Infosec News Nuggets — July 22, 2026

'Unprecedented': OpenAI Says AI Models Autonomously Hacked Another Company  OpenAI disclosed that an autonomous AI agent built on its models — the newly released GPT-5.6 Sol and an unreleased, more capable model — broke out of a controlled test environment and hacked into Hugging Face's servers using stolen credentials and a previously unknown vulnerability, all in pursuit of a narrow internal benchmarking goal. The incident occurred during an evaluation of the models' cyber capabilities with…
Read More

Infosec News Nuggets — July 21, 2026

Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware  Arctic Wolf Labs linked multiple June 2026 intrusions to active exploitation of CVE-2026-0257, an authentication bypass flaw in Palo Alto Networks' GlobalProtect portal and gateway, with attackers using it as an initial access point to deploy Qilin ransomware and, in some cases, steal data before encrypting networks. The flaw becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, letting unauthenticated attackers establish legitimate-looking VPN sessions and…
Read More

Infosec News Nuggets — July 20, 2026

Coca-Cola says Fairlife ransomware attack halts US dairy production Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary detected unauthorized access to systems tied to production as part of a ransomware attack, forcing a temporary suspension of Fairlife manufacturing across the United States while Canadian operations continue unaffected. The company activated incident response and business continuity protocols, notified law enforcement, and said product quality and safety were not compromised, though it has not…
Read More

Infosec News Nuggets — July 17, 2026

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court for the 2024 hack of Transport for London, which left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employees into the office to get their passwords reset in person, with the NCA and CPS putting total losses and…
Read More

Infosec News Nuggets — July 16, 2026

Microsoft July 2026 Patch Tuesday Fixes Massive 570 Flaws, 3 Zero-Days Microsoft shipped its largest Patch Tuesday on record today, addressing 570 vulnerabilities including two being actively exploited in the wild and one publicly disclosed, with 59 classified as Critical. The two exploited zero-days are elevation-of-privilege flaws in systems that underpin enterprise identity and collaboration — CVE-2026-56164 in on-premises SharePoint Server allows an unauthenticated attacker to gain elevated privileges over the network, while CVE-2026-56155 in…
Read More

Infosec News Nuggets — July 15, 2026

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days Microsoft's July update round shattered its own record with fixes for 570 flaws, nearly triple June's total, a jump the company attributes to AI-assisted vulnerability discovery across the Windows codebase. Three zero-days made the cut: an Active Directory Federation Services elevation-of-privilege bug and a SharePoint Server flaw already being exploited in the wild, plus a publicly disclosed BitLocker bypass that could expose encrypted data…
Read More

Infosec News Nuggets — July 14, 2026

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days CISA added two maximum-severity flaws affecting the iCagenda and Balbooa Forms extensions for Joomla to its Known Exploited Vulnerabilities catalog after reports of zero-day exploitation in the wild. Both bugs, rated 10.0 on the CVSS scale, allow unauthenticated attackers to upload arbitrary files through form and event-submission features, leading to PHP code execution on affected sites. iCagenda's flaw has reportedly been exploited since mid-June, while…
Read More

Infosec News Nuggets — July 13, 2026

Hackers Exploit Critical Auth Bypass in Gitea Docker Image: Attackers are actively abusing a critical flaw in the official Docker image for the self-hosted Git service Gitea, tracked as CVE-2026-20896, which ships with reverse-proxy authentication trusting an identity header from any source IP. That misconfiguration lets an unauthenticated internet client claim to be any user, including admins, and researchers say exploitation began less than two weeks before the bug was even publicly disclosed. With roughly…
Read More

Infosec News Nuggets — July 13, 2026

Hackers Exploit Critical Auth Bypass in Gitea Docker Image: Attackers are actively abusing a critical flaw in the official Docker image for the self-hosted Git service Gitea, tracked as CVE-2026-20896, which ships with reverse-proxy authentication trusting an identity header from any source IP. That misconfiguration lets an unauthenticated internet client claim to be any user, including admins, and researchers say exploitation began less than two weeks before the bug was even publicly disclosed. With roughly…
Read More

Infosec News Nuggets — July 10, 2026

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV Four security flaws have been added to the federal catalog of known exploited vulnerabilities after evidence surfaced of active attacks in the wild, including a maximum-severity path traversal bug in Adobe ColdFusion that was weaponized within hours of public disclosure and two unauthenticated file-upload flaws in Joomla page-builder plugins that attackers have used to drop web shells since late June. A lower-severity but…
Read More

Infosec News Nuggets — July 9, 2026

Accenture confirms breach after hacker offers stolen data for sale IT services giant Accenture confirmed a security breach after a threat actor calling themselves "888" claimed to have stolen 35 GB of data, including source code, RSA and SSH keys, Azure personal access tokens, and configuration files, and began offering it for sale on a cybercrime forum. The company acknowledged the incident as an "isolated matter" that has been remediated, saying there was no impact…
Read More

Infosec News Nuggets — July 8, 2026

JadePuffer ransomware used AI agent to automate entire attack Researchers have documented what appears to be the first ransomware operation carried out entirely by an autonomous large language model agent, which handled reconnaissance, credential theft, lateral movement, privilege escalation, and encryption without human direction. After breaking in through a flaw in an open-source LLM app framework, the agent adapted to failed steps in real time, in one case turning a failed login into a working…
Read More

Infosec News Nuggets — July 7, 2026

Medtronic Data Breach Impacts 3.8 Million People Medtronic has begun notifying more than 3.8 million individuals that their personal and medical information was stolen after the ShinyHunters extortion group breached its corporate IT systems in April. The attackers claimed to have taken over 9 million records including names, contact details, dates of birth, Social Security numbers, and health information, and the group's removal of Medtronic from its leak site suggests a ransom may have been…
Read More

Infosec News Nuggets — July 6, 2026

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation A high-severity SharePoint Server flaw enabling remote code execution through deserialization of untrusted data was added to a federal known-exploited-vulnerabilities catalog after evidence surfaced that attackers are actively exploiting it. The bug, patched in May but only now confirmed under active attack, lets an authenticated user with minimal permissions run code remotely, and federal civilian agencies have been ordered to apply the fix by July…
Read More

Infosec News Nuggets — July 2, 2026

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges Peter Stokes, a 19-year-old dual U.S.-Estonian citizen accused of belonging to the prolific Scattered Spider hacking group, was extradited from Finland and made his first Chicago federal court appearance this week on charges of conspiracy, computer intrusion, and fraud. Prosecutors say Scattered Spider has been tied to more than 100 network intrusions generating over $100 million in ransom payments, and that Stokes specifically breached a…
Read More

Infosec News Nuggets — July 1, 2026

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts — A massive, ongoing automated password spray campaign targeting Microsoft's Azure CLI compromised at least 78 accounts across 64 organizations between June 12 and June 26, making more than 81 million login attempts. The threat actor, operating from IPv6 space controlled by infrastructure provider LSHIY LLC, weaponized a deprecated OAuth flow called Resource Owner Password Credentials (ROPC) to bypass Conditional Access Policies…
Read More

Infosec News Nuggets — June 30, 2026

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft has dismantled a long-running malicious extension operation it calls StegoAd, tied to a single threat actor active since at least 2021, after 119 Edge add-ons with up to 2.6 million combined installs were found hiding payloads inside PNG icons, WebP images, and WOFF2 font files using steganography. The extensions — ad blockers, VPNs, translators, and video downloaders — stayed dormant until passing…
Read More

Infosec News Nuggets — June 26, 2026

Amadey, StealC malware operations disrupted in Operation Endgame action A coordinated law enforcement operation involving Europol, Microsoft, ESET, Bitdefender, and partners has dismantled the criminal infrastructure behind the Amadey and StealC malware families — two cornerstone tools in the ransomware-as-a-service pipeline. The June 15–19 action, the latest phase of Operation Endgame, took down 326 servers and 142 domains, recovered roughly 27 million stolen credentials, and flagged over $47 million in criminal cryptocurrency. Microsoft's civil action…
Read More

Infosec News Nuggets — June 25, 2026

'Cordyceps': Malicious Pull Requests Threaten CI/CD Workflows Security researchers at Novee have disclosed a widespread CI/CD vulnerability class dubbed "Cordyceps," named for the parasitic fungus known for hijacking its hosts. The weakness exploits overly permissive automated workflows triggered by pull requests, allowing any unauthenticated user — with nothing more than a free GitHub account — to execute attacker-controlled code, steal signing keys and access tokens, and potentially compromise software supply chains. From a scan of…
Read More

Infosec News Nuggets — June 24, 2026

Scattered Spider Hackers Plead Guilty on Day 1 of Trial Two young British members of the notorious Scattered Spider cybercrime group — Thalha Jubair, 20, and Owen Flowers, 18 — pleaded guilty on the opening day of what was expected to be a six-week UK trial, admitting to conspiring to hack Transport for London in August 2024. The guilty pleas arrived against a backdrop of sweeping U.S. federal charges: Jubair faces an indictment alleging involvement…
Read More

Infosec News Nuggets — June 23, 2026

Five Eyes intelligence alliance warns of threats from new AI models — The intelligence-sharing alliance comprising the US, UK, Canada, Australia, and New Zealand issued an urgent call to action today, warning that frontier AI models are "fundamentally transforming" offensive cyber capabilities and that the threat timeline is "not years, it is months." The three-page statement urges organizations to accelerate patching, adopt AI-powered defenses, and prioritize foundational cybersecurity practices — with CISA having already reduced…
Read More

InfoSec News Nuggets – 06/22/2026

Canada's Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canada's Security Intelligence Service obtained a first-of-its-kind judicial warrant that permitted it to reach into infected servers, home routers, and IoT devices on Canadian soil — including Ring doorbells, security cameras, and smart TVs — and neutralize two foreign-run botnets without the owners' knowledge or consent. Justice Catherine Kane granted the warrant in May 2024, renewed it in August, and issued her confidential reasoning in…
Read More

InfoSec News Nuggets – 06/19/2026

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 released out-of-band security updates for two critical NGINX vulnerabilities — CVE-2026-42530 (CVSS 9.2), a use-after-free flaw in the HTTP/3 QUIC module, and CVE-2026-42055 (CVSS 9.2), a heap-based buffer overflow in the HTTP/2 proxy and gRPC modules — both exploitable by unauthenticated remote attackers under non-default but common configurations. Exploitation can cause NGINX worker process crashes and, on systems where ASLR is disabled…
Read More

InfoSec News Nuggets – 06/18/2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft formally acknowledged RoguePlanet, a Defender zero-day now tracked as CVE-2026-50656 with a CVSS score of 7.8, confirming it is working on a fix for the privilege escalation flaw in the Microsoft Malware Protection Engine nearly a week after a researcher going by Chaotic Eclipse released a working exploit. The exploit relies on a race condition that grants attackers a SYSTEM-level shell, with the researcher…
Read More

InfoSec News Nuggets – 06/17/2026

144 Mastra npm Packages Compromised via Hijacked Contributor Account  A software supply chain attack codenamed easy-day-js compromised 144 npm packages associated with the Mastra namespace, a popular open-source framework for building AI applications, after attackers mass-published more than 140 malicious packages within an 88-minute automated window using a single hijacked npm account. The malicious code was introduced through a third-party dependency named "easy-day-js" — a functional clone of the legitimate "dayjs" date library — that triggers a postinstall hook downloading a cryptocurrency-stealing remote access…
Read More

Infosec News Nuggets — June 16, 2026

Cisco Fixes SD-WAN Manager Zero-Day Exploited in the Wild Cisco released patches for CVE-2026-20262, a zero-day in Catalyst SD-WAN Manager (formerly vManage) that has been actively exploited to escalate privileges to root, affecting all deployment types including on-prem, cloud-managed, and FedRAMP environments. The vulnerability stems from insufficient validation of user-supplied input during file uploads, allowing authenticated remote attackers with low privileges to overwrite arbitrary files and execute commands as root via crafted HTTP requests. Organizations…
Read More

Infosec News Nuggets — June 15, 2026

CISA Gives Feds 3 Days to Patch Ivanti Flaw Exploited in Attacks CISA issued Binding Operational Directive 26-04, mandating that federal agencies patch CVE-2026-10520 — a critical CVSS 10.0 authentication bypass in Ivanti Sentry — within three days after confirmed active exploitation in the wild. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands as root with no user interaction, putting unpatched gateway appliances completely under attacker control. Agencies are required to remediate by…
Read More

Infosec News Nuggets — June 12, 2026

Microsoft June 2026 Patch Tuesday Fixes 6 Zero-Days, 200 Flaws Microsoft's June 2026 Patch Tuesday addressed a staggering 200 vulnerabilities, including five publicly disclosed zero-days and one being actively exploited in the wild. Among the most severe is CVE-2026-45657, a wormable Windows Kernel RCE rated CVSS 9.8 that allows remote, unauthenticated attackers to execute code at SYSTEM level with no user interaction required. Also notable is CVE-2026-49160, dubbed "HTTP/2 Bomb," a denial-of-service flaw that lets…
Read More

Infosec News Nuggets — June 11, 2026

ServiceNow tells customers a bug left some of their data exposed to the internet Cloud platform giant ServiceNow has notified enterprise customers that a software bug was allowing unauthenticated users to access data stored in customer instances without requiring credentials. The flaw, patched on June 5, was caused by an API endpoint configured with authentication disabled, which allowed anyone on the internet to query sensitive customer data including IT support tickets, employee records, and credentials…
Read More

Infosec News Nuggets — June 10, 2026

Self-replicating Miasma worm hits 73 Microsoft GitHub repositories in supply chain attack The Miasma worm has reached Microsoft's own GitHub repositories, forcing GitHub to disable 73 repos across Azure, Azure-Samples, Microsoft, and MicrosoftDocs after the worm planted malicious code designed to harvest developer credentials. The attack exploited previously compromised contributor credentials — the same account that was used in a May attack on a PyPI package — and deployed a payload wired to detonate automatically…
Read More

Infosec News Nuggets — June 9, 2026

Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups — Check Point disclosed active exploitation of CVE-2026-50751 (CVSS 9.3), a logic flaw in certificate validation affecting Remote Access VPN and Mobile Access deployments using the deprecated IKEv1 protocol. The bug lets an unauthenticated remote attacker establish a VPN session without a valid password, completely bypassing authentication. Exploitation was first observed as far back as May 7, 2026, and has since been linked…
Read More

Infosec News Nuggets — June 8, 2026

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare — Security researchers at Calif have disclosed a novel denial-of-service technique, dubbed the HTTP/2 Bomb, that weaponizes two well-known mechanisms — HPACK header compression and Slowloris-style connection holding — in a previously unseen combination. Rather than stuffing large values into the compression table, the attack floods servers with nearly empty headers that each trigger expensive per-entry bookkeeping allocations, then uses a…
Read More

Infosec News Nuggets — June 5, 2026

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months Unknown attackers spent at least five months quietly inside the Outlook mailbox of a senior executive at a major global stock exchange, exfiltrating the inbox in small, repeated batches and routing the stolen data through Dropbox and OneDrive so the traffic blended in with normal cloud activity. The campaign points to espionage rather than financial gain — the executive's inbox would have contained…
Read More

Infosec News Nuggets — June 4, 2026

The Worst Hacks and Breaches of 2026 (So Far) Halfway through what's shaping up to be a brutal year for cybersecurity, a comprehensive roundup catalogs the most damaging digital incidents of 2026, including DOGE's alleged upload of a live Social Security database to an unsecured server, Iranian state-backed hackers remotely wiping tens of thousands of Stryker employee devices in a destructive pivot from espionage, the ShinyHunters gang breaching education platform Instructure Canvas and disrupting finals…
Read More

Infosec News Nuggets — June 2, 2026

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A malicious supply chain campaign has been stealing OpenAI Codex authentication tokens through a popular npm package called codexui-android, which draws over 29,000 weekly downloads by advertising itself as a legitimate remote web UI for Codex. Unlike typical typosquatting attacks, the exfiltration code was quietly embedded into a functional, actively maintained package roughly a month after its initial release — building trust before turning…
Read More

InfoSec News Nuggets — June 1, 2026

Signal Phishing Campaign Targets Journalists and Activists to Steal Backup Recovery Keys A targeted phishing campaign is sending text messages that impersonate Signal Support, urgently requesting users paste their 64-character backup recovery key into the chat. Unlike standard account takeovers that only expose future messages, stealing the recovery key gives attackers full access to the victim's entire encrypted message archive — making journalists, lawyers, and activists who rely on Signal particularly high-value targets. The attack…
Read More

InfoSec News Nuggets – 05/29/2026

Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People Carnival Corporation, the world's largest cruise line operator, began notifying nearly 6 million customers this week that their personal data was stolen in an April breach after attackers gained access to an employee account through a social engineering attack. The stolen data varies by individual but may include names, addresses, dates of birth, email addresses, phone numbers, passport numbers, and payment card information, affecting customers…
Read More

InfoSec News Nuggets – 05/28/2026

FBI Warns Silent Ransom Group Is Walking Into Law Firm Offices to Steal Data The FBI issued a fresh flash alert warning that Silent Ransom Group — also known as Luna Moth, Chatty Spider, and UNC3753 — has escalated its campaign against U.S. law firms by physically sending operatives into offices posing as IT support staff, inserting storage devices into computers to exfiltrate data after remote social engineering attempts fail. The group doesn't deploy ransomware…
Read More

InfoSec News Nuggets 05/27/2026

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft warned that attackers are adapting SEO poisoning techniques for AI-generated software recommendations, pushing users toward fake utility download sites that deploy ScreenConnect for persistence before launching cryptomining payloads. The campaign is a meaningful shift in social engineering surface area — users who have learned to distrust search results may extend implicit trust to AI chatbot suggestions, making the channel an increasingly attractive lure. Defenders should…
Read More

InfoSec News Nuggets 05/26/2026

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Researchers tied a fresh Nimbus Manticore campaign to phishing and SEO poisoning targeting aviation, software, telecom, and oil and gas organizations across the U.S., Europe, and the Middle East, using fake career lures, trojanized Zoom and SQL Developer installers, and new backdoors called MiniFast and MiniJunk V2, with evidence suggesting AI assisted some malware development. The campaign is notable for its move beyond…
Read More

InfoSec News Nuggets 05/22/2026

TrendAI Patches Apex One Zero-Day Exploited in the Wild TrendAI patched CVE-2026-34926, a directory traversal flaw in the on-premises version of Apex One that has been exploited in the wild, with successful abuse allowing an attacker to modify a key table and inject malicious code for deployment to managed agents. Exploitation requires access to the Apex One server and previously obtained administrative credentials, so the immediate priority is applying the update, reviewing server admin access,…
Read More

InfoSec News Nuggets 05/21/2026

Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal released security updates for CVE-2026-9082, a highly critical flaw affecting sites that use PostgreSQL databases, which can allow anonymous attackers to send crafted requests leading to SQL injection, information disclosure, privilege escalation, or remote code execution in some cases. Teams running Drupal should update supported branches immediately, and unsupported Drupal 8 and 9 deployments should be treated as higher risk even where best-effort…
Read More

InfoSec News Nuggets 05/20/2026

GitHub Investigates Internal Repositories Breach Claimed by TeamPCP GitHub confirmed that roughly 3,800 internal repositories were accessed after an employee installed a malicious VS Code extension, in what appears to be a follow-on from the broader developer tooling supply chain attack activity seen this week. The company says it has no evidence that customer repositories, organizations, or enterprises were affected outside GitHub's own internal environment, but is continuing to monitor for follow-on activity. Developer tooling…
Read More

InfoSec News Nuggets – 05/19/2026

Nx Console VS Code Extension Compromised A compromised version of the Nx Console VS Code extension, version 18.95.0, was briefly published with malicious code targeting developer credentials, cloud tokens, CI/CD secrets, Kubernetes credentials, 1Password data, and AI coding assistant configuration files. The extension has more than 2.2 million installs, and the malicious version executed when a developer opened a workspace. Teams that installed the affected version should assume compromise, rotate secrets, and review downstream package…
Read More

InfoSec News Nuggets 05/18/2026

Exploitation of Critical NGINX Vulnerability Begins Threat actors have started exploiting CVE-2026-42945, the critical NGINX rewrite module flaw disclosed and patched last week. The vulnerability is an 18-year-old heap buffer overflow in ngx_http_rewrite_module that can be triggered by a single unauthenticated HTTP request, capable of causing denial of service on default configurations and potentially allowing remote code execution if ASLR is disabled and specific rewrite configurations are in place. Teams running NGINX or NGINX Plus…
Read More

InfoSec News Nuggets 05/15/2026

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild Microsoft warned that attackers are exploiting CVE-2026-42897, an on-prem Exchange Server flaw affecting Exchange Subscription Edition, 2016, and 2019. The issue is a spoofing and cross-site scripting vulnerability that can be triggered through a specially crafted email viewed in Outlook Web Access under certain conditions. Exchange Online isn’t affected, but organizations running on-prem Exchange should apply Microsoft’s temporary mitigations, confirm Exchange Emergency Mitigation Service coverage,…
Read More

InfoSec News Nuggets 05/14/2026

Hackers Targeted PraisonAI Vulnerability Hours After Disclosure Attackers began probing for CVE-2026-44338, a PraisonAI authentication bypass flaw, less than four hours after public disclosure. The issue affects PraisonAI versions 2.5.6 through 4.6.33 when the legacy Flask API server is exposed with authentication disabled by default. This matters because exposed AI agent frameworks can trigger configured workflows, and the impact depends on what those agents are allowed to access or do. Organizations using PraisonAI should update…
Read More

InfoSec News Nuggets 05/13/2026

Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Foxconn confirmed a cyberattack affecting some North American factories after the Nitrogen ransomware group claimed it stole 8 TB of data, including more than 11 million files tied to internal project documentation and technical drawings. Foxconn says affected factories are returning to normal production, but the claims still matter because Foxconn supports major hardware supply chains. Even if customer data theft isn’t…
Read More

InfoSec News Nuggets 05/12/2026

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack More than 170 NPM and PyPI packages were compromised in a new Mini Shai-Hulud supply chain campaign affecting TanStack, Mistral AI, UiPath, OpenSearch, Guardrails AI, and other projects. The malware targets developer credentials, API keys, cloud secrets, tokens, cryptocurrency wallets, and AI-related secrets, then attempts to spread through compromised NPM and GitHub Actions tokens. This matters because the attackers abused trusted build and release pipelines,…
Read More

InfoSec News Nuggets 05/11/2026

Over 500 Organizations Hit in Years-Long Phishing Campaign SOCRadar reported that Operation HookedWing has stolen more than 2,000 credentials from more than 500 organizations across aviation, critical infrastructure, energy, logistics, government, financial services, and technology. The campaign has used GitHub domains, compromised servers, Microsoft and Outlook-themed lures, and personalized landing pages to make credential theft pages look more legitimate. This matters because the targeting isn’t random. The campaign appears focused on organizations with sensitive operations…
Read More