ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign
Prolific ShinyHunters group claims to have stolen data from nearly 400 websites in Experience Cloud attacks
20 articles
Prolific ShinyHunters group claims to have stolen data from nearly 400 websites in Experience Cloud attacks
The resurgence of one of Russia’s most notorious APT groups
Huntress researchers uncover campaign exploiting vulnerabilities to steal data using Elastic Cloud as a data hub
In a co-ordinated public-private operation between law enforcement agencies and cybersecurity industry partners, Tycoon 2FA - one of the world's most prolifi...
A bank, an airport, a non-profit and the Israeli branch of a US software company were among the targets of this new MuddyWater campaign
Malware campaign uses Ukrainian email service for credibility, deploying "BadPaw" to execute attacks
Espionage campaign exploits Israel-Iran conflict, distributing a trojanized Red Alert app via SMS
Key Findings Introduction In recent months, Check Point Research (CPR) has been tracking a sophisticated, Chinese-aligned threat group whose activity demonst...
Zscaler ThreatLabz assessed with medium to high confidence that an Iranian adversary targeted Iraq’s Ministry of Foreign Affairs in a new cyber-attack
UNC2814 hit 53 victims in 42 countries with novel backdoor in decade long cyber espionage operation
Introduction Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecomm...
Russia is escalating its hybrid warfare against NATO into a coordinated, full-scale campaign blending cyber attacks, sabotage, and influence operations. Read...
A low-skilled Russian-speaking attacker has used GenAI tools to help deploy a successful attack workflow targeting FortiGate instances
Commercial AI services are enabling even unsophisticated threat actors to conduct cyberattacks at scale—a trend Amazon Threat Intelligence has been tracking ...
Fraud campaign exploiting Indonesia’s Coretax resulted in $1.
GrayCharlie turns compromised WordPress sites into malware delivery machines. Discover how this threat actor chains fake browser updates and ClickFix lures t...
This article walks through how Elastic Security's Attack Discovery, combined with Workflows and Agent Builder, can automatically detect, correlate, and confi...
New phishing campaign dubbed Operation DoppelBrand targeted major financial firms like Wells Fargo
Introduction In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (A...
Google researchers found that government-backed hackers now use AI throughout the whole attack lifecycle