2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults

2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults

• 2025 saw 47.1 million DDoS attacks, a 236% rise since 2023. • Cloudflare mitigated 5,376 attacks per hour, 3,925 network‑layer, 1,451 HTTP. • Network‑layer attacks tripled to 34.

CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats

• CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today issuedBin

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 270 words
The Shadow Campaigns: Uncovering Global Espionage

The Shadow Campaigns: Uncovering Global Espionage

• Executive Summary This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. • We refer to the group’s activity as the Shadow Campaigns. • We asse

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 217 words
Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT

Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT

• Introduction Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against organizations in Russia, Kyrgyzstan, Kazakhstan, a

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 258 words
Detecting backdoored language models at scale

Detecting backdoored language models at scale

• Today, we are releasing new research on detecting backdoors in open-weight language models. • Our research highlights several key properties of language model backdoors, laying t

Cybersecurity · February 4, 2026 (updated February 24, 2026) · 2 min · 252 words
From guardrails to governance: A CEO's guide for securing agentic systems

From guardrails to governance: A CEO's guide for securing agentic systems

• Treat AI agents as semi‑autonomous users, enforcing rules at identity, tool, data, and output boundaries. • Assign narrow job scopes and run agents under user‑level identities, l

Why Smart People Fall For Phishing Attacks

Why Smart People Fall For Phishing Attacks

• Threat Research Center Insights Opinions Why Smart People Fall For Phishing Attacks By:Ria Bhatia Ria Bhatia Published:February 3, 2026 Categories:Business Email CompromiseCyberc

Cybersecurity · February 4, 2026 (updated February 24, 2026) · 2 min · 252 words

PP095: OT and ICS - Where Digital and Physical Risks Meet

• OT & ICs bridge digital and physical, powering critical infrastructure like nuclear plants and water systems. • Rising attacks target OT/ICS, demanding robust threat awareness an

The Notepad++ supply chain attack - unnoticed execution chains and new IoCs

The Notepad++ supply chain attack - unnoticed execution chains and new IoCs

• UPD 11.02.2026: added recommendations on how to use the Notepad++ supply chain attack rules package in our SIEM system. • Introduction On February 2, 2026, the developers of Note

Cybersecurity · February 3, 2026 (updated February 24, 2026) · 2 min · 269 words

Please Don't Feed the Scattered Lapsus ShinyHunters

• Scattered Lapsus ShinyHunters (SLSH) uses harassment, threats, even swatting to extort firms. • They notify journalists and regulators, amplifying pressure beyond typical ransomw

Cybersecurity · February 2, 2026 (updated February 24, 2026) · 1 min · 181 words
Privileged File System Vulnerability Present in a SCADA System

Privileged File System Vulnerability Present in a SCADA System

• Iconics Suite SCADA system vulnerable (CVE-2025-0921) allows privilege escalation via unnecessary file system operations. • Exploitation can corrupt critical binaries, leading to

Cybersecurity · January 30, 2026 (updated February 24, 2026) · 1 min · 176 words

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

• CVE-2024-54529: type confusion in CoreAudio’s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje

Threat Intelligence · January 30, 2026 (updated February 24, 2026) · 1 min · 173 words

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

• In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-f

Cybersecurity · January 30, 2026 (updated February 20, 2026) · 2 min · 281 words
Understanding the Russian Cyberthreat to the 2026 Winter Olympics

Understanding the Russian Cyberthreat to the 2026 Winter Olympics

• Threat Research Center Insights Opinions Understanding the Russian Cyberthreat to the 2026 Winter Olympics By:Justin Moore Justin Moore Published:January 29, 2026 Categories:Cybe

Cybersecurity · January 29, 2026 (updated February 24, 2026) · 2 min · 258 words
Supply chain attack on eScan antivirus: detecting and remediating malicious updates

Supply chain attack on eScan antivirus: detecting and remediating malicious updates

• UPD 30.01.2026: Added technical details about the attack chain and more IoCs. • On January 20, a supply chain attack has occurred, with the infected software being the eScan anti

Cybersecurity · January 29, 2026 (updated February 24, 2026) · 2 min · 215 words

CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats

• CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) is calling on cri

Cybersecurity · January 28, 2026 (updated February 24, 2026) · 2 min · 281 words
Rust at Scale: An Added Layer of Security for WhatsApp

Rust at Scale: An Added Layer of Security for WhatsApp

• WhatsApp introduces Rust-based security layer to protect billions of users from malware threats. • The new media consistency library, written in Rust, runs on devices and browser

Building a serverless, post-quantum Matrix homeserver

Building a serverless, post-quantum Matrix homeserver

• Ported Synapse Matrix homeserver to Cloudflare Workers, creating a fully serverless architecture. • Eliminated heavy operational costs: no VPS, PostgreSQL tuning, Redis, reverse

Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

• CVE-2025-8088: critical path traversal flaw in WinRAR allows arbitrary file writes via ADS. • Exploited by state-backed actors from Russia, China and financially motivated groups

Threat Intelligence · January 27, 2026 (updated February 24, 2026) · 1 min · 168 words
Celebrating Data Privacy Week with NIST's Privacy Engineering Program

Celebrating Data Privacy Week with NIST's Privacy Engineering Program

• Data Privacy Week celebrates global awareness, led by the National Cybersecurity Alliance. • NIST’s Privacy Engineering Program plans 2026 privacy risk management guidelines. • P

Spy vs spy at scale

Spy vs spy at scale

• AI reshapes espionage, intensifying global intelligence rivalry and prompting new defensive strategies. • China’s tech surge fuels new espionage tactics and countermeasures, resh

Developer Ecosystem · January 27, 2026 (updated February 24, 2026) · 1 min · 174 words
HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

• HoneyMyte upgraded CoolClient backdoor with new features, enhancing persistence and stealth. • The group deployed multiple browser login data stealers across recent campaigns. •

Cybersecurity · January 27, 2026 (updated February 24, 2026) · 1 min · 177 words

Who Operates the Badbox 2.0 Botnet?

• Kimwolf botnet, 2M infected devices, compromised Badbox 2.0 control panel screenshot. • Badbox 2.0: China-based botnet on Android TV streaming boxes, over ten million devices, us

Cybersecurity · January 26, 2026 (updated February 24, 2026) · 1 min · 195 words

26th January - Threat Intelligence Report

• Article inaccessible; requires JavaScript to load content. • Unable to verify authenticity of threat intel data. • No actionable insights provided due to technical barrier. • Sug

Threat Intelligence · January 26, 2026 (updated February 24, 2026) · 1 min · 133 words
Open Source Software, Public Policy, and the Stakes of Getting It Right

Open Source Software, Public Policy, and the Stakes of Getting It Right

• Open Source software drives global innovation, research, and economic growth, worth $8.8 trillion. • Without Open Source, companies would spend 3.5× more on software, highlightin

Linux & Open Source · January 26, 2026 (updated February 24, 2026) · 1 min · 188 words

Bypassing Windows Administrator Protection

• A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. • The goal of this feature is to replace User Account Control (UAC) with a mo

Cybersecurity · January 26, 2026 (updated February 20, 2026) · 2 min · 251 words
Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

• CTA founded in 2014, uniting Palo Alto, Fortinet, McAfee, and Symantec for shared threat intelligence. • Shifted industry from proprietary intel to collaborative defense, raising

Cybersecurity · January 24, 2026 (updated February 24, 2026) · 1 min · 184 words

CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump's Executive Order 14306

• CISA releases first product categories list for post‑quantum cryptography (PQC) adoption. • List identifies hardware and software that support or will support PQC standards. • De

Cybersecurity · January 23, 2026 (updated February 24, 2026) · 1 min · 185 words
I scan, you scan, we all scan for... knowledge?

I scan, you scan, we all scan for... knowledge?

• Reconnaissance is often ignored, yet it’s essential for protecting networks. • Know your environment: attackers excel at mapping assets, from Windows 7 machines to smart fridges.

Threat Intelligence · January 22, 2026 (updated February 24, 2026) · 1 min · 194 words
The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time

The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time

• Attackers embed a benign page that calls an LLM API to generate malicious JavaScript in real time. • Prompt engineering bypasses AI safety guardrails, producing polymorphic phish

Cybersecurity · January 22, 2026 (updated February 24, 2026) · 1 min · 202 words
Pwn2Own Automotive 2026 - Day One Results

Pwn2Own Automotive 2026 - Day One Results

• 76 unique 0‑day vulnerabilities discovered across three days, totaling $1,047,000 in rewards. • Fuzzware.io clinched Master of Pwn with 28 points, outperforming rivals like Team

Threat Intelligence · January 21, 2026 (updated February 24, 2026) · 3 min · 465 words

Kimwolf Botnet Lurking in Corporate, Govt. Networks

• Kimwolf botnet has infected over 2 million IoT devices, enabling massive DDoS attacks. • It scans local networks of compromised systems to spread to additional vulnerable devices

Cybersecurity · January 20, 2026 (updated February 24, 2026) · 2 min · 274 words
DNS OverDoS: Are Private Endpoints Too Private?

DNS OverDoS: Are Private Endpoints Too Private?

Azure Private Endpoints can unintentionally expose resources to DoS attacks. Attack vectors include accidental admin deployments, vendor setups, and malicious actors. Over 5% of Az

Cybersecurity · January 20, 2026 (updated February 24, 2026) · 1 min · 183 words

VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun

• VoidLink showcases AI-generated malware capable of crafting polymorphic code. • The malware leverages generative models to evade traditional signature-based detection. • Checkpoi

Threat Intelligence · January 20, 2026 (updated February 24, 2026) · 1 min · 168 words

19th January - Threat Intelligence Report

• Unable to access threat intel report due to JavaScript requirement, preventing data retrieval. • Checkpoint Research site blocked without JavaScript, limiting threat intelligence

Threat Intelligence · January 19, 2026 (updated February 24, 2026) · 1 min · 167 words
Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering

Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering

• Threat Research Center Insights Anatomy of an Attack Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering By:Randy Stone Randy Stone Published:January 16

Cybersecurity · January 17, 2026 (updated February 24, 2026) · 2 min · 255 words

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte

Cybersecurity · January 14, 2026 (updated February 20, 2026) · 2 min · 259 words

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change

Cybersecurity · January 14, 2026 (updated February 20, 2026) · 2 min · 307 words

CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT

• CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA), United Kingdom’s National Cyber

Cybersecurity · January 14, 2026 (updated February 24, 2026) · 2 min · 254 words

Patch Tuesday, January 2026 Edition

• Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. • Eight of the vulnerabilities earned Microsof

Cybersecurity · January 14, 2026 (updated February 19, 2026) · 2 min · 283 words
Threat Brief: MongoDB Vulnerability (CVE-2025-14847)

Threat Brief: MongoDB Vulnerability (CVE-2025-14847)

• Executive Summary On Dec. • 19, 2025, MongoDB publicly disclosed MongoBleed, a security vulnerability (CVE-2025-14847) that allows unauthenticated attackers to leak sensitive hea

Cybersecurity · January 13, 2026 (updated February 24, 2026) · 2 min · 242 words
Remote Code Execution With Modern AI/ML Formats and Libraries

Remote Code Execution With Modern AI/ML Formats and Libraries

• Executive Summary We identified vulnerabilities in three open-source artificial intelligence/machine learning (AI/ML) Python libraries published by Apple, Salesforce and NVIDIA o

Cybersecurity · January 13, 2026 (updated February 24, 2026) · 2 min · 309 words

Who Benefited from the Aisuru and Kimwolf Botnets?

• Our first story of 2026 revealed how a destructive new botnet called Kimwolf has infected more than two million devices by mass-compromising a vast number of unofficial Android T

Cybersecurity · January 8, 2026 (updated February 24, 2026) · 2 min · 357 words

CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity

• CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA) announced the succe

Cybersecurity · January 8, 2026 (updated February 24, 2026) · 2 min · 264 words
Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk

Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk

• Threat Research Center Insights General Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk By:Kate MiddaghMichael Spisak Kate Middagh Michael Spisak Published:

Cybersecurity · January 8, 2026 (updated February 24, 2026) · 2 min · 265 words

The Kimwolf Botnet is Stalking Your Local Network

• The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. • The vulnerability at issue has been exploited for months alrea

Cybersecurity · January 2, 2026 (updated February 24, 2026) · 2 min · 407 words

Happy 16th Birthday, KrebsOnSecurity.com!

• KrebsOnSecurity.com celebrates its 16th anniversary today! • A huge ’thank you’ to all of our readers - newcomers, long-timers and drive-by critics alike. • Your engagement this

Cybersecurity · December 29, 2025 (updated February 24, 2026) · 2 min · 352 words
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi

Cybersecurity · December 29, 2025 (updated February 24, 2026) · 2 min · 278 words
Threat landscape for industrial automation systems in Q3 2025

Threat landscape for industrial automation systems in Q3 2025

• Table of Contents Statistics across all threats Selected industries Diversity of detected malicious objects Main threat sources Threat categories Malicious objects used for initi

Cybersecurity · December 25, 2025 (updated February 24, 2026) · 2 min · 337 words
Evasive Panda APT poisons DNS requests to deliver MgBot

Evasive Panda APT poisons DNS requests to deliver MgBot

• Introduction The Evasive Panda APT group (also known as Bronze Highland, Daggerfly, and StormBamboo) has been active since 2012, targeting multiple industries with sophisticated,

Cybersecurity · December 24, 2025 (updated February 24, 2026) · 2 min · 233 words
Assessing SIEM effectiveness

Assessing SIEM effectiveness

• A SIEM is a complex system offering broad and flexible threat detection capabilities. • Due to its complexity, its effectiveness heavily depends on how it is configured and what

Cybersecurity · December 23, 2025 (updated February 24, 2026) · 1 min · 199 words

Dismantling Defenses: Trump 2.0 Cyber Year in Review

• The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum o

Cybersecurity · December 19, 2025 (updated February 24, 2026) · 3 min · 494 words

CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness

• CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness WASHINGTON - Today, the Cybersecur

Cybersecurity · December 17, 2025 (updated February 24, 2026) · 2 min · 295 words

Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS)

• Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS) WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agenc

Cybersecurity · December 17, 2025 (updated February 24, 2026) · 2 min · 287 words

Most Parked Domains Now Serving Malicious Content

• Direct navigation - the act of visiting a website by manually typing a domain name in a web browser - has never been riskier: A new study finds the vast majority of ‘parked’ doma

Cybersecurity · December 16, 2025 (updated February 24, 2026) · 3 min · 543 words
Draft NIST Guidelines Rethink Cybersecurity for the AI Era

Draft NIST Guidelines Rethink Cybersecurity for the AI Era

• Official websites use .govA.govwebsite belongs to an official government organization in the United States. • Secure .gov websites use HTTPSAlock(LockA locked padlock) orhttps://

Welcome to the new Project Zero Blog

• While on Project Zero, we aim for our research to be leading-edge, our blog design was ⦠not so much. • We welcome readers to our shiny new blog! • For the occasion, we asked me

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 252 words

Thinking Outside The Box [dusted off draft from 2017]

• Preface Hello from the future! • This is a blogpost I originally drafted in early 2017. • I wrote what I intended to be the first half of this post (about escaping from the VM to

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 306 words

Windows Exploitation Techniques: Winning Race Conditions with Path Lookups

• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 259 words

A look at an Android ITW DNG exploit

• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl

Cybersecurity · December 12, 2025 (updated February 20, 2026) · 1 min · 207 words