APT28-related campaign deploys BadPaw Loader and MeowMeow backdoor in Ukraine

Ravi LakshmananMarch 5, 2026Cyber espionage/threat intelligence Cybersecurity researchers have revealed details of a new Russian cyber campaign targeting organizations in Ukraine using two previously undocumented malware families, BadPaw and MeowMeow. “The attack chain begins with a phishing email containing a link to a ZIP archive. Once extracted, the first HTA file displays a decoy document […]
Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

Tycoon 2FA, one of the prominent phishing-as-a-service (PhaaS) toolkits that enabled cybercriminals to conduct large-scale man-in-the-middle (AitM) credential harvesting attacks, was dismantled by a coalition of law enforcement agencies and security companies. First launched in August 2023, this subscription-based phishing kit was described by Europol as one of the world’s largest phishing operations. The kit […]
FBI and Europol seize LeakBase forum used to trade stolen credentials

Ravi LakshmananMarch 5, 2026Malware/Dark Web A joint law enforcement operation dismantled LeakBase, one of the world’s largest online forums where cybercriminals buy and sell stolen data and cybercrime tools. According to the U.S. Department of Justice (DoJ), the LeakBase forum had over 142,000 members as of December 2025, with over 215,000 messages between members. Anyone […]
149 hacktivist DDoS attacks hit 110 organizations in 16 countries after Middle East conflict

Cybersecurity researchers have warned of a surge in retaliatory hacktivist activity in the wake of the joint US-Israeli military operations against Iran, codenamed Epic Fury and Roaring Lion. “The hacktivist threat in the Middle East is highly skewed, with two groups, Keymous+ and DieNet, leading nearly 70% of all attack activity from February 28 to […]
Coruna iOS exploit kit uses 23 exploits across 5 chains targeting iOS 13 to 17.2.1

Google announced that it has identified a “new and powerful” exploit kit called Coruna (also known as CryptoWaters) targeting Apple iPhone models running iOS versions 13.0 through 17.2.1. According to the Google Threat Intelligence Group (GTIG), the exploit kit included five complete iOS exploit chains and a total of 23 exploits. It has no effect […]
New RFP template for AI usage control and AI governance

hacker newsMarch 4, 2026Artificial Intelligence / SaaS Security As AI becomes the central engine of enterprise productivity, security leaders are finally getting the green light and budget to secure it. But a quiet crisis is brewing in the boardroom. Many organizations know they need “AI governance” but don’t know what they actually want. The CISO’s […]
Fake Laravel packages on Packagist deploy RAT on Windows, macOS, and Linux

Ravi LakshmananMarch 4, 2026Threat Intelligence/Application Security Cybersecurity researchers have flagged a malicious Packagist PHP package masquerading as a Laravel utility that acts as a vector for a cross-platform remote access trojan (RAT) that works on Windows, macOS, and Linux systems. The names of the packages are listed below – nhattuanbl/lara-helper (download 37) nhattuanbl/simple-queue (download 29) […]
APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

Ravi LakshmananMarch 4, 2026Malware / Windows Security Cybersecurity researchers have revealed details of an advanced persistent threat (APT) group called Silver Dragon that has been linked to cyberattacks targeting organizations in Europe and Southeast Asia since at least mid-2024. “Silver Dragon gains initial access by exploiting public internet servers and delivering phishing emails containing malicious […]
CISA adds actively exploited VMware Aria operational flaw CVE-2026-22719 to KEV catalog

Ravi LakshmananMarch 4, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw affecting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog as being actively exploited in the wild. High severity vulnerability CVE-2026-22719 (CVSS score: 8.1) is described as a case of […]
Fake tech support spam deploys customized Havoc C2 across organization

Threat hunters are cautioned as part of a new campaign in which malicious actors pose as fake IT support and offer the Havoc command and control (C2) framework as a precursor to data theft and ransomware attacks. The intrusion, which Huntress identified last month across five partner organizations, involved the attacker using email spam as […]