Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
What Am I Supposed to Do With This Threat Intelligence?Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Data breach60
New ExtraHop capabilities target malicious PowerShell use across enterprise environmentsHelp Net Security·Nov 5, 00:00 UTC · Nov 5, 2025Ransomware60
Critical Flaws in PowerShell Gallery Enable Malicious ExploitsInfosecurity Magazine·Aug 17, 17:00 UTC · Aug 17, 2023Exploit / PoC60
This Windows PowerShell Phish Has Scary PotentialKrebs on Security·Sep 19, 20:18 UTC · Sep 19, 2024Vulnerability55
Using the Manager Attribute in Active Directory (AD) for Password ResetsThe Hacker News·Oct 31, 15:56 UTC · Oct 31, 2021Phishing & fraud55
CVE-2019-0803 Windows flaw exploited to deliver PowerShell BackdoorSecurity Affairs·Apr 16, 07:03 UTC · Apr 16, 2019VulnerabilityCVE-2019-0803CVE-2019-0859160
Using DCOM objects for remote command executionKaspersky Securelist·Dec 19, 08:00 UTC · Dec 19, 2025Research155
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple StealersThe Hacker News·Dec 2, 05:40 UTC · Dec 2, 2025Malware55
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Case Study: Incident Response is a relationshipCisco Talos·May 17, 12:00 UTC · May 17, 2021Ransomware60
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Hafnium Update: Continued Microsoft Exchange Server ExploitationCisco Talos·Mar 10, 00:52 UTC · Mar 10, 2021Exploit / PoC60
Microsoft Urges Azure Users to Update PowerShell to Patch RCE FlawThe Hacker News·Jul 5, 06:42 UTC · Jul 5, 2021VulnerabilityCVE-2021-2670160
For many crooks, malware is out and PowerShell attacks are in, IBM saysCyberScoop·Feb 26, 14:22 UTC · Feb 26, 2019Malware in the wild60
91% of critical incidents involve known, legitimate binaries like PowerShellHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2018Malware55
The Gentlemen RaaS: rapid growth and a new ransomware variantKaspersky Securelist·Jun 30, 10:06 UTC · Jun 30, 2026Ransomware160
"PowerDrop" PowerShell Malware Targets US Aerospace IndustryInfosecurity Magazine·Jun 7, 16:30 UTC · Jun 7, 2023Malware55
Microsoft Confirms Two Exchange ZeroInfosecurity Magazine·Sep 30, 15:30 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
A closer look at fileless malware, beyond the networkHelp Net Security·Jan 4, 00:00 UTC · Jan 4, 2021Malware55
In Q2 2020, there was an average of 419 new threats per minuteHelp Net Security·Nov 6, 00:00 UTC · Nov 6, 2020Ransomware60
Fileless attacks against enterprise networksKaspersky Securelist·Feb 8, 08:58 UTC · Feb 8, 2017Exploit / PoC60
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active DirectoryThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware160
Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBotPalo Alto Unit 42·Jun 5, 23:28 UTC · Jun 5, 2024MalwareCVE-2017-1188260
Microsoft confirms Exchange zeroSecurity Affairs·Sep 30, 10:18 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
Iranian Hackers Exploit Log4j Vulnerability to Deploy PowerShell BackdoorThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2022VulnerabilityCVE-2021-4422860
CVE-2019-2725 Oracle WebLogic flaw exploited in cryptojacking campaignSecurity Affairs·Jun 11, 05:53 UTC · Jun 11, 2019Vulnerability in the wildCVE-2019-272560
The return of the AdvisorsBot malwareSecurity Affairs·Feb 1, 16:46 UTC · Feb 1, 2019MalwareCVE-2017-1188260
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
Cybersecurity on a budget: Strategies for an economic downturnCisco Talos·Oct 29, 10:00 UTC · Oct 29, 2025Ransomware60
Cryptocurrency Miner and Clipper Malware Spread via SourceForge Cracked Software ListingsThe Hacker News·May 20, 08:07 UTC · May 20, 2025Malware55
Multi-Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoaderThe Hacker News·Apr 18, 12:03 UTC · Apr 18, 2025MalwareCVE-2021-4044960
TookPS distributed under the guise of UltraViewer, AutoCAD, and AbletonKaspersky Securelist·Apr 2, 10:00 UTC · Apr 2, 2025Malware55