Recorded Future's Insikt Group has analyzed 24 threat actors operating in the malware crypting services market, revealing how these services enable evasion of security tools through obfuscation. The research examines the market dynamics of these offerings and highlights the evasion techniques employed, while recommending that defenders shift focus toward behavioral detection methods rather than relying solely on static analysis. This analysis provides threat intelligence professionals with insights into a key enabler of malware distribution and guidance for more effective detection strategies.
A fraudulent service called "Poison Claude" is luring users with counterfeit discounts on Anthropic's Claude AI, demonstrating how attackers exploit popular AI tools to compromise victims. Additionally, a phishing-as-a-service platform named "Greatness" has developed a sophisticated attack that leverages legitimate Microsoft login pages to bypass traditional security indicators and gain full organizational access without requiring fake URLs or password theft.
A sophisticated campaign tracked as "City-Forum" has been conducting data theft operations against Salesforce and ServiceNow users since at least March 2025, leveraging custom-developed tools to compromise targets across various industries. The long-running nature of the operation suggests a well-resourced threat actor with sustained capability against popular enterprise platforms.
Researchers have demonstrated that RISC-V processors are vulnerable to Spectre attacks, revealing that the microarchitectural threat persists across different CPU instruction set architectures. The finding underscores that speculative execution vulnerabilities continue to pose security challenges nearly a decade after Spectre was first disclosed, suggesting that architectural defenses remain incomplete across diverse processor designs.
Qualys has launched a real-time Cloud Security Posture Management solution designed to detect cloud configuration risks as they occur rather than waiting for periodic scans, reducing the window of exposure in dynamic cloud environments. The platform maintains support for traditional periodic scanning while correlating posture findings with vulnerability data to contextualize risk assessment across cloud infrastructure.
Planning your cybersecurity budget shouldn't be a headache. See how to protect your business and get the most out of your security spend without the fluff.
Walmart is leveraging a collaborative purple teaming approach by colocating red and blue teams to strengthen its security posture through shared exercises and mutual trust-building. This integrated model combines offensive and defensive perspectives to identify vulnerabilities and improve overall defensive capabilities more effectively than siloed team structures.
A threat actor has combined WindRelay NFC malware with SpyNote RAT to execute live-call scams that enable card cloning. The pairing allows attackers to intercept and manipulate card data during phone conversations, creating a coordinated fraud attack that leverages both near-field communication exploitation and remote access capabilities.
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
The Lazarus threat group employed post-quantum cryptography in its key exchange mechanism while distributing a previously unknown Windows vulnerability, demonstrating sophisticated operational security practices. This approach suggests advanced threat actors are already integrating quantum-resistant encryption methods into their attack infrastructure ahead of mainstream adoption.
Gunra ransomware actors are leveraging Fortinet vulnerabilities to compromise critical infrastructure while employing stealth tactics to exfiltrate large volumes of data from Microsoft services. US and Korean government agencies have jointly warned of this threat activity, highlighting the use of legitimate cloud services in data theft operations.
An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.
AI has moved from experimental pilot programs to embedded production systems in security operations centers, with 97% of SOC teams reporting positive outcomes—yet security executives are notably more concerned than frontline staff about data governance, accountability, and risk management. The confidence gap reflects a maturity shift: operational teams validated that AI works, while leaders now grapple with harder questions about governance, oversight, and what happens when AI systems fail. The organizations pulling ahead aren't choosing between AI and human expertise; they're building models where AI handles volume and pattern matching while analysts retain decision authority, and buyers increasingly expect transparency into how AI decisions are made rather than simply faster automation.
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research