Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The FortiGuard Labs Incident Response team analyzed a QuickFox supply chain attack that used trojanized Windows installers. The attack featured selective targeting and an evolving FDMTP implant to compromise systems.
Nearly half of command-and-control malware samples bypass DNS by connecting directly to IP addresses. Implementing zero trust IP enforcement helps secure networks against these threats.
Nearly half of command-and-control malware samples bypass DNS by connecting directly to IP addresses. Implementing zero trust IP enforcement helps secure networks against these threats.
Nearly half of command-and-control malware samples bypass DNS by connecting directly to IP addresses. Implementing zero trust IP enforcement helps secure networks against these threats.
Microsoft warns that a Russian threat group is abusing hotel and conference Wi-Fi networks in a campaign called CaptiveCrunch. Attackers manipulate captive portals to steal logins, deliver malware, or perform machine-in-the-middle attacks.
Threat actors are increasingly using legitimate cloud services to host phishing pages and evade detection. This analysis covers how platforms like Cloudflare Workers and Vercel are abused for adversary-in-the-middle attacks and provides statistics on commonly abused domains.