CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.
A banking trojan moving through Portugal highlights a familiar fraud tactic: attackers often win by matching the victim's language, not just their code.
A Go-written malware operation reported to use 20+ RCE vectors shows how quickly AI connectors and MCP-style services can become a practical target for automation.
A macOS-focused information stealer detected by MistEye is reported to collect wallet databases, Keychain material, browser data, and Apple Notes, then use those fragments for offline cryptocurrency theft attempts.
A subscription phishing kit is using familiar cloud-sharing patterns and bot checks to steer Microsoft 365 users toward fake sign-in pages.
A campaign using spoofed security notices against LastPass and Bitwarden users shows how attackers can weaponize the very language of account protection to lure victims onto fraudulent websites.
A vishing campaign is steering Microsoft 365 users toward counterfeit Microsoft Entra ID login pages, showing how social engineering now targets the identity layer itself.
A GodDamn ransomware incident highlights a familiar but dangerous pattern: legitimate Windows tooling, credential harvesting, and rapid internal spread.
A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.
A credential-harvesting campaign tied to FortiGate access puts a spotlight on how stolen perimeter logins can move from IT inconvenience to industrial extortion risk.
A newer Kratos PhaaS flow is drawing attention because it appears designed to look more like routine sign-in friction while reducing the cues defenders normally use to triage phishing.
A targeted credential-phishing run is blending recruiter impersonation with layered redirects, turning ordinary job-seeker behavior into a trap for Google accounts.
A confirmed data breach at Moody Bible Institute shows how a large email exposure can become a launchpad for phishing, impersonation, and leak-driven pressure.
A credential-harvesting campaign tied to FortiGate devices shows how edge access can be repurposed into a ransomware foothold, even without a flashy new exploit.
A reported FortiGate credential-harvesting campaign tied to INC Ransom and Lynx shows how edge access can matter more to criminals than a new exploit.
A FortiGate credential-theft campaign is drawing attention not just for access theft, but for how stolen perimeter identities can feed ransomware operations.
A Fortinet credential-harvesting campaign known as FortiBleed highlights how stolen perimeter access can matter more than a new exploit.
A reported FortiBleed campaign shows how stolen credentials, not flashy malware, can become the most valuable product in an access-broker economy.
A Go-based tool tied to compromised FortiGate appliances turns the network edge into a credential risk, not just a traffic-control point.
A credential-harvesting operation tied to FortiGate appliances shows how exposed remote access can turn trusted security gear into an identity-risk magnet.