How AI-powered phishing killed blocklists for good

Phishing’s New Frontier: AI-Powered Attacks Outrun Blocklists The landscape of cybersecurity has taken a significant hit with the rise of AI-powered phishing attacks. These sophisticated campaigns are leaving traditional defense mechanisms, such as blocklists, in the dust. For years, blocklists have been struggling to keep pace with the ever-evolving tactics used by attackers, but AI … Read more

Google Blogger locks hundreds of blogs in malware false positive

Hundreds of Legitimate Blogs Locked in Malware False Positive, Google Investigates A massive misclassification error has locked hundreds of legitimate blogs on Google’s Blogger platform, with many owners reporting that their sites have been flagged as hosting malware. The issue began on August 4 and appears to be a result of an automated system incorrectly … Read more

COLDCARD security audit phishing attack installs remote access tool

A Phishing Campaign Exploits COLDCARD Vulnerability, Installs Remote Access Tool A malicious phishing campaign is currently targeting users of the COLDCARD wallet, a popular hardware cold storage device used for secure cryptocurrency storage. The attackers are exploiting fears surrounding a recent vulnerability in the COLDCARD device, which was linked to an estimated $88.6 million Bitcoin … Read more

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian Man’s Guilty Plea Exposes Widespread Data Theft from Snowflake Cloud Storage Provider Connor Riley Moucka, a 26-year-old Canadian, has pleaded guilty to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations. The scheme, which unfolded between February and October 2024, resulted in the … Read more

Ransom Cartel ransomware creator sentenced to 16 years in prison

A Major Ransomware Player Brought Down: Maksim Silnikau Sentenced to 16 Years for Ransom Cartel Crimes Maksim Silnikau, the mastermind behind the notorious Ransom Cartel ransomware operation, has been dealt a severe blow. The Belarusian national has been sentenced to 16 years in prison by a US court for his role in orchestrating devastating attacks … Read more

Google Blogger locks hundreds of blogs in malware false positive

Huge Malware False Positive Locks Hundreds of Legitimate Blogs on Google’s Platform In a shocking turn of events, hundreds of innocent Blogger websites have been wrongly flagged as hosting malware and subsequently locked out of their dashboards. The issue, which began on August 4, has left many web admins scrambling to restore access to their … Read more

COLDCARD security audit phishing attack installs remote access tool

Cyber Attackers Exploit COLDCARD Wallet Vulnerability with Phishing Scam A sophisticated phishing campaign is targeting users of the COLDCARD cold storage wallet, exploiting fears surrounding a recent vulnerability and suspected $88.6 million Bitcoin theft. The attackers are using emails impersonating COLDCARD to trick victims into installing remote access software, granting them unauthorized control over devices. … Read more

Hackers run khunt post-exploitation toolkit from Oracle database

Cyberattackers have successfully installed a post-exploitation toolkit, known as khunt, directly inside an Oracle database used to breach a corporate network. The attack was discovered by Huntress on July 27, 2026, after its security platform detected credential theft on a server hosting the Oracle database server. The attackers exploited a SQL injection vulnerability in a … Read more

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

A major disruption has shaken up a sprawling online scam network, known as Poipet, which has been using AI-powered chatbots to deceive victims across multiple continents. The network’s operations were severely impacted after OpenAI, the company behind the popular language model ChatGPT, took steps to disrupt their activities. At the heart of the Poipet scheme … Read more

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A massive online scheme has been uncovered, where over 250 domains masquerading as legitimate repair services are using browser fingerprinting techniques to lure macOS users into downloading malware. The compromised domains, all tied to the “ClickFix” brand, have been found to employ a sophisticated approach that exploits vulnerabilities in Apple’s Safari and Google Chrome browsers. … Read more