Ransomware group PAYLOAD weaponizes Microsoft Active Directory for disruption
The PAYLOAD ransomware group targeted a manufacturing organization in the Middle East, gaining initial access via a compromised VPN account, Kaspersky reported.
20 articles
The PAYLOAD ransomware group targeted a manufacturing organization in the Middle East, gaining initial access via a compromised VPN account, Kaspersky reported.
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page tha...
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. ...
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on Septem...
Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud.
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a plat...
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Power...
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [.
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens ...
Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than ...
ManageEngine has addressed a critical remote code execution vulnerability in ADSelfService Plus, which could allow an unauthenticated attacker to execute arb...
Google released Chrome version 154 to the Stable channel for Windows, macOS, and Linux, fixing 108 security vulnerabilities. This update addresses 11 critica...
A detailed Microsoft SharePoint vulnerability, tracked as CVE-2026-65660, allows authenticated, low-privileged users to execute arbitrary code on vulnerable ...
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcemen...
Claude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure.
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days throu...
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated Las...
Cisco Duo is the best MFA for most buyers comparing on price and speed published per-user tiers, a free small-team floor, and device trust included while Mic...
A Windows malware implant named CLOSEDQUORUM that uses commercial large language models as an autonomous command-and-control layer, shifting tactical decisio...