
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100

Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100

Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems

Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing

Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an

Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.

Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.

Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.

RatHat malware-as-a-service banking trojan analyzes stolen Android data with Google Gemini AI to prioritize victims with higher financial value.

Stolen infostealer data exposed AI service credentials from over 80,000 corporate domains, enabling account takeover and LLMjacking attacks.

Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.