Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This blog entry from Trend Micro's TrendAI Research analyzes a phishing campaign in May 2026 targeting Japanese hotels. The attackers used Booking.com to deliver the TONResolver RAT, which leverages the TON blockchain.
Unit 42's threat brief provides mitigation guidance for large-scale credential attacks, focusing on recent campaigns that targeted security vendors' devices as initial access vectors. The recommendations include implementing multi-factor authentication, monitoring for anomalous credential usage, and applying vendor security patches promptly.
We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices.
This Unit 42 threat brief offers guidance on preparing for and mitigating large-scale credential attacks. It highlights recent campaigns specifically targeting security vendors' devices.
This Fortinet report details a Shai Hulud-linked attack that compromised CI/CD pipelines. It exposed Jenkins credentials, enabling AWS privilege escalation and a Redshift data breach.
This article details how a threat actor linked to Shai Hulud compromised a CI/CD pipeline to steal Jenkins credentials, then escalated privileges in AWS and breached a Redshift database. The activity was detected by FortiCNAPP, highlighting the risks of CI/CD to cloud data security.