Tuesday, August 25, 2026

THREATS

Nike Alleged Breach: Threat Actors Claim Leak of Millions of Customer Records

A threat actor on a prominent cybercrime forum has claimed responsibility for leaking data allegedly belonging to Nike and Alcon, posting the purported datasets for download. The claims, currently...

7 AI Security Platforms That Use Machine Learning to Stop Attacks in Real Time 

Attackers don’t wait around anymore. They use automation, stolen tools, and clever tricks to move from one system to another in minutes. If your defenses only...

Rising Insider Threat: Criminal Groups Pay Employees for Sensitive Access

Cybercriminal syndicates are increasingly abandoning brute-force attacks in favor of a more efficient, albeit disturbing, tactic: recruiting insiders. A surge in darknet advertisements and...

Hackers Use ClickFix Technique to Deploy NetSupport RAT Loaders

Cybercriminals are increasingly using a technique known as "ClickFix" to deploy the NetSupport remote administration tool (RAT) for malicious purposes. According to a new...

Threat Actors Exploit Discord Webhooks for C2 via npm, PyPI, and Ruby Packages

Threat actors are increasingly abusing Discord webhooks as covert command-and-control (C2) channels inside open-source packages, enabling stealthy exfiltration of secrets, host telemetry, and developer...

Iran-Nexus Hackers Impersonate Omani MFA to Target Governments Entities

Cybersecurity researchers uncovered a sophisticated, Iran-linked spear-phishing operation that exploited a compromised Ministry of Foreign Affairs (MFA) mailbox in Oman to deliver malicious payloads...

New Scam Targets PayPal Users During Account Profile Setup

A highly sophisticated phishing campaign is targeting PayPal users with a deceptive email designed to grant scammers direct access to their accounts. The attack, which...

Threat Actors Exploit Velociraptor Incident Response Tool for Remote Access

Researchers from the Counter Threat Unit (CTU) at Sophos uncovered a sophisticated intrusion where threat actors repurposed the legitimate open-source Velociraptor digital forensics and...

U.S. Treasury Sanctions North Korean IT Worker Network Funding Weapons Programs

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) has imposed sanctions on Russian national Vitaliy Sergeyevich Andreyev, DPRK official Kim...

New Research Explores Emulating Scattered Spider Tactics in Real-World Scenarios

Experts have described methods for mimicking the strategies of the advanced persistent threat (APT) group Scattered Spider in a recent in-depth analysis by cybersecurity...

TAG-144: Actors Attacking Government Entities With New Tactics, Techniques, and Procedures

The threat actor known as TAG-144, also referred to as Blind Eagle or APT-C-36, has been linked to five distinct activity clusters operating from...