May 2, 2026

Two Americans Sentenced for BlackCat Ransomware Attacks

Two Americans were sentenced for their roles in BlackCat ransomware attacks targeting U.S. victims. The case highlights the growing threat of ransomware-as-a-service, cyber extortion, data theft, and the need for stronger incident response, vulnerability management, and penetration testing.
May 3, 2026

Google AppSheet Phishing Hits Facebook Accounts

The AccountDumpling phishing campaign abused Google AppSheet, Netlify, Vercel, Google Drive, Canva, and Telegram to compromise about 30,000 Facebook accounts. This analysis explains how attackers used authenticated Google-sent phishing emails, fake Meta warnings, cloud-hosted landing pages, Telegram exfiltration, and real-time operator panels to steal credentials, 2FA codes, identity documents, and business account data.
May 4, 2026

Email Bombing Attacks Fuel Fake IT Support Scams

Email bombing attacks are being combined with fake Microsoft Teams IT support calls to trick employees into granting remote access through Quick Assist, AnyDesk, and similar tools. This analysis explains how the attack works, why it bypasses traditional controls, what risks organizations face, and how penetration testing, incident response, Microsoft Teams hardening, remote access restrictions, and employee verification procedures can reduce exposure.
May 5, 2026

pnpm 11 Blocks Risky New Package Installs

pnpm 11 enables minimum release age by default, delaying installation of newly published packages for 24 hours to reduce exposure to fast-moving npm supply chain attacks. This analysis explains how the feature works, why dependency cooldowns matter, what risks organizations face, and how penetration testing, incident response, CI/CD hardening, lockfile review, and package manager controls can strengthen software supply chain security.
May 6, 2026

Shadow Earth 053 Exploits Exchange Servers

SHADOW-EARTH-053 is exploiting known Microsoft Exchange and IIS vulnerabilities, including the ProxyLogon chain, to target government, defense, technology, and critical infrastructure organizations. This analysis explains how the China-aligned campaign uses GODZILLA web shells, ShadowPad malware, DLL sideloading, credential tools, WMIC, and proxy utilities, and what organizations should do to improve detection, incident response, penetration testing, and Exchange Server protection.
May 7, 2026

CloudZ RAT Abuses Windows Phone Link OTPs

CloudZ RAT is abusing Microsoft Phone Link through a custom Pheno plugin to potentially steal synced SMS messages, mobile notifications, credentials, and one-time passwords from compromised Windows PCs. This analysis explains how the malware works, why Phone Link synchronization can weaken MFA, what risks organizations face, and how penetration testing, incident response, endpoint monitoring, phishing-resistant MFA, and Phone Link policy controls can reduce exposure.