Iranian threat actor #NimbusManticore rapidly developed its tooling, introducing the AI-assisted MiniFast backdoor and new delivery methods including trojanized software and SEO-poisoned sites.
Read More -->
https://t.co/hPjlKBFMFt
⚠️ Iranian APT conducts a wide M365 password spray campaign - focus on Israeli and UAE orgs
🌐TOR used to scan and spray, Israeli VPN infrastructure used for successful logins
🏙️ Israeli municipalities - key focus, likely for missiles BDA
Read more :
https://t.co/N7rJbCJ08t
Operation TrueChaos
Zero-day exploited in the wild by Chinese-nexus actor
💥 TrueConf client CVE-2026-3502
🌏 Southeast Asian government entities
🧰 Havoc C2, DLL sideloading, UAC bypass
Read more :
https://t.co/XgzxRBiPd4
Check Point researchers have observed increased activity by Chinese-nexus APT actors in the Middle East. Camaro Dragon attempted to deploy a variant of PlugX malware against Qatari targets within one day of the launch of Operation Epic Fury. https://t.co/vJs2LlLUaK
🚨ALERT🚨
Gulf countries, Cyprus & Israel - A massive wave of IP camera scanning and exploitation from Iran-linked infrastructure.
✅ Patch to the latest version
🔐 Enforce strong, unique passwords and restrict external access
Read More :
https://t.co/iuZkd446nQ
📜🤫2025: The Untold Stories of Check Point Research
Zero-days, wipers, election interference - much of what we uncover never makes it into public reports.
From #APT36 to #MuddyWater, #COLDRIVER to #FlaxTyphoon, here's what we tracked across every region.
https://t.co/OmcamzHreQ
The wait is over! Registration and the full agenda for BlueHatIL 2026 are now live. Register now before spots are gone!
Register here: https://t.co/zVl9dIyv4u
Full agenda: https://t.co/tumf4VWCVG
#Voidlink, A new era of malware has arrived! We discovered that the framework was built nearly end-to-end using agentic AI. It stands as an alarming example of what experienced actors are capable of using artificial intelligence.
https://t.co/4cGE620Nrd
Deep dive into the new #Sicarii ransomware: technical details and the bigger question - is it pure cybercrime, political signaling, or a possible false flag operation?
Read More :
https://t.co/jAOzQWmvTt
Check Point Research unveils #VoidLink, a highly modular Linux malware framework with 30+ plugins, cloud/container persistence, robust OPSEC (runtime encryption, rootkits, self-delete), and links to Chinese-affiliated actors. Full analysis on our blog
https://t.co/9ucKf6eyGC
Iranian threat actor #NimbusManticore (aka Smoke Sandstorm) launches advanced malware campaigns targeting Western Europe’s defense & telecom sectors with fake HR lures and evolving stealthy tools.
Read More -->
https://t.co/8Elb5SXdaz
Unmasking the China-nexus #Storm2603 toolset that pre-dated the ToolShell wave.
📅Active since at least Apr 2025.
🔑Multiple ransomware deployed together: LockBit + Warlock.
💥Custom backdoors: ak47dns & ak47http.
Read more -->
https://t.co/ah6i4DT1FG
Malicious executions of compiled JavaScript, leading to the of JSCEAL — a stealthy, multi-stage crypto stealer :
⚠️ Malicious ads for fake crypto apps installers
🧩 Modular PowerShell loaders
🕵️ Unique evasion techniques that kept the campaign undetected
https://t.co/S9DTH0QU0i
🚨 The Sting of Fake Kling: Our latest research uncovers a global malvertising campaign impersonating #KlingAI—delivering a masqueraded, multi-stage #infostealer.
https://t.co/Onbwih7j0G
CVE-2025-24054 was patched in Microsoft’s March 11 update, but just over a week later, threat actors began exploiting this NTLM Hash Disclosure Spoofing vulnerability in the wild.
Stay patched. 🔒
Read More -->
https://t.co/cGVWNO4ERu
#APT29 (#CozyBear) is back — this time with a twist of 🍷
📨 Fake diplomat wine event invites
🎯 Targeting government entities across Europe
🧬 New custom loader we’re calling #Grapeloader along with a new variant of #Wineloader
Read more --> https://t.co/l7s871LX0j