Latest Cybersecurity News and Articles

SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks

The Scattered LAPSUS$ Hunters (SLH) are actively recruiting women for IT help desk vishing attacks, offering $500–$1,000 per call. Recruits are provided with pre-written scripts to enhance the success of these social engineering attacks.

North Korea's APT37 Expands Toolkit to Breach Air-Gapped Networks

APT37, a North Korean cyber espionage group, has launched a new campaign named "Ruby Jumper" targeting air-gapped networks. The campaign introduces five new tools: Restleaf, SnakeDropper, ThumbSBD, VirusTask, and FootWine.

Madison Square Garden warns of data breach that leaked SSNs

Madison Square Garden (MSG) has reported a data breach that exposed names and Social Security numbers due to a zero-day vulnerability in Oracle’s E-Business Suite, managed by a third-party vendor.

Microsoft warns of RAT delivered through trojanized gaming utilities

Microsoft has identified a campaign involving trojanized gaming utilities, Xeno.exe and RobloxPlayerBeta.exe, which deploy a Remote Access Trojan (RAT). The RAT connects to a command and control (C2) server at IP address 79.110.49[.]15.

$4.8M in crypto stolen after Korean tax agency exposes wallet seed

A significant security lapse by South Korea's National Tax Service led to the theft of $4.8 million in cryptocurrency. The incident underscores the critical importance of safeguarding mnemonic recovery phrases.

Darktrace Flags 32 Million Phishing Emails in 2025 as Identity Attacks

The data was collected by Darktrace from incidents across its global customer base and points to a year defined by automation, convergence and accelerating attacker speed.
February 26, 2026

APT37 Adds New Tools For Air-Gapped Networks

ThreatLabz details the Ruby Jumper campaign in the following sections, focusing on the specific malware employed, the deployment methods, and how the final payload is delivered to achieve the ultimate objective.

Japanese chip-testing toolmaker Advantest suffers ransomware attack

Japanese tech testing company Advantest has suffered a ransomware attack, the company confirmed last Thursday, after detecting unusual activity within its IT environment on February 15, 2026.

APT28 Targeted European Entities Using Webhook-Based Macro Malware

APT28, a Russia-linked state-sponsored threat actor, has been attributed to a campaign targeting selected entities across Western and Central Europe, active from September 2025 through January 2026, according to S2 Grupo’s LAB52 team.

Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer

Atomic (AMOS) Stealer has evolved from being distributed via cracked software to a more sophisticated supply chain attack that manipulates AI agentic workflows on platforms like OpenClaw.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags