Hospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint EmailsSecurity Affairs·Jun 28, 15:07 UTC · Jun 28, 2026Threat actor157
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2026Threat actor in the wildCVE-2026-2023060
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js ImplantThe Hacker News·Jun 26, 09:27 UTC · Jun 26, 2026Threat actor57
Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Threat actor60
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code TunnelsThe Hacker News·May 30, 06:13 UTC · May 30, 2026Threat actor157
Chinese Threat Actors Shift to Live Credential InterceptionInfosecurity Magazine·May 26, 14:45 UTC · May 26, 2026Threat actor45
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto FraudThe Hacker News·Apr 30, 06:30 UTC · Apr 30, 2026Threat actor45
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy CirclesThe Hacker News·Apr 22, 07:58 UTC · Apr 22, 2026Threat actor57
Attackers exploit Twilio's misconfigured cloud storage, inject malicious code into SDKHelp Net Security·Apr 20, 09:45 UTC · Apr 20, 2026Threat actor45
Thousands of Adobe Commerce stores hacked in competing CosmicSting campaignsSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Threat actorCVE-2024-3410260
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and CredentialsThe Hacker News·Mar 25, 07:01 UTC · Mar 25, 2026Threat actor45
First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft CredentialsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Threat actor57
Lazarus Campaign Plants Malicious Packages in npm and PyPI EcosystemsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Threat actor45
North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job InterviewsThe Hacker News·Jan 21, 17:17 UTC · Jan 21, 2026Threat actor57
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy OrganizationsThe Hacker News·Jan 12, 08:28 UTC · Jan 12, 2026Threat actor45
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users WorldwideThe Hacker News·Jan 1, 09:11 UTC · Jan 1, 2026Threat actor45
Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 SitesThe Hacker News·Dec 30, 07:57 UTC · Dec 30, 2025Threat actor57
ShadyPanda's 7-Year Campaign Infects 4.3M Chrome and Edge UsersInfosecurity Magazine·Dec 2, 15:10 UTC · Dec 2, 2025Threat actor57
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & MoreThe Hacker News·Nov 3, 17:59 UTC · Nov 3, 2025Threat actorCVE-2025-61932CVE-2025-55315CVE-2025-10680+18 CVEs160
BlueNoroff's latest campaigns: GhostCall and GhostHireKaspersky Securelist·Oct 28, 03:00 UTC · Oct 28, 2025Threat actor45
AI-Generated Code Used in Phishing Campaign Blocked by MicrosoftInfosecurity Magazine·Sep 29, 16:45 UTC · Sep 29, 2025Threat actor145
FileFix Campaign Using Steganography and Multistage PayloadsInfosecurity Magazine·Sep 17, 16:45 UTC · Sep 17, 2025Threat actor in the wild60
A new RevengeHotels campaign targets Latin AmericaKaspersky Securelist·Sep 16, 10:00 UTC · Sep 16, 2025Threat actorCVE-2017-019950
GhostAction Supply Chain Attack Compromises 3000+ SecretsInfosecurity Magazine·Sep 8, 11:00 UTC · Sep 8, 2025Threat actor57
Amazon shuts down watering hole attack attributed to Russia’s APT29 hacking groupThe Record·Sep 3, 00:03 UTC · Sep 3, 2025Threat actor145
Amazon Stops Russian APT29 Watering Hole AttackInfosecurity Magazine·Sep 1, 11:00 UTC · Sep 1, 2025Threat actor60
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code AuthenticationThe Hacker News·Aug 30, 04:26 UTC · Aug 30, 2025Threat actor45
Phishing Campaign Uses UpCrypter to Deploy Remote Access ToolsInfosecurity Magazine·Aug 26, 16:00 UTC · Aug 26, 2025Threat actor45
North Korea's Late 2017 Campaign Targeted South Korean Cryptocurrency UsersRecorded Future·Aug 23, 00:00 UTC · Aug 23, 2025Threat actorCVE-2017-8291CVE-2015-658560
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike DomainThe Hacker News·Jul 31, 10:03 UTC · Jul 31, 2025Threat actor45
Hackers Using PDFs to Impersonate Microsoft, DocuSign, and More in Callback Phishing CampaignsThe Hacker News·Jul 22, 07:17 UTC · Jul 22, 2025Threat actor45
China-Linked Hackers Launch Targeted Espionage Campaign on African IT InfrastructureThe Hacker News·Jul 21, 17:09 UTC · Jul 21, 2025Threat actor57
North Korean Actors Expand Contagious Interview Campaign with New MalwInfosecurity Magazine·Jul 15, 12:30 UTC · Jul 15, 2025Threat actor57
Widespread Campaign Targets Cybercriminals and GamersInfosecurity Magazine·Jun 4, 13:30 UTC · Jun 4, 2025Threat actor57
Large-Scale Phishing Campaigns Target Russia and UkraineInfosecurity Magazine·May 1, 16:00 UTC · May 1, 2025Threat actor57
I Went to See ‘God’s Influencer,’ the Millennial Saint Carlo Acutis404 Media·Apr 16, 12:40 UTC · Apr 16, 2025Threat actor60
Legacy Stripe API Exploited to Validate Stolen Payment Cards in Web Skimmer CampaignThe Hacker News·Apr 8, 03:53 UTC · Apr 8, 2025Threat actor45