🚨 Reports of activity referred to as FortiBleed indicate malicious cyber activity targeting Fortinet FortiGate devices across government & private sector organizations. Review our Alert and take immediate action to protect your organization’s systems. 👉 https://t.co/VhDx0zq2o1
Codeless attack: An attacker types plain text into a chat app. An #LLM turns the text into shell commands on the victim. Stolen files come back through the same chat. Zero coding skills needed to operate, and no custom infrastructure to detect. Details at https://t.co/nlg8UeFy4h
We detected a malicious browser extension campaign that trojanizes legitimate extensions to serve ads covertly. The extension categories include ad blocking, messaging privacy, screen recording and music control. 1,000+ installations so far. Details at https://t.co/xrHkntgcUk
🚨 APT28 Turns EdgeRouters Into Attack Infrastructure
https://t.co/yqtqJTQzjO
Russia-linked APT28, also known as Fancy Bear, is shifting more of its operations onto compromised SOHO routers and edge devices.
At the peak of the activity, more than 18,000 unique IPs across 120 countries were seen communicating with APT28-controlled servers.
The group abused Ubiquiti EdgeRouters, targeted MikroTik and TP-Link routers, and routed malware traffic through trusted cloud services.
Instead of using obvious C2 servers, Fancy Bear is hiding behind compromised routers and trusted cloud services.
#ThreatIntelligence #FancyBear #APT28 #CyberSecurity
We detected an evasive #ClickFix injection with a fake Lirunex payment platform lure tricking the user into requesting the SSL certificate path through a file dialog box but silently delivers a RAT disguised as image files. Details at https://t.co/3gOKYWrMLz
We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort victims: https://t.co/gyaGA1iG1S
Microsoft has uncovered a supply chain attack involving malicious npm packages registered under organizational scopes that mirror real internal corporate namespaces, employing dependency confusion technique to deploy a reconnaissance payload. https://t.co/z2GjRIAyYS
A threat actor operating under three maintainer aliases, mr.4nd3r50n, ce-rwb, and t-in-one, published malicious packages that impersonate internal corporate packages, with several spoofing internal enterprise infrastructure URLs in their package.json to appear legitimate.
Once installed, the packages download and execute an obfuscated payload from an attacker-controlled command-and-control (C2) server to collect system information, hostnames, environment variables, and developer context. Read the blog for in-depth analysis and mitigation, detection, and hunting details.
Secret Blizzard’s Kazuar malware has evolved from a traditional backdoor into a modular botnet optimized for stealth and persistence. This upgrade aligns with the Russian state actor’s espionage-focused operations. https://t.co/KRnrTZRIqJ
While many threat actors rely on increasing usage of native tools (living-off-the-land binaries (LOLBins)) to avoid detection, Kazuar’s evolution highlights how Secret Blizzard is engineering resilience and stealth directly into their tooling.
Our latest blog breaks down Kazuar’s architecture and botnet operations, and provides protection and detection guidance for defenders:
Google Threat Intelligence Group is dropping our latest AI Threat Tracker report today, which covers several threats we are watching through a variety of means. The report includes some details of the first 0day exploit we've found developed with AI. 1/x https://t.co/klvOrX31xv
We observed a phishing campaign pivot to evade static analysis, shifting from credential theft to #OAuth device code phishing. Attackers replaced hardcoded URLs with runtime-fetched landing pages and generated images as blob URLs. Details at: https://t.co/R0zi1o5smS
Microsoft Defender has published analysis, detection insights, and mitigation recommendations for CVE-2026-31431 (also known as “Copy Fail”), a high-severity local privilege escalation vulnerability affecting multiple major Linux distributions: https://t.co/hX49wPOIPB
Better understand agentic AI systems and mitigate the cybersecurity risks using a new guide we authored with @ASDGovAu and others. View the joint report. #Cybersecurity#AgenticAI
https://t.co/3nOvJwMYdS
🆕 Tracking ShinyHunters just got easier.
🚀We launched a free, unified intelligence timeline for the ShinyHunters threat group — all their activity in one place, in real time.
3 categories, all in one view:
🔶 Ransomware — direct victim claims from their darknet leak site
🔴 Group Forum Activity — forum posts published under their own identity
🟣 Intel Reports — third-party mentions & intelligence about the group.
All events are AI-classified and risk-scored by DarkFeed's monitoring engine.
Free & open to everyone 👇 https://t.co/ryQtWBdqKU
#ThreatIntelligence #Ransomware #ShinyHunters #CTI #Cybersecurit
We discovered phishing emails falsely warning recipients their mailbox storage limit was exceeded. Emails include shortened links that redirect to fake cloud storage pages, ultimately redirecting users to pages selling VPNs or antivirus software. Details: https://t.co/BvzeEWd5Y7
At least 300 Germans are confirmed victims, including a senior CDU foreign policy MP and the former deputy head of German foreign intelligence (BND). The BfV's own internal warning says the real number is "significantly higher" and that numerous Signal groups in the parliamentary sphere are likely being read in real time, right now. The FBI and CISA put the international count in the thousands.
The BfV sent a 20-page warning to parliamentary party leaders last week. Klöckner, for her part, had previously warned publicly about the growing threat of cyberattacks on the Bundestag.
More reliable story link: https://t.co/8GZ6h6nsUa
🚨New research reveals how two sophisticated surveillance actors exploited the global telecom ecosystem and, for the first time, directly links combined 3G and 4G network attacks to mobile operator infrastructure.
Full report 👇
https://t.co/NfBNUuewdj
Microsoft Defender Research discovered an intent redirection vulnerability in a widely used third-party Android SDK that enabled apps on the same device to bypass Android sandbox protections and gain unauthorized access to private data. https://t.co/AkmCJ0uSuV
The Russian military intelligence actor Forest Blizzard has conducted large-scale exploitation of vulnerable small office/home office (SOHO) devices to hijack DNS requests and enable persistent, passive visibility and reconnaissance at scale. https://t.co/6oONFAtP20
By compromising edge devices that are upstream of larger targets, threat actors could take advantage of less closely monitored assets to pivot into enterprise environments. We have identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard’s malicious DNS infrastructure.
Microsoft Threat Intelligence is publishing this research to increase awareness of the risks associated with insecure home and small-office internet devices and to give users and organizations tools to mitigate, detect, and hunt for these threats where they might be impacted.
NEW: An APT41/Winnti ELF backdoor with near-maximum entropy obfuscation, invisible to Shodan for 2.5 years.
Three C2 domains typosquatting Chinese tech companies:
- ai[.]qianxing[.]co (Qianxin AI)
- ns1[.]a1iyun[.]top (Alibaba Cloud — note the "1" replacing "l")
- ai[.]aliyuncs[.]help (Alibaba Cloud Storage)
All resolve to one Alibaba Cloud IP in Singapore. Let's Encrypt wildcard cert from August 2023.
The implant harvests cloud instance metadata (169.254.169.254) for credential theft across AWS, GCP, Azure, and Alibaba Cloud workloads. Uses SMTP port 25 as a covert C2 channel. UDP broadcast to 255.255.255.255:6006 for LAN discovery.
Lineage: PWNLNX → RedXOR → AzazelFork → Earth Lusca → Melofee → this sample.
3 YARA + 9 Suricata on GitHub.
Full writeup: https://t.co/383qWNvGyU
h/t @TuringAlex