Hackers target Microsoft 365 accounts with 81 million login attempts

A massive password-spraying campaign has been targeting Microsoft 365 accounts, generating over 81 million login attempts over a two-week period. The threat actor used valid username and password combinations exposed in past breaches to attempt authentication via Microsoft’s Azure command-line interface (CLI). Once authenticated, the hacker exploited a vulnerability in Conditional Access policies, bypassing multi-factor … Read more

And the Winner in Dominant Malware Delivery? ClickFix

Malware Delivery Via Social Engineering Soars with ClickFix Technique A new threat has emerged in the world of cybersecurity, with social engineering technique ClickFix becoming the dominant method for malware delivery. In just two years, this tactic has gone from an emerging strategy to a widespread favorite among threat actors. According to research by ReliaQuest, … Read more

Crafty Phishing Campaigns Auto-Adapt to Victim’s Device, OS

Phishing Campaigns Get Smarter, Auto-Adapt to Victim’s Device and OS Threat actors have upped their phishing game by creating campaigns that can automatically adapt to a target’s device and operating system. This sophisticated approach has significantly increased the chances of successful attacks and made it more profitable for hackers. According to research published by anti-phishing … Read more

Over 900 Oracle E-Business instances exposed to ongoing attacks

Over 900 Oracle E-Business instances exposed to ongoing attacks, with malicious actors exploiting a critical security flaw that allows for low-complexity takeovers. The vulnerability, tracked as CVE-2026-46817, was patched by Oracle in May but has since been actively exploited, according to threat intelligence firm Defused. Oracle’s E-Business Suite (EBS) is a widely used business software … Read more

Turning Indicators into Intelligence in OpenCTI with Criminal IP

A New Era in Threat Intelligence: OpenCTI Teams Up with Criminal IP to Transform Indicators into Structured Intelligence In a major breakthrough for cybersecurity teams, the integration of Criminal IP’s threat intelligence with OpenCTI is revolutionizing the way indicators are analyzed and utilized. This powerful combination is transforming isolated IP addresses, domains, and URLs into … Read more

Hackers target Microsoft 365 accounts with 81 million login attempts

A massive password-spraying campaign has targeted Microsoft 365 accounts with a staggering 81 million login attempts over just two weeks. The attack, which exploited valid username and password combinations exposed in past breaches, has left at least 78 businesses across 64 organizations compromised. The alarming numbers highlight the importance of robust security measures, particularly when … Read more

Webinar: Why traditional email security is no longer enough

Email Security No Longer Enough as Modern Attacks Exploit Trust Traditional email defenses are failing to keep pace with the evolving landscape of cyber threats. For years, organizations have relied on secure email gateways, reputation services, and signature-based detection to stop phishing attacks before they reached employees. However, today’s attackers are increasingly exploiting trusted identities … Read more

DHS confirms hackers breached HSIN info-sharing platform

Cyber Attack on DHS Info-Sharing Platform Raises Security Concerns Across the US A recent cyber attack has compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. The Department of Homeland Security is currently investigating the breach, which is believed to have occurred sometime between late … Read more

New ChocoPoC malware targets researchers via trojanized PoC exploits

Cybersecurity Researchers Targeted by Malicious Proof-of-Concept Exploits Delivering ChocoPoC RAT A sophisticated campaign has been uncovered, where multiple proof-of-concept (PoC) exploits on GitHub are being used to deliver a Python-based remote access trojan (RAT) named ChocoPoC. The malware is designed to target cybersecurity researchers and has the capability to execute commands, steal sensitive data, and … Read more

Kubota says hackers had month-long access to network systems

Kubota’s Network Breach Exposes Employee Data to Hackers for Over a Month Japanese industrial giant Kubota has revealed that its network systems were compromised by hackers for over a month, leaving sensitive employee data vulnerable. The breach, which occurred between March 16 and April 20 this year, exposed personal information of employees and their dependents, … Read more