Cybercrime
-
GREYVIBE campaign targets Ukraine with phishing, fake sites and AI tools
GREYVIBE has targeted Ukraine-linked entities since at least August 2025 using phishing, fake CAPTCHA pages and fraudulent websites, while a WithSecure analysis says the group appears to have used AI tools to speed malware development.
-
Malicious NuGet package poses as Sicoob SDK to steal banking credentials
A malicious NuGet package posing as a Sicoob SDK stole banking credentials and certificate data from developers before being blocked, according to a technical analysis. Researchers said the package could expose payment-related API responses too.
-
Fake LinkedIn emails abuse Adobe service in phishing campaign
A phishing campaign is using fake LinkedIn business emails and Adobe Target to hide credential theft, with attackers disguising HTML attachments as PDFs and redirecting victims to a real LinkedIn page after login.
-
FBI warns of fake FIFA sites ahead of 2026 World Cup
The FBI warned that fake FIFA websites are being used ahead of the 2026 World Cup to steal data, sell bogus tickets and push other scams. Researchers said hundreds of phishing sites and related campaigns are already active.
-
Threat actors abuse patched FortiClient EMS flaw to push credential stealer
Threat actors are exploiting a patched FortiClient EMS flaw to push a credential stealer disguised as a Fortinet update, according to a technical analysis from Arctic Wolf. The campaign affects managed endpoints and can expose browser data, cookies and saved credentials.
-
Romanian man gets 56 months for hacking Oregon state network
A Romanian national was sentenced to 56 months in federal prison for breaching an Oregon state government network and selling access to other U.S. victims, in a case tied to at least $250,000 in losses.
-
New campaign targets crypto firms with macOS malware and supply chain attacks
A new campaign against cryptocurrency firms and developers used fake recruitment lures, macOS malware and a supply chain attack to steal credentials and target development infrastructure, according to a technical analysis by Wiz.
-
Grandoreiro and BTMOB campaigns target banking users in Europe and Latin America
Researchers say Grandoreiro and BTMOB are being used in separate campaigns against banking users in Europe and Latin America, combining phishing, DLL side-loading and Android social engineering with malware-as-a-service sales.
-
CrowdStrike and partners disrupt GlassWorm malware command channels
CrowdStrike said it and partners disrupted all command and control channels used by GlassWorm, a developer-targeting malware campaign that poisoned more than 300 GitHub repositories and used four separate infrastructure layers.
-
Microsoft says AI chatbot recommendations were used to steer users to cryptojacking sites
Microsoft said it blocked a cryptojacking campaign that used AI chatbot recommendations and search poisoning to steer users to fake software downloads, with more than 150 malicious domains identified and ScreenConnect used to deploy miners.







