MalwareRecorded Future·1 week ago

Malware Crypting Services and the Threat Actors Who Sell Them

Recorded Future's Insikt Group has analyzed 24 threat actors operating in the malware crypting services market, revealing how these services enable evasion of security tools through obfuscation. The research examines the market dynamics of these offerings and highlights the evasion techniques employed, while recommending that defenders shift focus toward behavioral detection methods rather than relying solely on static analysis. This analysis provides threat intelligence professionals with insights into a key enabler of malware distribution and guidance for more effective detection strategies.

PhishingGraham Cluley·1 week ago

Smashing Security podcast #480: This is the AI service you should never sign up to

A fraudulent service called "Poison Claude" is luring users with counterfeit discounts on Anthropic's Claude AI, demonstrating how attackers exploit popular AI tools to compromise victims. Additionally, a phishing-as-a-service platform named "Greatness" has developed a sophisticated attack that leverages legitimate Microsoft login pages to bypass traditional security indicators and gain full organizational access without requiring fake URLs or password theft.

Data BreachDark Reading·1 week ago

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A sophisticated campaign tracked as "City-Forum" has been conducting data theft operations against Salesforce and ServiceNow users since at least March 2025, leveraging custom-developed tools to compromise targets across various industries. The long-running nature of the operation suggests a well-resourced threat actor with sustained capability against popular enterprise platforms.

VulnerabilityThe Register·1 week ago

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Researchers have demonstrated that RISC-V processors are vulnerable to Spectre attacks, revealing that the microarchitectural threat persists across different CPU instruction set architectures. The finding underscores that speculative execution vulnerabilities continue to pose security challenges nearly a decade after Spectre was first disclosed, suggesting that architectural defenses remain incomplete across diverse processor designs.

OtherQualys·1 week ago

Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation

Qualys has launched a real-time Cloud Security Posture Management solution designed to detect cloud configuration risks as they occur rather than waiting for periodic scans, reducing the window of exposure in dynamic cloud environments. The platform maintains support for traditional periodic scanning while correlating posture findings with vulnerability data to contextualize risk assessment across cloud infrastructure.

OtherDark Reading·1 week ago

Walmart Takes a 'Trusted Agent' Approach to Purple Teaming

Walmart is leveraging a collaborative purple teaming approach by colocating red and blue teams to strengthen its security posture through shared exercises and mutual trust-building. This integrated model combines offensive and defensive perspectives to identify vulnerabilities and improve overall defensive capabilities more effectively than siloed team structures.

MalwareInfosecurity Magazine·1 week ago

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

A threat actor has combined WindRelay NFC malware with SpyNote RAT to execute live-call scams that enable card cloning. The pairing allows attackers to intercept and manipulate card data during phone conversations, creating a coordinated fraud attack that leverages both near-field communication exploitation and remote access capabilities.

MalwareInfosecurity Magazine·1 week ago

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

The Lazarus threat group employed post-quantum cryptography in its key exchange mechanism while distributing a previously unknown Windows vulnerability, demonstrating sophisticated operational security practices. This approach suggests advanced threat actors are already integrating quantum-resistant encryption methods into their attack infrastructure ahead of mainstream adoption.

RansomwareInfosecurity Magazine·1 week ago

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Gunra ransomware actors are leveraging Fortinet vulnerabilities to compromise critical infrastructure while employing stealth tactics to exfiltrate large volumes of data from Microsoft services. US and Korean government agencies have jointly warned of this threat activity, highlighting the use of legitimate cloud services in data theft operations.

RansomwareHuntress Blog·1 week ago

Akira Hits Safe Mode: Ransomware Rebooting Around EDR

An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.

Policy & LegalRapid7 Blog·1 week ago

AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?

AI has moved from experimental pilot programs to embedded production systems in security operations centers, with 97% of SOC teams reporting positive outcomes—yet security executives are notably more concerned than frontline staff about data governance, accountability, and risk management. The confidence gap reflects a maturity shift: operational teams validated that AI works, while leaders now grapple with harder questions about governance, oversight, and what happens when AI systems fail. The organizations pulling ahead aren't choosing between AI and human expertise; they're building models where AI handles volume and pattern matching while analysts retain decision authority, and buyers increasingly expect transparency into how AI decisions are made rather than simply faster automation.

Load more