Threat actors stories
Iran-linked cyber spies blend tactics to target US policy experts
This month
#
threat actors
Iran-linked cyber spies have combined tactics from multiple hacking groups in a new phishing campaign targeting US experts on Iranian politics and the IRGC.
Curly COMrades abuse Hyper-V for covert malware operations in VMs
This month
#
threat actors
Curly COMrades exploit Microsoft Hyper-V to run hidden malware inside lightweight VMs, evading detection and maintaining stealthy control over targets.
Ransom payment rates drop to historic low as attackers adapt
Last month
#
threat actors
Ransom payments fell to a historic low of 23% in Q3 2025 as cyber extortion tactics shift towards targeted, costlier attacks on larger firms.
Overconfidence threatens supply chain cyber security resilience
Last month
#
threat actors
Despite 94% public sector confidence in handling supply chain cyberattacks, nearly half faced breaches last year, revealing a troubling gap in resilience.
Ransomware groups surge as automation cuts attack time to 18 mins
Last month
#
threat actors
Automation and AI slash ransomware attack times to 18 minutes, challenging defenders to match speed with automated defences, says ReliaQuest report.
Ransomware’s business model reshapes costs as cybercrime hits USD $10.5 trillion
Last month
#
threat actors
Ransomware has evolved into a profit-centric business, driving cybercrime costs to USD $10.5 trillion and reshaping global cybersecurity risks and responses.
Expel Intel launches to deliver actionable threat intelligence insights
Last month
#
threat actors
Expel has launched Expel Intel, a new team providing actionable cyber threat insights based on real-world incidents to help security teams improve defences.
Oracle issues urgent patch as Cl0p exploits suite flaw for attacks
Last month
#
threat actors
Oracle has issued an urgent patch for a critical flaw in its E-Business Suite, exploited by the Cl0p ransomware group using advanced social engineering tactics.
Broadcom patches VMware zero-day exploited for nearly a year
Last month
#
threat actors
Broadcom patches a VMware zero-day flaw exploited for nearly a year, allowing attackers root access to virtual machines in certain configurations.
Chinese cyber group targets US policy bodies during trade talks
Thu, 18th Sep 2025
#
threat actors
A Chinese cyber group has targeted US government and policy organisations with spearphishing attacks amid trade talks, using advanced tactics to gain persistent access.
Vane Viper linked to over 1 trillion DNS queries & ad fraud scams
Wed, 17th Sep 2025
#
threat actors
Vane Viper, a threat actor posing as an adtech firm, generated over 1 trillion DNS queries last year linked to malware and ad fraud, warns Infoblox.
Lazarus subgroup deploys trio of RATs in finance sector attacks
Wed, 10th Sep 2025
#
threat actors
Lazarus subgroup deploys three remote access trojans, including PondRAT and ThemeForestRAT, to target financial and cryptocurrency organisations with advanced cyberattacks.
Bell Canada adds cybersecurity as core company service
Wed, 10th Sep 2025
#
threat actors
Bell launched Bell Cyber, aiming to build a CAD $1 billion AI-powered solutions business amid rising cyber threats in Canada.
Oyster Backdoor mimics IT management tools to target IT professionals
Wed, 27th Aug 2025
#
threat actors
Oyster Backdoor malware, disguised as WinSCP and PuTTY, targets healthcare IT professionals to enable ransomware operations like Rhysida, warns BlueVoyant.
Proactive threat intelligence boosts security & resilience
Mon, 25th Aug 2025
#
threat actors
Proactive threat intelligence enables organisations to anticipate cyber threats, enhancing security resilience and shifting focus from reactive to preventive defence strategies.
Global ransomware attacks rise as healthcare faces surge in cyber threats
Fri, 22nd Aug 2025
#
threat actors
Ransomware attacks surge to 20 daily incidents in 2025H1, with healthcare facing increased cyber threats and hackers targeting overlooked IoT devices worldwide.
Phishing campaign uses fake Microsoft apps to bypass MFA
Tue, 19th Aug 2025
#
threat actors
Proofpoint exposes phishing attacks using fake Microsoft apps to bypass MFA and hijack Microsoft 365 accounts, affecting thousands globally in 2025.
Half of Australian government agencies lack top email security
Fri, 15th Aug 2025
#
threat actors
Half of Australian government agencies have not adopted the strongest email security, risking cyberattacks on sensitive public sector data and communications.
LevelBlue & Akamai launch managed service for web app security
Fri, 15th Aug 2025
#
threat actors
LevelBlue and Akamai have teamed up to offer a managed web app and API security service, tackling rising threats with AI-driven, 24/7 protection and expert support.
ANZ firms face rising repeat ransomware attacks & executive threats
Mon, 11th Aug 2025
#
threat actors
Ransomware attacks in Australia and New Zealand have surged, with one in three incidents repeated and executives facing rising physical threats, warns new report.