Tortoiseshell is known to be active since at least July 2018, mainly targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. https://sellrentcars.com/news/climbing-search-rankings-seo-technical-maintenance-done-right.html Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026 Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections Scroll down for all the latest threat intelligence news and articles.
This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data. Apple’s own guidance states that the company never asks for a password, device passcode, https://helm-engine.org/tag/sensitive-details or 2FA code to provide support. Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. Nimbus Manticore also has a history of orchestrating its own version of the Dream Job campaign to deliver malware under the pretext of job opportunity-themed social engine…
The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host. Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The accounts “were being used to promote the International Burke Institute (IBI), a self-described ‘expert community’ based in Israel,” the company said .
Rhysida Ransomware Attack: How Hackers Hit a Major U.S. School District
- The activity was concentrated on DSEwiki , a German software developer wiki that runs on the ProWiki farm at wikiservice.at and had been edited about 20 times over the previous decade.
- A successful attack gives the attacker code execution on the store’s server and installs a persistent backdoor.
- The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.
- The mechanism allows “malware stagers to fetch commands directly from the protocol’s initial response,” SOCRadar said in a technical report.
- Tortoiseshell is known to be active since at least July 2018, mainly targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S.
- This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data.
Microsoft did not disclose a victim count or attribute the activity to a named threat actor in the report published Tuesday. The researchers said 1,923 cameras were configured with a persistent account during the operation and 283 were reached through the P2P path. Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. “What makes SilkParasite interesting is the traces of AI-assisted development running through otherwise expert code, which is a different thing from AI-generated malware,” https://eurodialogue.org/How-Turkey-wants-to-reshape-NATO Bitdefender Labs said in a technical report shared with The Hacker News. A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).
Because the malicious code sat in the build script of the injected dependency, building a project that resolved it was sufficient to run the payload, and nothing from the crates themselves had to be called. Although the security bulletin originally marked the “Exploited” field under the Exploitability Assessment table as “Yes,” on August 21, 2026, Microsoft corrected the “Exploited” status to “No” after The Hacker News contacted the company for comment. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. Two subsequent artifacts, each detected in June and July 2026, make use of a Virtual Hard Disk (VHD) file that activates the infection chain. The activity is assessed to be the work of a China-nexus threat actor with moderate confidence.
- Although the security bulletin originally marked the “Exploited” field under the Exploitability Assessment table as “Yes,” on August 21, 2026, Microsoft corrected the “Exploited” status to “No” after The Hacker News contacted the company for comment.
- “Sansec is publishing early because stores are being compromised right now,” the company said.
- Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application.
- The researchers said 1,923 cameras were configured with a persistent account during the operation and 283 were reached through the P2P path.