A coordinated operation has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks aimed at installing remote monitoring and management (RMM) and malware tools onto their machines. The campaign also attempts in some instances to compromise organizations' domain controllers. Researchers from Palo Alto Networks observed the operations - which they've dubbed "Spring Ring" - according to a report published this week. READ MORE...
A cybercrime group is infiltrating Brazilian financial systems to abuse payment infrastructure and send itself illegal transactions. Most hackers want money. Most of the time, they get it in some roundabout kind of way. They might convince vulnerable individuals to invest in fake currency exchanges. They might lock up all of a company's files, then hold them for ransom. "Breeze Comet," formerly known as UNC5669, goes straight to the source. READ MORE...
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no workarounds. READ MORE...
Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date. The SHARE Foundation said Wednesday that it found 14 people targeted in all, including one member of parliament and a local government official. READ MORE...
In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust. READ MORE...
The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else's database. Someone else's processes built it, someone else's judgement calls shaped it, and someone else's bad Tuesday is sitting it right now, waiting for the automation to act on it. READ MORE...
Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure Email have been publicly disclosed. The two flaws, tracked as CVE-2026-20354 and CVE-2026-20355, are medium-severity issues affecting the S/MIME decryption functionality of the threat protection solution. According to Cisco, insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways. READ MORE...
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. The plugin is used to back up, export, import, and move entire websites, including their databases, media, themes, and plugins, between servers or domains. The security flaw is tracked as CVE-2026-19949 and received a high-severity score. It was discovered by security researcher Jack Taylor. READ MORE...