Executive Summary Between January and April 2026, Palo Alto Networks Unit 42 identified a coordinated social engineering operation that leveraged external Microsoft Teams accounts to masquerade as internal IT help desk personnel. The operation, dubbed Spring
Continue ReadingBlog
Arrest of Two TeamPCP Hackers in Australia
Threat Overview On 2026-08-27, Australian Federal Police (AFP) announced the arrest of two men from Western Australia, aged 21 and 23, who are suspected of leading the notorious cybercrime group TeamPCP. The group has orchestrated the
Continue ReadingIoT Botnet Water Systems SharePoint Exploits ThreatsDay Report
Threat Overview The latest ThreatsDay bulletin, published by The Hacker News on 2026‑08‑27, maps a sprawling landscape of cyber‑threats that span industrial control systems, cloud services, and everyday productivity tools. At its core is a 296,000‑device
Continue ReadingDark Caracal Returns New Malware Same Hunting Grounds
In late August, Arctic Wolf Labs released a detailed threat report titled Dark Caracal Reloaded: New Malware, Same Hunting Grounds that sheds light on the latest evolution of the Lebanon‑based state-sponsored group GDGS’s cyber espionage operations.
Continue ReadingAI-Enabled Malware State August 2026 Report
In August 2026, Palo Alto Networks Unit 42 released a comprehensive threat report titled “The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution.” The report synthesizes the findings of a 400‑sample analysis that
Continue ReadingCheck Point SmartConsole Authentication Bypass Vulnerability Report
Threat Overview Check Point has issued an urgent security advisory on August 25, 2026, describing three critical vulnerabilities that impact its Security Management, Multi‑Domain Management, Quantum Security Gateway, and Gaia operating system products. The most significant
Continue ReadingMicrosoft Entra ID Remote Code Execution Vulnerability Patched
Microsoft released a critical security bulletin on 23 August 2026 that addressed a remote code execution flaw in its Entra ID service, previously known as Azure Active Directory. The vulnerability, catalogued as CVE‑2026‑69836, received a maximum
Continue ReadingHead Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware
Threat Overview The Kaspersky Threat Report released on 2026-08-21 details a sophisticated attack by the Head Mare APT group that targets unpatched installations of the TrueConf video‑conferencing platform. By exploiting two internal vulnerabilities (KLCERT-26-057 and KLCERT-26-058)
Continue ReadingMirage2FA Hijacks Microsoft 365 Sessions Over 4K Victims in the US
Mirage2FA Hijacks Microsoft 365 Sessions Over 4K Victims in the US On 2026-08-20, Any Run published a detailed threat report that links the Mirage2FA phishing‑as‑a‑service (PhaaS) kit to more than 4,500 compromised Microsoft 365 accounts across
Continue ReadingMedusa Ransomware Threaters Steal Data Disable Security Tools and Encrypt Networks
In a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS), a new wave of ransomware activity has
Continue Reading