Safe Events Start With Threat Intel and Digital Security

**Major Events Face Unseen Cyber Threats Before the First Guest Arrives** The summer of 2026 is packed with high-profile events that will draw global audiences and intense scrutiny. But behind the scenes, security teams are working tirelessly to prevent potential cyber threats from turning these gatherings into disaster scenarios. The threat landscape around major events … Read more

‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat

A New AI-Driven Threat Emerges in Software Supply Chain: ‘Phantom Squatting’ Cybercriminals have discovered a novel way to compromise software supply chains using large language models (LLMs) that “hallucinate” fictional web domains for legitimate brands. This emerging threat, dubbed “phantom squatting,” allows attackers to register nonexistent domains linked to well-known companies and use them to … Read more

Medtronic notifies customers impacted by ShinyHunters data breach

Medtronic Data Breach Exposes Sensitive Customer Information to Unauthorized Hackers Healthcare device company Medtronic has notified customers that their personal data was compromised in a recent data breach attributed to the notorious hacking group ShinyHunters. The incident, which occurred between April 13 and 19, exposed sensitive information from approximately 9 million customer records, including full … Read more

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

A newly discovered vulnerability in Microsoft’s SharePoint software, CVE-2026-45659, has been added to the US Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) list after being actively exploited by attackers. This development highlights the ongoing threat posed by AI-generated vulnerabilities and emphasizes the need for organizations to prioritize proactive security measures. The vulnerability, … Read more

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

A new and sophisticated remote access Trojan (RAT) has been discovered, targeting vulnerability researchers who use proof-of-concept (PoC) exploit repositories to identify and test software vulnerabilities. The ChocoPoC RAT, as it’s called, exploits a known vulnerability in popular PoC exploit repository platforms, allowing attackers to secretly install malware on researchers’ systems. The ChocoPoC RAT is … Read more

And the Winner in Dominant Malware Delivery? ClickFix

Cybercrime’s New Favorite: ClickFix Malware Delivery Technique Dominates Threat Landscape In just two years, ClickFix has evolved from a niche social engineering tactic to the go-to method for malware attacks. According to research by ReliaQuest, this highly effective technique is no longer an exception, but the rule, dominating initial access and defense-evasion categories in recent … Read more

Crafty Phishing Campaigns Auto-Adapt to Victim’s Device, OS

Phishing Campaigns Get Smarter, Delivering OS-Specific Payloads to Boost Compromise Rates A new wave of sophisticated phishing campaigns is spreading like wildfire across the globe, with attackers adapting their tactics to target specific devices and operating systems. According to a recent study by anti-phishing security vendor Cofense, these advanced campaigns are able to automatically detect … Read more

Over 900 Oracle E-Business instances exposed to ongoing attacks

Over 900 Oracle E-Business instances exposed to ongoing attacks, prompting urgent patching by users. In a disturbing trend that continues to unfold, more than 900 instances of Oracle’s E-Business Suite (EBS) have been discovered online and left vulnerable to attacks. The vulnerability, tracked as CVE-2026-46817, resides in the File Transmission component of EBS’s Oracle Payments … Read more

Turning Indicators into Intelligence in OpenCTI with Criminal IP

Cybersecurity teams around the world are constantly on the lookout for innovative ways to turn raw data into actionable intelligence. A new integration between OpenCTI, a leading open-source threat intelligence platform, and Criminal IP, a provider of cybersecurity insights, is set to revolutionize the way security analysts investigate and respond to cyber threats. The integration … Read more

Hackers target Microsoft 365 accounts with 81 million login attempts

A massive password-spraying campaign has been targeting Microsoft 365 accounts, generating over 81 million login attempts over a two-week period. The threat actor used valid username and password combinations exposed in past breaches to attempt authentication via Microsoft’s Azure command-line interface (CLI). Once authenticated, the hacker exploited a vulnerability in Conditional Access policies, bypassing multi-factor … Read more