Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and…
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where attackers…
Analysts have numerous options for probing phishing attacks, but a single malware analysis sandbox often suffices. Blending static and dynamic…
March 2026 delivered a surge in cyber threats targeting users and organizations alike from banking apps hijacked to siphon personal…
An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet's FortiGate appliances and related products. Threat actors are exploiting…
A global data storage and infrastructure company fell victim to a severe ransomware attack orchestrated by Howling Scorpius, the group…
A sophisticated attack campaign uncovered where cybercriminals are weaponizing Cisco's own security infrastructure to conduct phishing attacks. The attackers are…
A zero-day vulnerability in the popular file compression tool WinRAR, actively exploited by the Russia-aligned threat group RomCom to deliver…
SSL certificates are used everywhere from websites and APIs to mobile apps, internal tools and CI/CD pipelines. While most teams…
Phishing kits are evolving fast. Threat actors behind toolkits like Tycoon2FA, EvilProxy, and Sneaky2FA are getting smarter, setting up infrastructure…