Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another...
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another...
Microsoft is closing the legacy Microsoft Threat Intelligence portal on August 1, leaving security teams only days to verify that...
Swati KhandelwalJul 29, 2026Mobile Security / Threat Intelligence Source code for the Flying Eagle Android remote access trojan (RAT) framework...
Ravie LakshmananJul 28, 2026Vulnerability / Threat Intelligence A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has...
Ravie LakshmananJul 27, 2026Cyber Attack / Threat Intelligence Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor...
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found...
Ravie LakshmananJul 24, 2026Threat Intelligence / Browser Security The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced...
Swati KhandelwalJul 23, 2026Malware / Threat Intelligence An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks...
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial...
Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to...
Ravie LakshmananJul 19, 2026Vulnerability / Network Security A previously undocumented threat actor has been attributed to the exploitation of recently...
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns,...
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared...
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared...
Ravie LakshmananJul 17, 2026Social Engineering / Malware North Korean threat actors linked to the Contagious Interview campaign have been observed...