Hackers abuse Notepad++ plugins to stealthily install malware

Cyberattackers have been discovered using a clever tactic to stealthily install malware on unsuspecting computers, exploiting the trust placed in popular software Notepad++. The attackers, linked to a threat cluster tracked as UAC-0099, have been targeting organizations primarily based in Ukraine. This campaign marks a shift in tactics for the group, which has previously provided … Read more

Russian hackers exploit Zimbra zero-click flaw for email theft

Russian hackers have been exploiting a zero-click vulnerability in Zimbra Collaboration email servers to steal sensitive information from organizations worldwide. The attacks, attributed to the Russian state-sponsored hacking group Laundry Bear (also known as Void Blizzard), combine phishing campaigns with the exploitation of a patched flaw to compromise user accounts. Laundry Bear has targeted a … Read more

Russian hackers exploit Zimbra zero-click flaw for email theft

Russian Hackers Exploit Zimbra Vulnerability to Steal Email Data from Organizations Worldwide A sophisticated hacking group backed by the Russian government has been using a previously patched vulnerability in Zimbra email servers to steal sensitive data, including emails, passwords, and two-factor authentication (2FA) tokens. The attackers, known as Laundry Bear or Void Blizzard, have targeted … Read more

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Malicious Ads on Bing Promote Fake Claude App, Delivering SectopRAT Malware to Over 29 Organizations In a disturbing example of how malicious ads can compromise even the most trusted online services, researchers at Huntress have uncovered a malvertising campaign on Microsoft’s Bing search platform. This operation, dubbed “FakeAgent,” has been pushing a fake installer for … Read more

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A Malvertising Campaign on Bing Exposes Users to SectopRAT Malware A sophisticated malvertising campaign has been discovered on the Bing search service, which uses fake ads to promote a malicious Claude desktop app installer. This installer, hosted on a legitimate Claude.ai domain, delivers the notorious SectopRAT malware, capable of stealing sensitive user data and gaining … Read more

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

A flurry of high-profile security breaches and vulnerabilities have exposed weaknesses in our digital defenses, with artificial intelligence (AI) playing a double-edged role in both attacking and protecting systems. Android spyware has infected thousands of devices worldwide, while industrial control system (ICS) attacks targeting programmable logic controllers (PLCs) threaten critical infrastructure. One particularly concerning trend … Read more

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

A Worrying Trend Emerges as AI-Powered Vulnerability Discovery Tools Leave Organizations Scrambling to Keep Pace In recent months, a new wave of artificial intelligence (AI) powered tools has emerged, capable of discovering software vulnerabilities at an unprecedented rate. This surge in AI-facilitated vulnerability discovery has left many organizations struggling to keep up with the sheer … Read more

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Russian Espionage Group Exploits Zimbra Zero-Day to Steal Mail and 2FA Codes, Leaving Thousands Exposed A sophisticated Russian espionage group has been identified exploiting a previously unknown vulnerability in the popular email server software Zimbra, compromising thousands of users’ sensitive information. According to experts, the attackers targeted organizations worldwide, making off with email content, as … Read more

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Russian Espionage Group Exploits Zimbra Zero-Day Flaw, Steals Sensitive User Data A sophisticated Russian espionage group has been using a previously unknown vulnerability in Zimbra’s email software to steal sensitive user data, including emails and two-factor authentication (2FA) codes. The revelation highlights the ongoing threat posed by state-sponsored actors to organizations worldwide. The zero-day flaw … Read more

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

A New Era in Cybersecurity Assurance: FedRAMP 20X Ditches Narrative-Based Controls for Continuous Evidence The Federal Risk and Authorization Management Program (FedRAMP) has been a cornerstone of US government cybersecurity compliance since its inception. However, as of July 23, 2026, the long-awaited transition to Rev5 is coming to an end. This shift marks a significant … Read more