Advanced Persistent Threat (APT) stories
The scam network's fake texts may have reached millions of Android users, with authorities linking it to major card theft and losses.
Healthcare providers face a new malware route as Varist's engine scans DICOM, HL7 and FHIR files for hidden threats in imaging systems.
A near-decade of undetected access raises fresh concern after investigators found the group had hidden in a disconnected network since 2016.
BlueVoyant says a ClickFix malware campaign using fake browser updates is linked to the Rapid Brigantine ransomware ecosystem.
Older, internet-facing IIS servers are being singled out by China-linked hackers, with one new cluster able to persist despite partial containment.
Nearly 100 organisations were hit in a six-week phishing spree that used GitHub repositories and Visual Studio Code tools to infect developers.
CrowdStrike said state-backed espionage and extortion are surging as AI assets inside tech groups draw hackers seeking code, models and access.
Businesses in Europe and Africa now face localised phishing and malware attacks from a suspected China-aligned group that has widened beyond Asia.
The report says Chinese threat groups are now tracking oil, reconstruction and strategic technologies across Venezuela, Syria, South Korea and the Gulf.
European ministries face a stealthier cyber-espionage campaign as Webworm shifts to Discord and Microsoft cloud tools to steal data.
Repeat breaches exposed an Azerbaijani oil and gas operator to espionage as FamousSparrow exploited Microsoft Exchange flaws for two months.
AI is now being used to write exploits and malware, with Google saying it has traced the first zero-day linked to machine assistance.
Security teams face a broader threat as criminals and state-backed actors use generative AI to speed hacks, phishing and malware.
Small defence contractors are left exposed as state-backed hackers spend years mapping supply chains and laying covert access routes before striking.
Diplomatic missions in Europe and the Middle East face renewed PlugX-backed espionage as TA416 shifts tactics and targets amid regional tensions.
Businesses face credential theft and reinfection risks as DeepLoad hides inside trusted Windows processes and evades routine clean-up.
Existing Threat Scan customers get new free tools to spot ransomware in backups before restoration, reducing the risk of reinfecting production systems.
The strain's self-checking code and file-wiping routine could make recovery harder for victims while giving investigators a rare attribution clue.
Attackers are now moving fast enough that patching delays, standing privilege and inherited trust leave organisations exposed within minutes.
Operational technology outages are leaving most manufacturers and critical infrastructure firms facing losses of up to GBP £5 million, a survey found.