2026-07-02 19:27 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software w…
P0
2026-07-02 18:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cloud application security keeps threat actors away from your data. We share practical ways to protect your apps and why it matters for your team today.
P0
2026-07-02 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malwa…
P0
2026-07-02 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
P0
2026-07-01 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress explains lateral movement attacks, how attackers move through networks, common techniques like pass-the-hash, and how Managed EDR stops lateral movement.
P0
2026-07-01 16:01 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE-ID Security Impact Rating CVSS Base Score Cisco Catalyst Center Arbitrary File Read Vulnerability CVE-2026-20191 High 7.5 ClamAV Vulnerabilities Affecting Cisco Products: July 2026 CVE-2026-20216CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20217CVE-2026-20243CVE-2026-20244 High 7.5 To fully remediate the vulnerabilities that were disclosed on July 1, 2…
P5
2026-07-01 15:10 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could all…
P5
2026-07-01 14:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-07-01 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Ransomware-as-a-Service turned ransomware into a scalable criminal business. Learn how the model works, why it creates so much disruption, and where defenders can shut attacks down before encryption starts.
P15
2026-07-01 08:35 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe.
P0
2026-07-01 06:00 UTC
Vendor Research
Cloudflare Security · Jin-Hee Lee · indexed 2026-08-15 18:58 UTC
Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.
P0
2026-06-30 20:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.
P0
2026-06-30 14:39 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
P0
2026-06-30 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Most Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.
P0
2026-06-30 12:00 UTC
Government
NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo, Heather Flanagan · indexed 2026-08-15 20:45 UTC
This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared the underlying credential formats (ISO/IEC “mdoc” vs. W3C Verifiable Credentials). In this post, we turn to the other side of the story: presentation; that is, how a holder shows their VDC to a verifier at runtime in both in-person and online contexts. We’ll ag…
P0
2026-06-29 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cybercriminals are hijacking Microsoft 365 accounts in seconds. Learn the 2026 hacker tactics, including ConsentFix, that bypass security training and exploit normal user behavior.
P0
2026-06-29 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented…
P0
2026-06-29 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Your inbox is an identity system all of its own: whoever owns it may own a lot more
P0
2026-06-29 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress responds to recent public allegations of an insider threat, separating fact from speculation and sharing how we approach ethics, transparency, and trust.
P0
2026-06-29 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analyzed a credential dumping attack where threat actors disabled Defender, killed monitoring tools, and used Mimikatz to steal credentials.
P0
2026-06-26 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
P0
2026-06-26 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what the average cost of a data breach is and how factors like industry and location impact it. Plus, learn how to protect yourself from costly breaches.
P0
2026-06-25 14:31 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link t…
P5
2026-06-25 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how MSPs/MSSPs can identify if a client is a DoD contractor handling CUI.
P0
2026-06-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cy…
P0
2026-06-25 09:30 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone an architectural shift from .NET to native C++, while continuing to leverage the Telegram Bot API for command and control, requiring no dedicated server infrastructure. This blog also profiles the developer “ShinyEnigma”, and threat actor cluster “Y2K Operators” responsible for active Millenium RAT exploitation campaigns. Over 62,000 compromised endpoints across more than 160 countries have been identified, w…
P0
2026-06-25 08:45 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
P0
2026-06-25 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See the 27 biggest data breaches in history, what caused each one, and how Huntress helps protect your business from being the next headline.
P0
2026-06-25 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn about some of the most common cyberattacks, how threat actors access computers and networks, and how to lower future risks.
P0
2026-06-24 12:35 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
P0