Hackers target Microsoft Entra accounts in device code vishing attacks

Hackers target Microsoft Entra accounts in device code vishing attacks

• Hackers target Microsoft Entra accounts via device code vishing, exploiting OAuth 2.0 flow. • Attack uses legitimate OAuth client IDs, bypassing phishing sites and standard login

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 1 min · 189 words
A week in security (February 9 – February 15)

A week in security (February 9 – February 15)

• Credential‑stealing Chrome extensions discovered; Malwarebytes Labs offers detection and removal guide. • Fake online shops target Winter Olympics 2026 fans, phishing for payment

Threat Intelligence · February 16, 2026 (updated February 24, 2026) · 1 min · 187 words

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

• CVE-2024-54529: type confusion in CoreAudio’s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje

Threat Intelligence · January 30, 2026 (updated February 24, 2026) · 1 min · 173 words
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

• CVE-2025-8088: critical path traversal flaw in WinRAR allows arbitrary file writes via ADS. • Exploited by state-backed actors from Russia, China and financially motivated groups

Threat Intelligence · January 27, 2026 (updated February 24, 2026) · 1 min · 168 words
Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

• CTA founded in 2014, uniting Palo Alto, Fortinet, McAfee, and Symantec for shared threat intelligence. • Shifted industry from proprietary intel to collaborative defense, raising

Cybersecurity · January 24, 2026 (updated February 24, 2026) · 1 min · 184 words
I scan, you scan, we all scan for... knowledge?

I scan, you scan, we all scan for... knowledge?

• Reconnaissance is often ignored, yet it’s essential for protecting networks. • Know your environment: attackers excel at mapping assets, from Windows 7 machines to smart fridges.

Threat Intelligence · January 22, 2026 (updated February 24, 2026) · 1 min · 194 words

KONNI Adopts AI to Generate PowerShell Backdoors

• KONNI leverages AI to auto-generate PowerShell backdoor scripts, streamlining malware development. • AI models produce obfuscated code, enhancing stealth against signature-based

Threat Intelligence · January 22, 2026 (updated February 24, 2026) · 1 min · 187 words
Pwn2Own Automotive 2026 - The Full Schedule

Pwn2Own Automotive 2026 - The Full Schedule

• Pwn2Own Automotive 2026 returns to Tokyo, featuring record 73 entries. • Competition spans real‑world automotive components, testing IVI and Level‑2 EV chargers. • Random draw se

Threat Intelligence · January 20, 2026 (updated February 24, 2026) · 1 min · 210 words
Impact of AI on cyber threat from now to 2027

Impact of AI on cyber threat from now to 2027

• AI is accelerating threat sophistication, enabling attackers to craft more convincing phishing campaigns. • Machine‑learning models are used to generate polymorphic malware that

Russian GRU Targeting Western Logistics Entities and Technology Companies

• Russian GRU’s 85th GTsSS unit 26165 targets Western logistics and tech firms. • Campaign focuses on coordination, transport, delivery of foreign aid to Ukraine. • Uses known TTPs

Cybersecurity · May 12, 2025 (updated February 24, 2026) · 1 min · 155 words

Fast Flux: A National Security Threat

• Fast flux hides malicious server locations by rapidly changing DNS records. • Enables cybercriminals and nation-state actors to evade detection and maintain C2. • Resilient, high

Cybersecurity · April 1, 2025 (updated February 24, 2026) · 1 min · 156 words
Threat report on application stores

Threat report on application stores

• Malware increasingly hides in legitimate app store listings, exploiting user trust for widespread infection. • Supply‑chain attacks target third‑party libraries, enabling attacke

The threat from commercial cyber proliferation

The threat from commercial cyber proliferation

• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac

The near-term impact of AI on the cyber threat

The near-term impact of AI on the cyber threat

• AI accelerates threat detection, enabling faster identification of malicious activity. • Adversarial AI allows attackers to craft evasive malware that bypasses traditional defens

The cyber threat to Universities

The cyber threat to Universities

• Universities face rising ransomware attacks targeting research data and student records. • Phishing campaigns exploit faculty credentials to gain network access. • Supply‑chain v

The Cyber Threat to UK Business

The Cyber Threat to UK Business

• Ransomware remains the top threat, targeting critical UK business data. • Phishing campaigns exploit remote working, increasing credential theft. • Supply‑chain attacks grow, com

The cyber threat to sports organisations

The cyber threat to sports organisations

• Sports organisations increasingly targeted by ransomware, phishing, and credential‑stealing attacks. • High‑profile events like the Olympics and World Cup attract sophisticated t

Summary of the NCSC analysis of May 2020 US sanction

Summary of the NCSC analysis of May 2020 US sanction

• US sanctions in May 2020 targeted Russian cyber actors and infrastructure. • NCSC identified increased threat actor activity following sanction announcements. • Sanctions disrupt

Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking

Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking

• BGP is critical for inter-ISP routing, requiring strict policy enforcement to prevent leaks and hijacks. • Implement prefix filtering and route origin validation to ensure only l

Incident trends report (October 2018 - April 2019)

Incident trends report (October 2018 - April 2019)

• Over 1,200 cyber incidents reported across 30 countries, highlighting rising ransomware activity. • Ransomware attacks surged 35%, with CryptoLocker variants targeting healthcare