Threat Overview In the past week, security researchers have identified a surge in phishing campaigns that target Microsoft OAuth Device Code flow, a feature designed to simplify authentication for devices that lack input capabilities. The technique,
Continue ReadingBlog
Critical Cisco FMC Vulnerability Enables Full System Takeover
Threat Overview On March 4, 2026, Cisco released a bundled security advisory (ERP‑75736) that highlighted 48 vulnerabilities across its Secure Firewall ASA, Secure Firewall Management Center (FMC), and Secure Threat Defense (FTD) software. Among these, two
Continue ReadingSigned Malware Mimicking Workplace Apps Deploys RMM Backdoors
In early 2026, a sophisticated phishing campaign surfaced that leveraged digitally signed malware to masquerade as trusted workplace applications. Threat actors distributed malicious executables that appeared to be legitimate software such as Microsoft Teams, Adobe Reader,
Continue ReadingNorth Korean Actors Abuse npm Ecosystem With Steganography Based Malware
Threat Overview On March 3, 2026, the research team at CODERED_VTA released a detailed threat bulletin exposing a new campaign by a North Korean threat actor group, informally dubbed FAMOUS CHOLLIMA. The actors have moved beyond traditional malware vectors
Continue ReadingGRIDTIDE Campaign Disruption Global Cyber Espionage Targeting Telecom and Gov
The threat landscape continues to evolve, and the recent disruption of the GRIDTIDE global cyber espionage campaign underscores the need for vigilance across all sectors. In this report, we analyze the tactics, techniques, and procedures (TTPs)
Continue ReadingAPT37 Expands Reach Into Air Gapped Systems
The latest threat analysis from Zscaler ThreatLabz reveals a sophisticated campaign orchestrated by the DPRK‑backed group APT37, also known as ScarCruft, Ruby Sleet, and Velvet Chollima. Published on March 1, 2026, the report details a multi‑stage
Continue ReadingPlugX Meeting Invitation via MSBuild and GDATA Threat Report
Threat Overview On 2026-02-27, CyberHunter_NL released a detailed threat report titled PlugX Meeting Invitation via MSBuild and GDATA. The report documents a sophisticated spear‑phishing campaign that leverages a legitimate G DATA antivirus executable and the Windows
Continue ReadingMoonrise RAT Low Detection High Cost Threat
In the fast‑moving world of cyber‑threats, a new remote‑access trojan (RAT) has been identified that flies under the radar of conventional signature‑based defenses. The RAT, dubbed Moonrise, was first documented in a 2026 AlienVault threat report
Continue ReadingActiveMQ Vulnerability Triggers LockBit Ransomware Attack
Threat Overview On 2026-02-23 the DFIR Report identified a multi‑stage intrusion that began with exploitation of the CVE‑2023‑46604 vulnerability in an internet‑facing Apache ActiveMQ instance. The threat actor achieved remote code execution via a malicious Spring
Continue ReadingAI Powered Mass Compromise of Internet Exposed FortiGate Management Interfaces
On 2026-02-22, Amazon Threat Intelligence released a detailed advisory titled "Advisory on AI-augmented mass compromise of internet-exposed FortiGate management interfaces (600+ devices reported). " The report documents a large‑scale cyberattack that spanned 55 countries and impacted
Continue Reading