APT28 targets UKR-net users in Ukraine in long-running credential phishing campaign

December 17, 2025Ravi LakshmananEmail Security/Threat Intelligence A Russian state-sponsored threat actor known as APT28 is believed to be involved in what is described as an “ongoing” credential harvesting campaign targeting UKR users.[.]net is a popular webmail and news service in Ukraine. This activity was observed by Recorded Future’s Insikt Group from June 2024 to April […]

New forum troll phishing attack uses fake e-library emails to target Russian academics

December 17, 2025Ravi LakshmananVulnerabilities/Malware According to Kaspersky, the attackers involved in the forum troll operation are believed to be involved in a new phishing campaign targeting individuals in Russia. A Russian cybersecurity vendor announced that it detected new activity in October 2025. The origin of the threat actor is currently unknown. “While the spring cyberattacks […]

See threats to your industry and country in real time

Modern security teams often feel like they’re driving through fog with broken headlights. Threats are accelerating, alerts are increasing, and SOCs struggle to understand which hazards are currently important to the business. Moving away from reactive defense is no longer an option. It’s the difference between preventing an incident and handling it afterwards. Here’s a […]

China-linked Ink Dragon uses ShadowPad and FINALDRAFT malware to hack government

The threat actor known as Jewelbug has increasingly focused on government targets in Europe since July 2025, even as it continues to attack organizations located in Southeast Asia and South America. Check Point Research is tracking this cluster under the name Ink Dragon. It is also referred to by the names CL-STA-0049, Earth Alux, and […]

GhostPoster malware found in 17 Firefox add-ons with over 50,000 downloads

December 17, 2025Ravi LakshmananAd fraud/browser security The new campaign, dubbed GhostPoster, utilized logo files associated with 17 Mozilla Firefox browser add-ons to embed malicious JavaScript code designed to hijack affiliate links, inject tracking codes, and commit click and ad fraud. In total, the extension was downloaded more than 50,000 times, according to Koi Security, which […]

Compromised IAM Credentials Power Massive AWS Crypto Mining Campaign

December 16, 2025Ravi LakshmananMalware/threat detection An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining. The activity was first detected by Amazon’s managed threat detection service GuardDuty and its automated security monitoring systems on November 2, 2025, and employs never-before-seen persistence […]

Malicious NuGet package impersonates Tracer.Fody and steals cryptocurrency wallet data

December 16, 2025Ravi LakshmananCybersecurity/Cryptocurrency Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its creator to sneak into cryptocurrency wallet stealers. The malicious package named “Tracer.Fody.NLog” remained in the repository for nearly six years. This was published on February 26, 2020 by a user named […]

Amazon exposes years-long GRU cyber campaign targeting energy and cloud infrastructure

December 16, 2025Ravi LakshmananCloud security/vulnerabilities Amazon’s threat intelligence team has revealed details of a “multiyear-long” Russian state-led campaign targeting critical infrastructure in the West from 2021 to 2025. Targets of the campaign included organizations in the energy sector in Western countries, critical infrastructure providers in North America and Europe, and companies with cloud-hosted network infrastructure. […]

Why data security and privacy needs to start in code

AI-assisted coding and AI app generation platforms have sparked an unprecedented surge in software development. Enterprises are currently facing rapid growth in both the number of applications and the pace of change within applications. Security and privacy teams are under tremendous pressure as the surface area they must cover expands rapidly, even as staffing levels […]

Fortinet FortiGate under active attack with SAML SSO authentication bypass

December 16, 2025Ravi LakshmananNetwork security/vulnerabilities Threat actors began exploiting two newly disclosed security flaws in Fortinet FortiGate devices less than a week after they were made public. Cybersecurity company Arctic Wolf announced that it observed an active intrusion involving a malicious single sign-on (SSO) login on a FortiGate appliance on December 12, 2025. The attack […]