Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim’s inherent trust in several different enterprise software providers. Threat Details In late December 2025, UNC6692 conducted a large email campaign designed to overwhelm the target with messages, creating a sense of urgency and distraction.
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite. Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration.
We initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found.
We initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found.
AI threats in the wild: The current state of prompt injections on the web. We initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns.
AI threats in the wild: The current state of prompt injections on the web. We initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns.