CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

A New Wave of Account Hijacking Threats Loom Large, As Insurance Phishing Evolves into Real-Time Attacks Insurance phishing scams have been a persistent menace for individuals and businesses alike, preying on vulnerabilities in email security. However, researchers at CTM360 have uncovered a disturbing evolution in these tactics – from mere phishing attempts to real-time account … Read more

OpenAI confirms ChatGPT is down worldwide

ChatGPT Users Worldwide Hit by Widespread Outage as OpenAI Investigates Cause OpenAI’s popular chatbot, ChatGPT, has been taken offline for millions of users worldwide in a major outage that is causing widespread disruption. The outage, which started at around 5 AM ET on July 25th, is affecting users across the globe, including those in the … Read more

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

A new threat landscape has emerged with the launch of DevMan RaaS, a centralized portal that streamlines payload builds, victim management, and affiliate payouts for ransomware operators. This sophisticated platform is designed to simplify the process of launching and managing large-scale ransomware attacks, making it easier than ever for malicious actors to extort money from … Read more

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cybersecurity experts are warning of a new wave of attacks targeting companies that expose their Product Lifecycle Management (PLM) software to the internet. Cl0p, a notorious cybercrime group, has been exploiting unauthenticated Remote Code Execution (RCE) vulnerabilities in PTC Windchill and FlexPLM systems, granting attackers unfettered access to sensitive data and systems. The affected companies … Read more

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Cyberthieves have taken insurance phishing scams to a new level, leveraging sophisticated artificial intelligence (AI) models to hijack online accounts in real-time. According to a recent study by CTM360 Research, these attackers are using AI-powered tools to automate the process of infiltrating victims’ accounts, making it increasingly difficult for individuals and businesses to stay one … Read more

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A Critical GitLab Vulnerability Allows Authenticated Users to Run Commands with Elevated Privileges, Leaving Thousands of Developers Exposed GitLab, a popular web-based platform for software development collaboration, has been hit by a critical vulnerability that allows authenticated users to run commands as if they were administrators. Researchers have published a proof-of-concept (PoC) exploit, demonstrating the … Read more

ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)

Cybersecurity experts have sounded the alarm over a sophisticated phishing campaign targeting businesses and individuals worldwide. The malicious emails are designed to exploit a specific vulnerability in email clients, potentially allowing attackers to bypass security measures and gain unauthorized access to sensitive data. The threat was highlighted by SANS Institute’s Internet Storm Center (ISC) in … Read more

Despite multiple takedowns, botnets continue to grow

Botnets Powered by Residential Proxies Continue to Grow, Evade Detection A staggering 60 million victim IP addresses are currently being exploited by botnets worldwide, with a significant proportion of these compromised devices located in the United States. These malicious networks are powered by residential proxy networks, which allow cybercriminals to blend in with legitimate traffic … Read more

Rockwell Patches Code Execution Flaws in Arena Simulation Software

Rockwell Automation’s Arena Simulation Software Patches High-Severity Code Execution Flaws Rockwell Automation has released patches to fix four critical vulnerabilities in its popular Arena Simulation software, which could allow attackers to execute arbitrary code on affected systems. The flaws, identified by researcher Michael Heinzl, were classified as high-severity and stem from the improper validation of … Read more