Loading…

Whats The Hax?

Daily intelligence on threats, breaches, and defenders

Latest
WeLiveSecurityThis month in security with Tony Anscombe – July 2026 editionSecurelistNetwork Anomaly Detection in KATAProofpoint News FeedMax-severity Exchange server flaw under active exploitation by Kremlin hackersSecurelistOctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central AsiaWeLiveSecurityBeyond the screenshot: Why you should verify what you seeSecurelistToy Ghouls’ new toy: the GenieLocker ransomwareRecorded FutureIran War’s Secondary Effects Shape 2026 US Violent ExtremismRecorded FutureDealing with AI-Generated ExtortionTrend Micro Research, News, PerspectivesWhy the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment FlexibilityTrend Micro Research, News, PerspectivesTracking Over 35,000 Fake Sites in the 2026 World Cup Scam WaveSecurelistMirage Kitten targets Middle East and Africa region with new malwareRecorded FutureRansomware is the ScoreboardTrend Micro Research, News, PerspectivesThe Signs Were There: What the First Autonomous Ransomware Case ConfirmsProofpoint News FeedNew warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractorsProofpoint News FeedRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesProofpoint News FeedUS and allies say Russian hackers stole emails without social engineeringRecorded FutureTAG-195 Upgrades MaaS Ecosystem with Modular ToolsTrend Micro Research, News, Perspectives13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in JapanTrend Micro Research, News, PerspectivesInside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind ItTrend Micro Research, News, PerspectivesFederal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. InfrastructureWeLiveSecurityThis month in security with Tony Anscombe – July 2026 editionSecurelistNetwork Anomaly Detection in KATAProofpoint News FeedMax-severity Exchange server flaw under active exploitation by Kremlin hackersSecurelistOctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central AsiaWeLiveSecurityBeyond the screenshot: Why you should verify what you seeSecurelistToy Ghouls’ new toy: the GenieLocker ransomwareRecorded FutureIran War’s Secondary Effects Shape 2026 US Violent ExtremismRecorded FutureDealing with AI-Generated ExtortionTrend Micro Research, News, PerspectivesWhy the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment FlexibilityTrend Micro Research, News, PerspectivesTracking Over 35,000 Fake Sites in the 2026 World Cup Scam WaveSecurelistMirage Kitten targets Middle East and Africa region with new malwareRecorded FutureRansomware is the ScoreboardTrend Micro Research, News, PerspectivesThe Signs Were There: What the First Autonomous Ransomware Case ConfirmsProofpoint News FeedNew warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractorsProofpoint News FeedRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesProofpoint News FeedUS and allies say Russian hackers stole emails without social engineeringRecorded FutureTAG-195 Upgrades MaaS Ecosystem with Modular ToolsTrend Micro Research, News, Perspectives13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in JapanTrend Micro Research, News, PerspectivesInside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind ItTrend Micro Research, News, PerspectivesFederal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure

By Source

Feeds organized so you can skim by site.

Density Sort
WE
WeLiveSecurity
2d ago · 20 items
20 loaded
SE
Securelist
2d ago · 10 items
Network Anomaly Detection in KATA 2d ago An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples. OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia 3d ago Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging. Toy Ghouls’ new toy: the GenieLocker ransomware 3d ago Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group. Mirage Kitten targets Middle East and Africa region with new malware 5d ago Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools. A new extortion cocktail: office printers, small ransoms, and BitLocker 12d ago We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations. New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery 12d ago Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses. HelloNet campaign: new malicious modules launched through the ViPNet update system 17d ago We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks). GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration 17d ago Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. OkoBot: new sophisticated malware framework targets cryptocurrency users 18d ago Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the R... Threat landscape for industrial automation systems. Q1 2026 26d ago This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.
PN
Proofpoint News Feed
2d ago · 10 items
Max-severity Exchange server flaw under active exploitation by Kremlin hackers 2d ago New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors 9d ago Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes 10d ago US and allies say Russian hackers stole emails without social engineering 10d ago The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of ​the Zimbra email program without having to fool them into opening ‌an attachment or clicking a link. If you pay a hacker’s ransom, chances are that they’ll come back for more 11d ago Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective 11d ago Global study reveals that AI is amplifying phishing, impersonation and credential theft, transforming ransomware into a human-centric extortion problem 40% OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 19d ago Hackers find a new trick to collect Microsoft Entra user data without raising red flags 20d ago Suspected Chinese snoops caught breaking into universities' Roundcube mailservers 25d ago Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen' New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams 32d ago Cargo theft is evolving with cybercrime. Learn how organized crime is hijacking shipments—from a $400,000 lobster theft to a $500,000 bourbon heist—and what needs to be done.
RF
Recorded Future
3d ago · 20 items
20 loaded
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility 3d ago Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave 4d ago The Signs Were There: What the First Autonomous Ransomware Case Confirms 9d ago 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan 10d ago Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It 10d ago Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure 10d ago Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass 11d ago Volume Is Not Risk: Making Sense of the 'Vulnpocalypse' 12d ago Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet 19d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry 34d ago
20 loaded
WE
WeLiveSecurity
19d ago · 48 items
Forgotten UEFI shims undermining Secure Boot 19d ago ESET Threat Report H1 2026 25d ago Cyber readiness for SMBs: Getting the basics right 30d ago This month in security with Tony Anscombe – June 2026 edition 33d ago Inside the inbox: Why cybercriminals want to break into your email account 34d ago SMB cyber readiness: the road to resilience starts here 37d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances 38d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc 39d ago Killing me gently: Inside Gentlemen’s EDR killer framework 45d ago Protecting legacy OT systems against modern cyberthreats 46d ago
48 loaded
TH
Threatpost
1432d ago · 10 items
Student Loan Breach Exposes 2.5M Records 1432d ago 2.5 million people were affected, in a breach that could spell more trouble down the line. Watering Hole Attacks Push ScanBox Keylogger 1433d ago Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool. Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms 1434d ago Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system. Ransomware Attacks are on the Rise 1437d ago Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group. Cybercriminals Are Selling Access to Chinese Surveillance Cameras 1437d ago Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed. Twitter Whistleblower Complaint: The TL;DR Version 1439d ago Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk. Firewall Bug Under Active Attack Triggers CISA Warning 1440d ago CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP. Fake Reservation Links Prey on Weary Travelers 1441d ago Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels. iPhone Users Urged to Update to Patch 2 Zero-Days 1444d ago Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack. Google Patches Chrome’s Fifth Zero-Day of the Year 1445d ago An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

No matching sources found.