Threat actors stories - Page 6
GhostFrame iframe phishing kit powers 1m attacks
Wed, 10th Dec 2025
#
firewalls
#
email security
#
breach prevention
GhostFrame phishing kit has fuelled over 1m iframe-powered attacks since September, using hidden pages and anti-inspection tricks to evade defences.
AI agents to transform enterprise, retail & security by 2026
Wed, 10th Dec 2025
#
uc
#
devops
#
digital transformation
AI agents are tipped to sweep through enterprises, shops and security by 2026, automating work, reshaping retail and redefining digital trust.
AI-driven cyber wars to reshape security in 2026
Wed, 10th Dec 2025
#
firewalls
#
data protection
#
dr
AI-powered attackers and defenders will clash in 2026, driving autonomous breaches, VPN failures and stricter rules that reshape cyber security.
Microsoft patches Windows zero-day & risky Office flaws
Wed, 10th Dec 2025
#
storage
#
dr
#
encryption
Microsoft fixes a Windows zero-day used in attacks and Office flaws that can execute code when emails are merely received or previewed.
SonicWall acts after backup breach as state actors target cloud files
Fri, 21st Nov 2025
#
firewalls
#
dr
#
ransomware
SonicWall confirmed state actors accessed backup cloud files via an API, prompting swift investigation and enhanced security for partners and customers.
AI-driven cyber attacks surge, outpacing security defences
Wed, 19th Nov 2025
#
firewalls
#
network security
#
advanced persistent threat protection
AI-driven cyber attacks are escalating rapidly, outpacing traditional defences and forcing security teams to adopt advanced AI tools to keep pace.
Curly COMrades abuse Hyper-V for covert malware operations in VMs
Wed, 5th Nov 2025
#
malware
#
virtualisation
#
firewalls
Curly COMrades exploit Microsoft Hyper-V to run hidden malware inside lightweight VMs, evading detection and maintaining stealthy control over targets.
Ransom payment rates drop to historic low as attackers adapt
Thu, 30th Oct 2025
#
ransomware
#
crypto
#
phishing
Ransom payments fell to a historic low of 23% in Q3 2025 as cyber extortion tactics shift towards targeted, costlier attacks on larger firms.
Ransomware groups surge as automation cuts attack time to 18 mins
Thu, 23rd Oct 2025
#
ransomware
#
encryption
#
advanced persistent threat protection
Automation and AI slash ransomware attack times to 18 minutes, challenging defenders to match speed with automated defences, says ReliaQuest report.
Expel Intel launches to deliver actionable threat intelligence insights
Thu, 9th Oct 2025
#
advanced persistent threat protection
#
socs
#
cybersecurity
Expel has launched Expel Intel, a new team providing actionable cyber threat insights based on real-world incidents to help security teams improve defences.
Oracle issues urgent patch as Cl0p exploits suite flaw for attacks
Wed, 8th Oct 2025
#
ransomware
#
mfa
#
advanced persistent threat protection
Oracle has issued an urgent patch for a critical flaw in its E-Business Suite, exploited by the Cl0p ransomware group using advanced social engineering tactics.
Broadcom patches VMware zero-day exploited for nearly a year
Thu, 2nd Oct 2025
#
cloud security
#
advanced persistent threat protection
#
it automation
Broadcom patches a VMware zero-day flaw exploited for nearly a year, allowing attackers root access to virtual machines in certain configurations.
Vane Viper linked to over 1 trillion DNS queries & ad fraud scams
Wed, 17th Sep 2025
#
martech
#
advanced persistent threat protection
#
cybersecurity
Vane Viper, a threat actor posing as an adtech firm, generated over 1 trillion DNS queries last year linked to malware and ad fraud, warns Infoblox.
Oyster Backdoor mimics IT management tools to target IT professionals
Wed, 27th Aug 2025
#
malware
#
firewalls
#
ransomware
Oyster Backdoor malware, disguised as WinSCP and PuTTY, targets healthcare IT professionals to enable ransomware operations like Rhysida, warns BlueVoyant.
Global ransomware attacks rise as healthcare faces surge in cyber threats
Fri, 22nd Aug 2025
#
firewalls
#
ransomware
#
encryption
Ransomware attacks surge to 20 daily incidents in 2025H1, with healthcare facing increased cyber threats and hackers targeting overlooked IoT devices worldwide.
Phishing campaign uses fake Microsoft apps to bypass MFA
Tue, 19th Aug 2025
#
hyperscale
#
mfa
#
cloud security
Proofpoint exposes phishing attacks using fake Microsoft apps to bypass MFA and hijack Microsoft 365 accounts, affecting thousands globally in 2025.
LevelBlue & Akamai launch managed service for web app security
Fri, 15th Aug 2025
#
firewalls
#
devops
#
application security
LevelBlue and Akamai have teamed up to offer a managed web app and API security service, tackling rising threats with AI-driven, 24/7 protection and expert support.
Black Kite unveils ASI for targeted third-party cyber risk
Sat, 9th Aug 2025
#
ransomware
#
advanced persistent threat protection
#
supply chain
Black Kite has launched its Adversary Susceptibility Index to help firms spot which suppliers are most exposed to specific cyber threat actors, enhancing risk management.
DDoS attacks surge 364% in APAC, driven by AI & hacktivists
Fri, 8th Aug 2025
#
ddos
#
advanced persistent threat protection
#
ai
DDoS attacks in APAC have surged 364% year-on-year, driven by AI and hacktivists, with service providers and government bodies as prime targets.
SquareX launches open-source toolkits to defend browsers
Fri, 8th Aug 2025
#
firewalls
#
network security
#
advanced persistent threat protection
SquareX launches two open-source toolkits to help security teams simulate and defend against browser-based attacks that evade traditional enterprise defences.