Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Researchers published a working exploit called Certighost (CVE-2026-54121, CVSS 8.8) that lets low-privileged Active Directory users obtain a certificate for a Domain Controller and authenticate as that machine. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.
Google Threat Intelligence Group announces a unified naming schema for tracking threat actors, replacing separate systems from Mandiant and TAG. The update includes a table of new names for prominent actors to standardize public reporting.
Google Threat Intelligence Group is rolling out a unified naming schema for threat actors, using cryptonyms with two-word combinations. The first word is unique and memorable, while the second categorizes by motivation or origin, aiming to improve intuition and standardization.
Google Threat Intelligence Group is rolling out a unified naming schema for threat actors, using cryptonyms with two-word combinations. The first word is unique and memorable, while the second categorizes by motivation or origin, aiming to improve intuition and standardization.
Update (July 30): A table listing the new names of select prominent threat actors was appended to This.
German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its suspected developer in Indonesia during "Operation Olympus Blade." Over 200 servers were seized, disrupting a network used by 1,800 cybercriminals to launch 15,000 monthly phishing campaigns targeting U.S. and European victims. Kratos offered toolkits for credential theft, including an adversary-in-the-middle (AitM) mode to bypass multi-factor authentication (MFA).