unauthorized code execution, posing significant risks, particularly for devices that lack robust memory protections.
New Avalon Malware Framework Discovered with Ransomware Functionality
Researchers have identified Avalon, a modular malware framework featuring the CrownX ransomware. Avalon employs sophisticated phishing techniques and extensive evasion tactics to bypass security measures, posing significant threats to various organizations.
Malicious npm Packages Linked to North Korea Target Developers' Secrets
North Korea-linked malicious npm packages masquerade as Rollup polyfills, enabling data theft. The packages mimic legitimate ones to facilitate remote access to sensitive developer information, highlighting ongoing threats against the tech development community.
U.S. Increases Surveillance for World Cup and Independence Day Events
The U.S. is ramping up surveillance for the World Cup and Independence Day celebrations, designating these events as National Special Security Events (NSSE). This heightened security response includes biometric tracking and increased law enforcement presence, raising concerns among privacy advocates about the lasting implications of such surveillance measures.
Apple's iOS 27 introduces Trust Insights to combat real-time scams
Apple has unveiled the Trust Insights framework in iOS 27, designed to help apps detect social engineering scams in real-time. By analyzing user behavior during interactions, it can flag potential scams and notify users through apps, addressing the growing prevalence of such scams, particularly with the rise of AI deepfakes.
Anubis Ransomware Group Exploits Citrix Bleed 2 Vulnerability for Attacks
The Anubis ransomware operation has been identified exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain access to targeted environments. This trend, utilizing legitimate remote access tools for lateral movement, highlights the evolving tactics of ransomware groups and the urgent need for organizations to address vulnerabilities.
Umbrij Malware Exploits OAuth to Access Gmail Through Google API
The ToddyCat threat actor has released a new malware named Umbrij, which gains unauthorized access to Gmail accounts via the Google API using OAuth tokens. This technique could significantly impact corporate email security, as it leverages existing Gmail sessions for access.
New Android malware silently infects billions of devices via Google
A new Trojan horse malware disguised as 'Android Developer Verifier' has infected around 4 billion Android devices running version 8 or higher. It operates in the background with root privileges, preventing users from removing it and blocking access to software from unregistered developers.
Serious Flaw in Argo CD Repo-Server Allows Remote Code Execution
An unpatched flaw in Argo CD's repo-server allows unauthenticated attackers to execute code, potentially taking over Kubernetes clusters. Synacktiv, which discovered the issue, reports that the vulnerability remains unaddressed nearly 18 months after it was reported.
Critical Vulnerability in Progress Kemp LoadMaster Enables Root Command Execution
A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster permits unauthenticated root command execution via API requests. Patches are released to mitigate the CVSS 9.8 flaw. Reports indicate active exploitation attempts, causing security concerns among users.