Topic
Reports

CTI Roundup: Rogue Tools, ClickFix, and BlueNoroff
Cyber attackers exploit legitimate tools, ClickFix attacks accelerate, and BlueNoroff targets macOS devices

CTI Roundup: Hazy Hawk, Remcos RAT, and npm Phishing
Recent news on Hazy Hawk using DNS records, a fileless Remcos RAT campaign, and the use of AES encryption with malicious npm packages in phishing attack.

CTI Roundup: Marbled Dust, Horabot, and TA406
Learn about Marbled Dust exploiting a zero-day vulnerability in Output Messenger, a new phishing campaign using Horabot malware, and TA406 changing targets.

CTI Roundup: Luna Moth, Venom Spider, StealC V2
Updates on Luna Moth threatening U.S. legal and financial firms, Venom Spider targeting hiring managers and recruiters, and StealC malware getting upgrades.

CTI Roundup: Infostealers, Zero-Day Attacks, and Gremlin Stealer
The latest news on infostealers, Google observing 75 zero-day exploits in 2024, and new threat Gremlin Stealer.

CTI Roundup: SMS Phishing, Node.js, and Fake PDF Converters
The latest news about threat actors exploiting SMS with social engineering, misusing Node.js for malware, and fake PDF converters delivering malware.

CTI Roundup: Email Attacks, Hunters International, and New Ransomware Data
Read the latest news about attacks combining credential phishing and malware, Hunters International pivoting to data extortion, and ransomware trends.

CTI Roundup: QR Code Phishing, Babuk Locker 2.0, and Qilin
QR code phishing accelerates, LockBit 3.0 rebrands, and Qilin affiliates target downstream customers of an MSP.

CTI Roundup: StilachiRAT, Reddit Infostealers, and New Password Reuse Data
The latest information about StilachiRAT malware, AMOS and Lumma stealers spreading via Reddit, and research on how many logins use compromised passwords.

CTI Roundup: Malvertising, XCSSET Variant, and GitHub Abuse
The latest news about a malvertising campaign threatening devices, XCSSET variant, and an ongoing campaign using fake GitHub repositories to spread malware.

CTI Roundup: Silk Typhoon, Fake Ransom Notes, and ClickFix
The latest cyber threat news on Silk Typhoon shifting tactics, threat actors targeting executives with physical ransom notes, and the ClickFix trick.

Drilling Down on Data Privacy: 5 Key Charts From ISACA’s 2025 Report
Regulations are pushing more enterprises to build data privacy programs, but ISACA researchers were surprised by some of the hows and whys – and why nots – revealed in this new report. We highlight five to guide enterprises in their own data privacy plans.