On 2026-04-18, AlienVault released a comprehensive threat report titled "Operation PhantomCLR: Stealth Execution via AppDomain Hijacking and In-Memory .NET Abuse." The report details a highly sophisticated multi‑stage post‑exploitation framework that has been actively targeting organizations within
Continue ReadingAuthor: Tudorel Iancu
UNC1945 Threat Overview Leveraging Custom Islands for Targeted Infiltration
UNC1945 Threat Overview Leveraging Custom Islands for Targeted Infiltration Published by CyberHunter_NL on 2026-04-17, this threat report delivers a comprehensive analysis of the actor group UNC1945. The report focuses on the financial and professional consulting sectors,
Continue ReadingAPT Group Targets Web3 Support Teams With Malware Hidden as Customer Screenshots
On 17 April 2026, the threat intelligence community received a new threat report from CODERED_VTA titled Working the Queue: APT‑Q‑27 Malware Targets Web3 Customer Support. The report details a highly targeted campaign that exploits the human
Continue ReadingN8N N8mare How Threat Actors Exploit AI Workflow Automation
N8N N8mare How Threat Actors Exploit AI Workflow AutomationThe latest threat report from Cisco Talos, published 2026-04-16, uncovers a sophisticated malware campaign targeting Taiwanese non‑governmental organizations and universities. The campaign centers on a Lua‑based stager named
Continue ReadingChrome Extensions Campaign Causes Data Theft and Session Hijacking
Executive Summary On 2026-04-14 a coordinated campaign of 108 malicious Chrome extensions was uncovered by AlienVault. The extensions, published under five different developer names, share a single command‑and‑control (C2) infrastructure that harvests Google identities, steals Telegram
Continue ReadingAdobe Reader Zero Day Exploitation
On April 7 2026, a security researcher disclosed a critical zero‑day vulnerability in Adobe Reader that has been actively exploited in the wild since at least December 2025. The flaw allows threat actors to execute privileged Acrobat APIs via
Continue ReadingFake Windows Support Site Distributes Password Stealer
The latest threat landscape feature a highly convincing fake Microsoft support website that is designed to deliver a password‑stealing malware bundle. The campaign, first spotted on microsoft-update.support, masquerades as an official Windows update portal and lures
Continue ReadingPawn Storm Launches PRISMEX Campaign Targeting Government and Critical Infrastructure
Threat Overview The Russian‑aligned Advanced Persistent Threat (APT) group Pawn Storm (also known as APT28, Fancy Bear, UAC‑0001, Forest Blizzard) has released a new campaign that leverages the PRISMEX malware suite to target the Ukrainian defense
Continue ReadingClickFix Threats Target Windows And macOS Systems
Executive Summary The Insikt Group’s latest intelligence reveals a sophisticated, multi‑cluster social engineering campaign known as ClickFix. Leveraging deceptive interfaces that mimic trusted applications such as Intuit QuickBooks and Booking.com, the threat actors compel victims to
Continue ReadingTrivy To Checkmarx Supply Chain Compromise Expands
Background On March 19 2026, the threat actor TeamPCP compromised Aqua Security’s Trivy vulnerability scanner and its GitHub Actions, injecting a credential‑stealing payload into CI/CD pipelines across thousands of repositories. The malicious code was delivered through
Continue Reading