State-Sponsored UAT-4356 Deploys FIRESTARTER Backdoor on Cisco Firepower Devices via Chained N-Day Vulnerabilities
Cisco Talos has uncovered an active espionage campaign by state-sponsored group UAT-4356, which chains two Cisco Firepower FXOS vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to deploy the FIRESTARTER backdoor —...
CERT-UA Exposes APT Malware Campaign Targeting Eastern European Governments and Municipal Hospitals
Ukraine's CERT-UA has disclosed a sophisticated infostealer campaign targeting government bodies and municipal healthcare institutions across Eastern Europe. The malware harvests credentials from Chromium browsers and exfiltrates WhatsApp...
MuddyWater-Linked APT Campaign Scanned 12,000+ Systems Before Striking Middle East Critical Infrastructure
Iran-linked threat group MuddyWater is behind a sophisticated espionage campaign that scanned over 12,000 systems in the Middle East before stealing passport records and payroll data from an...
Battlefield 6’s Rise Is Fueling a Surge of Malware: How Attackers are Capitalizing on the Hype
Since its release this October, “Battlefield 6” has ignited gaming communities, with millions eagerly jumping into the action-packed experience. However, alongside the excitement comes a darker side –...
ToddyCat’s new tricks: email hacking evolves with the cloud
The age-old adage “if it ain’t broke, don’t fix it” doesn’t always hold true in cybersecurity. As attackers are increasingly leveraging cloud services to protect sensitive data, their...
Akira: a CAPTCHA breach unravels enterprise security
The recent escalation of attacks attributed to the Howling Scorpius ransomware group has highlighted a chillingly simple, yet devastatingly effective, entry vector. While often touted as the vanguard...
WhatsApp’s silent threat: the screen-sharing scams
The current wave of WhatsApp scams, fueled by the platform’s recently introduced screen-sharing feature, is a prime example. It’s a chilling demonstration of how a seemingly innocuous feature...
Trojanized KeePass campaign: novel loader and credential theft in ransomware operations
A recent investigation by WithSecure’s Threat Intelligence team has uncovered a sophisticated malware campaign leveraging a trojanized version of the open-source password manager KeePass. This operation, active for...