HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions...
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions...
Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to...
Ravie LakshmananJul 19, 2026Vulnerability / Network Security A previously undocumented threat actor has been attributed to the exploitation of recently...
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is...
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from...
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit...
Sophos has been named a 2026 Gartner® Peer Insights™ Customers’ Choice in the 2026 Gartner® Peer Insights™ Voice of the...
Ravie LakshmananJul 10, 2026Enterprise Security / Authentication A threat actor has been targeting organizations spanning multiple sectors with voice-based fake...
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between...
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of...
Ravie LakshmananJul 06, 2026Vulnerability / DevOps Threat actors have been observed attempting to exploit a recently patched critical security flaw...
A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver...
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web...
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade...
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the...