Ukrainian Intelligence Report: Russian APT Groups Intensify Cyber Operations — 5,927 Incidents, 37% Rise in 2025
A new intelligence report from Ukraine's National Security and Defense Council reveals Russian state-sponsored threat groups dramatically escalated cyber operations in 2025, with CERT-UA recording 5,927 incidents —...
ClickFix Evolves: Attackers Combine Social Engineering With Decade-Old PySoxy SOCKS5 Proxy for Persistent Access
A new ClickFix campaign observed by ReliaQuest pairs the social engineering technique with PySoxy, a 10-year-old Python SOCKS5 proxy, creating a two-channel persistent access chain that continues operating...
DigiCert Breached via Weaponized Screensaver: Threat Actor Steals EV Code Signing Certificates to Spread Zhong Stealer
A sophisticated threat actor breached DigiCert's internal support environment in early April 2026 by tricking analysts into executing a disguised .scr malware file, ultimately obtaining EV Code Signing...
Email Bombing and Fake IT Support on Microsoft Teams: How Attackers Are Stealing Remote Access
Attackers are combining inbox-flooding email bombing with fake IT support personas on Microsoft Teams to trick employees into granting remote access, leading to confirmed data exfiltration. Groups including...
Threat Group UNC6692 Breaches Enterprise Networks via Microsoft Teams Impersonation and SNOW Malware Suite
The newly identified threat group UNC6692 is compromising enterprise networks by impersonating IT helpdesk staff on Microsoft Teams, deploying a modular three-component malware suite called SNOW, and leveraging...
Booking.com Data Breach Exposes Customer Reservation Details, Raising Phishing Risk for Travellers
Booking.com has notified customers of a data breach that exposed names, addresses, email addresses, phone numbers, and full reservation details. While payment data was not compromised, security experts...
The Sophisticated ClickFix Sting: How Calisto Disguises Itself to Steal Credentials
Calisto, a cyberespionage campaign attributed to the Russian FSB’s Center 18 for Information Security (military unit 64829), has been making waves in the cybersecurity community. This group has...
DoorDash data breach: a social engineering compromise
The recent disclosure by DoorDash regarding a cybersecurity incident, initially attributed to a social engineering attack, warrants a detailed examination beyond the standard press release narrative. While the...