-
Security researchers have reported active exploitation attempts targeting multiple critical vulnerabilities in Fortinet FortiSandbox appliances, raising concerns about potential compromises in enterprise security infrastructure. According to threat int…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft Teams’ trusted infrastructure has been exploited by threat actors to secretly route malicious traffic, leading to a highly stealthy ransomware campaign attributed to the DragonForce group. Security researchers have discovered a novel te…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A professionally engineered loader called OnionDrop is being used in high-tempo campaigns to deliver multiple infostealers at scale. Between February 28 and May 20, 2026, YARA retro-hunting uncovered more than 645 unique OnionDrop DLL samples, and deli…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Novo Nordisk, the Danish pharmaceutical giant behind blockbuster weight-loss drugs Ozempic and Wegovy, has confirmed a cybersecurity breach involving unauthorized access to sensitive clinical data and internal artificial intelligence (AI) assets. The c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A data breach affecting the widely used K–12 student information system, Infinite Campus, has exposed the personal information of approximately 137,000 users. This incident is linked to an extortion campaign that occurred in March 2026 and has been att…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In April 2026, incident responders traced a sophisticated intrusion that abused compromised WordPress sites to deliver GULoader via an EtherHiding → ClickFix → UNC-chain. The real-world ClickFix incident produced convergent evidence from an ANY.RUN san…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes, CERT Polska reports. The group historically focused on Poli…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active campaign in which attackers are abusing Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow to take over Microsoft 365 accounts. Rather than capturing credentials with a fake login page, the threat actors persuade victims to c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than 1.2 million websites to active compromise. The campaign also affects the TrustPulse and PushEngage plugins, both developed by Awesome Motive, si…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Rhysida and Interlock sit inside the same ransomware supply chain, but their latest observed behavior shows a more nuanced relationship than simple code reuse. IBM X-Force’s long-term analysis ties both groups to initial access brokers, private crypter…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


