On January 13, 2026, AlienVault released a comprehensive threat report titled Booking.com Phishing Campaign Targeting Hotels and Customers. The analysis uncovers a sophisticated, multi‑stage phishing operation that specifically targets the hospitality sector. By compromising Booking.com administrator
Continue ReadingBlog
Black Cat Gang Uses Search Engines to Spread Counterfeit Notepad Backdoors
Black Cat Gang Threat Overview In a recent intelligence briefing released by AlienVault on 9 January 2026, security analysts were warned about a sophisticated campaign conducted by the criminal group known as the "Black Cat" gang.
Continue ReadingPHALT BLYX Fake BSODs Trusted Build Tools Threat Analysis
Threat Overview The latest intelligence from AlienVault, published on 2026-01-09, reveals a sophisticated campaign dubbed PHALT#BLYX that targets the hospitality industry. The adversaries employ a multi‑stage social engineering attack that begins with a phishing email designed
Continue ReadingPhishing Actors Use Complex Routing and Misconfigured Spoof Protections
Threat OverviewOn January 7 2026 AlienVault published a new threat report titled Phishing actors exploiting complex routing scenarios and misconfigured spoof protections. The analysis reveals that adversaries are leveraging advanced email routing techniques and weak spoof‑protection
Continue ReadingFortiWeb Exploitation Enables Persistent Sliver C2 Deployment
Threat Overview The latest threat intelligence report, published by CyberHunter_NL on January 6, 2026, details a sophisticated campaign in which a threat actor has leveraged multiple outdated FortiWeb web application firewalls to establish long‑term persistence via
Continue ReadingRogue ScreenConnect Social Engineering Tactics 2025
Threat Overview In 2025, security analysts observed a sharp rise in rogue ScreenConnect installations, a remote monitoring and management (RMM) tool widely used by IT teams worldwide. Threat actors hijacked the legitimate software to gain footholds,
Continue ReadingEmEditor Site Download Button Malware Incident
EmEditor Site Download Button Malware Incident Between December 19 and December 22, 2025 the official EmEditor website was compromised. Attackers hijacked the main download button and replaced the legitimate installer with a malicious payload. The fake
Continue ReadingMacSync Stealer Evolution: A Shift to Code-Signed Swift Malware
MacSync Stealer Evolution: A Threat Report MacSync Stealer Evolution: A Threat Report Executive Summary This report details the evolution of the MacSync Stealer malware, a macOS threat that has transitioned from relatively simple delivery mechanisms –
Continue ReadingWatchGuard Firewall Hijacking via Zero-Day Vulnerability
Threat Report: WatchGuard 0-day Exploitation Threat Report: WatchGuard 0-day Exploitation Report Published: December 21, 2025 18:13:42.191Z Source: CyberHunter_NL Executive Summary This report details the active exploitation of a critical zero-day vulnerability within WatchGuard firewalls. Hackers are
Continue ReadingUAT 9686 Targets Cisco Secure Email Gateway and Web Manager
Threat Overview On 2025-12-17 AlienVault released a new threat report titled UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager. The report details a Chinese-nexus advanced persistent threat (APT) that has been
Continue Reading