New StormEncryptor ransomware used by former Medusa affiliate

A highly motivated threat actor, previously linked to the notorious Medusa ransomware operation, has resurfaced with a new strain of malware called StormEncryptor. The attacker, tracked by Microsoft as “Storm-1175,” has been using this powerful tool to extort money from victims worldwide. The bad news is that Storm-1175 is believed to be based in China … Read more

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

As we wrap up another week in the world of cybersecurity, a disturbing trend has emerged that highlights the increasing threat of identity exposure and its potential consequences. In a series of incidents that span multiple industries and geographies, it’s become clear that when an individual’s identity is compromised, the door to active attack paths … Read more

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

A New Storm is Brewing: China-Linked Hackers Deploy Sophisticated Ransomware via N-central Flaw In a worrying trend, China-linked hackers have been spotted deploying a new type of ransomware known as StormEncryptor, which exploits a previously unknown flaw in the popular network management platform N-central. The attackers are using this vulnerability to gain unauthorized access to … Read more

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA Confirms Ransomware Gangs Exploit SonicWall SMA1000 Flaws, Despite Patches A critical vulnerability in SonicWall’s enterprise-grade secure remote access gateway, the SMA1000, has been confirmed to be actively exploited by ransomware gangs. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the … Read more

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

TrueConf Server Flaws Exposed, Client Installers Hijacked in Sophisticated Attack A sophisticated cyberattack has been uncovered, where hackers exploited vulnerabilities in TrueConf server software to replace client installers with a malicious payload called PhantomCore. The attack, which affects users of the popular video conferencing platform, highlights the importance of secure server-side configurations and underscores the … Read more

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

As we continue to move further into an era of rapid technological advancements, the risk of identity exposure has become a pressing concern for organizations worldwide. A recent webinar highlighted 11 real-life stories where compromised identities were used to unlock active attack paths, resulting in devastating consequences for those affected. The concept of cross-domain privilege … Read more

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

A new wave of Passkey attacks has emerged, putting users’ sensitive data at risk by exploiting a vulnerability in password managers that sync private keys across devices. These sophisticated attacks can not only recover synced private keys but also bypass even the most secure multi-factor authentication (MFA) systems. The targeted threat actors use complex methods … Read more

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Kimsuky, a North Korean threat group, has been spotted building an offline AI-powered toolset designed to supercharge its phishing and malware development capabilities. This new arsenal, dubbed “offline AI stack,” is poised to significantly amplify Kimsuky’s attack vectors, putting organizations at increased risk of cyber compromise. At the heart of this toolset lies a sophisticated … Read more

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

A pair of critical vulnerabilities in SonicWall’s SMA1000 secure remote access gateway has been exploited by ransomware gangs, leaving countless organizations at risk. The flaws, which were patched by SonicWall in mid-July, have already been targeted in zero-day attacks, with threat actors deploying custom malware on vulnerable VPN appliances. The affected vulnerabilities, tracked as CVE-2026-15409 … Read more

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

TrueConf Server Vulnerabilities Allow Malicious Installers to Slip In Undetected A concerning report has emerged of vulnerabilities in TrueConf servers being exploited by attackers to inject malicious client installers, raising questions about the security posture of organizations that use these conferencing platforms. According to sources, at least 11 companies have fallen prey to this tactic, … Read more