Dust Specter targets Iraqi officials with new SPLITDROP and GHOSTFORM malware

Ravi LakshmananMarch 5, 2026Malware/Threat Intelligence A suspected Iranian-linked actor is believed to have been involved in a campaign targeting Iraqi government officials by impersonating the Iraqi Ministry of Foreign Affairs and delivering a series of never-before-seen malware. Zscaler ThreatLabz, which observed this activity in January 2026, is tracking this cluster under the name Dust Specter. […]

Where multi-factor authentication stops and credential abuse begins

Organizations typically deploy multi-factor authentication (MFA) and assume that a stolen password is not sufficient to gain access to a system. In Windows environments, that assumption is often incorrect. Attackers still use valid credentials to breach networks every day. The problem isn’t MFA itself, it’s coverage. MFA enforced through an identity provider (IdP) such as […]

Can you tie a knot in four dimensions? A mathematician explains.

We all know that we live in three-dimensional space. But what do people mean when they talk about the fourth dimension? Is it just a large space? Is it the general idea of ​​“spacetime” born from Einstein’s theory of relativity? If you’ve ever wondered what the fourth dimension actually looks like, you may have seen […]

APT28-related campaign deploys BadPaw Loader and MeowMeow backdoor in Ukraine

Ravi LakshmananMarch 5, 2026Cyber ​​espionage/threat intelligence Cybersecurity researchers have revealed details of a new Russian cyber campaign targeting organizations in Ukraine using two previously undocumented malware families, BadPaw and MeowMeow. “The attack chain begins with a phishing email containing a link to a ZIP archive. Once extracted, the first HTA file displays a decoy document […]

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

Tycoon 2FA, one of the prominent phishing-as-a-service (PhaaS) toolkits that enabled cybercriminals to conduct large-scale man-in-the-middle (AitM) credential harvesting attacks, was dismantled by a coalition of law enforcement agencies and security companies. First launched in August 2023, this subscription-based phishing kit was described by Europol as one of the world’s largest phishing operations. The kit […]

FBI and Europol seize LeakBase forum used to trade stolen credentials

Ravi LakshmananMarch 5, 2026Malware/Dark Web A joint law enforcement operation dismantled LeakBase, one of the world’s largest online forums where cybercriminals buy and sell stolen data and cybercrime tools. According to the U.S. Department of Justice (DoJ), the LeakBase forum had over 142,000 members as of December 2025, with over 215,000 messages between members. Anyone […]

Google settles with Epic Games, lowers Play Store fees to 20%

Google is moving forward with a series of changes to the Play Store, settling a years-long legal battle with Fortnite maker Epic Games over anti-competitive concerns. The tech giant announced Wednesday that it will reduce Play Store fees on in-app purchases to 20%, with an additional 5% added if app developers choose to use Google’s […]