A group calling itself pear has claimed an attack on Faro-Products-Inc., but the available record does not confirm a compromise.
Pear is tied to a new victim listing for Faro Products Inc., yet the available record does not confirm a breach, data theft, or operational impact.
A reported campaign pairs AI-generated first-stage code with a Python infostealer, showing how low-friction phishing can still reach high-value public and energy targets.
A reported campaign tied to APT-C-60 shows how a legitimate file-sharing service, a Windows shortcut, and a normal developer tool can be chained into a deceptive delivery path.
A reported spear-phishing campaign borrowed real event details, then used an ISO container and process injection to move RokRAT onto Windows systems.
A targeted phishing campaign used academic event PDFs and cloud links to deliver RokRAT, showing how trusted document workflows can be turned into an access path.
A callback-phishing lure uses fake account sign-in alerts to pull targets off the inbox and into a live voice scam, where trust is easier to exploit and harder to automate away.
A newly named threat group is being tied to phishing, AI-generated loaders, and BusySnake Stealer, a mix that turns one bad click into a broader credential risk.
A named ransomware crew is claiming an incident tied to a CPA firm and its website, but the real story is the pressure this kind of allegation puts on confidentiality, backup readiness, and incident verification.
A ransomware-extortion listing can be a pressure tactic, a real incident, or both - and for accounting firms, the difference matters because client data is often high value.
A comparison of email security tools is really a stress test for how organizations balance phishing defense, malware filtering, and data-loss controls across a very fragile channel.
A targeted email lure tied to aerospace branding reportedly used a password-protected archive, a multi-stage dropper, and legitimate remote-access software to create a stealthy access path.
A MedusaLocker listing tied to a masked .gc.ca domain shows how extortion crews can turn even a small batch of email addresses into pressure, while leaving defenders to separate signal from theater.
A phishing campaign built around fake job interviews and brand impersonation shows how a simple login prompt can become the endgame of a carefully staged social-engineering chain.
A targeted credential-phishing run is blending recruiter impersonation with layered redirects, turning ordinary job-seeker behavior into a trap for Google accounts.
A researcher-tracked phishing campaign used government-themed lures and a counterfeit filing tool to push DcRAT onto Windows systems, showing how trust in official workflows can be turned into an attack path.
A single command-and-control indicator can be enough to expose the wider shape of a credential-theft operation, especially when the target is a sector where email trust and operational continuity matter.
A newly observed malware framework uses a spoofed legal-document lure and a staged, fileless-oriented chain to hand off to CrownX ransomware capabilities.
A phishing-led intrusion chain tied to the Armored Likho label shows how a stealer, scheduled-task persistence, and covert tunneling can turn one inbox click into a durable access problem.
A phishing campaign using Interpol impersonation, formal wording, and legal references shows how trust itself becomes the delivery mechanism for malicious attachments.