A new tool has emerged that promises to revolutionize the way organizations approach threat modeling. STRIDE GPT, an AI-powered threat modeling tool, leverages the capabilities of large language models (LLMs) to generate comprehensive threat models and attack trees for...
Cybercriminals are leveraging Gamma AI, a platform for creating presentations, websites, and documents, to build sophisticated and difficult-to-detect phishing page redirectors.
These malicious actors are exploiting Gamma's advanced capabilities to host phishing redirect pages directly on the legitimate domain,...
Microsoft Threat Intelligence has identified an evolved iteration of the XCSSET malware family actively exploiting macOS developers via weaponized Xcode projects.
This modular backdoor, first documented in 2020, now employs advanced obfuscation techniques, refined persistence mechanisms, and novel infection vectors...
Cybercriminals have escalated their phishing tactics by leveraging Scalable Vector Graphics (SVG) files to bypass traditional anti-phishing and anti-spam defenses.
These attacks, which first became widespread late last year, have increased dramatically since January 2025, exploiting the unique properties of...
Cyber threats are natural enemies of any business trying to survive and thrive in the modern digital environment. Just like living beings, threats emerge and evolve. They change, mutate, adapt, and proliferate.
To withstand these malevolent dynamics, businesses have to...
Russian state-sponsored hacking group Star Blizzard has shifted its tactics to exploit WhatsApp users through malicious QR codes.
This marks a significant evolution in the group’s spear-phishing campaigns, which have historically targeted government officials, diplomats, defense researchers, and organizations associated...
In a concerning development, the notorious ransomware group Black Basta has been observed leveraging Microsoft Teams as part of a sophisticated social engineering campaign.
This new tactic, which combines email bombing with impersonation of IT support staff, has raised...
The notorious Cl0p ransomware group has published a list of companies compromised through vulnerabilities in Cleo's managed file transfer (MFT) software.
The announcement, made on the group’s dark web leak site, highlights the exploitation of a critical vulnerability, CVE-2024-50623....
As 2024 concludes, cybersecurity experts are reflecting on an eventful Q4 that witnessed evolving threats and heightened activity in the malware landscape.
ANY.RUN, a leading interactive malware analysis platform, has released its quarterly report, shedding light on emerging trends and...
CoinLurker is a sophisticated data-stealing malware that has revolutionized fake update campaigns. Written in the Go programming language, CoinLurker incorporates advanced obfuscation and anti-analysis techniques, enabling it to evade detection and execute stealthy cyberattacks.
According to Morphisec's report, his next-generation...