Cyber News

Identity Abuse Through Trusted Communication Channels

Identity Abuse Through Trusted Communication Channels

This Unit 42 research matters because it explains how identity attacks ride inside the tools employees already trust. The danger…

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix is valuable as a stand-alone story because it shows a modern ClickFix chain built for persistence, not just initial…

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Spring Ring is useful because it shows how collaboration platforms are becoming identity and access attack surfaces, not just communication…

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's Rhysida incident matters because it shows how quickly a public-sector cyber event becomes a data-governance and continuity problem once…

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA's latest KEV move matters because it turns two PaperCut flaws into an immediate exposure decision, not a routine backlog…

Identity Abuse Through Trusted Communication Channels

Identity Abuse Through Trusted Communication Channels

This Unit 42 research matters because it explains how identity attacks ride inside the tools employees already trust. The danger…

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix is valuable as a stand-alone story because it shows a modern ClickFix chain built for persistence, not just initial…

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42's AI-enabled malware research is useful because it separates hype from operational change. The story is not that attackers…

McKesson discloses breach after ShinyHunters claims patient data theft

McKesson discloses breach after ShinyHunters claims patient data theft

The McKesson disclosure is not valuable because of the raw record claim alone. It matters because it points to a…

PaperCut releases second emergency patch for exploited flaws

PaperCut releases second emergency patch for exploited flaws

PaperCut is warning that active exploitation now affects every NG and MF deployment, which makes this an exposure-mapping problem before…

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Unit 42's AI-enabled malware dataset is useful because it cuts through hype with numbers: 405 samples collected, only 12 observed…

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Arctic Wolf's GoCaracal research is useful because it adds specifics to the Dark Caracal story: a Go-based framework with lightweight…

Critical Avada WordPress theme flaw enables zero-click RCE

Critical Avada WordPress theme flaw enables zero-click RCE

CVE-2026-18431 is not a simple plugin bug. Wordfence says attackers can chain six weaknesses across the Avada theme and Fusion…