Microsoft Recognized as a Leader in the 2026 IDC MarketScape for MDR/MXDR for Enterprises
Security teams are tasked with protecting an expanding attack surface with limited personnel and around-the-clock vigilance, facing adversaries who never rest. As cybercriminals increasingly leverage AI to enhance and scale their operations, the frequency, speed, and complexity of threats are on the rise. Bridging this gap requires more than just tools; it necessitates a partner…
New StormEncryptor Ransomware Deployed by China-Linked Hackers, Likely Exploiting N-central Vulnerability
Microsoft has revealed that a financially driven threat group known as Storm-1175, associated with China, has introduced a new ransomware variant called StormEncryptor, which had not been documented before. This new ransomware signifies a departure from the adversary’s earlier use of Medusa ransomware, according to the Microsoft Threat Intelligence Team. According to Microsoft’s posts on…
New StormEncryptor Ransomware Utilized by Ex-Medusa Affiliate
A financially driven threat actor, previously linked to the Medusa ransomware group, has begun using a new ransomware variant known as StormEncryptor. Microsoft Threat Intelligence is monitoring this actor under the designation Storm-1175 and indicates that the recent attacks were likely preceded by the exploitation of an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring…
Hackers Target US Companies in FastJson RCE Zero-Day Exploits
Cybercriminals are currently taking advantage of a flaw in the FastJson open-source Java library, which enables remote code execution without the need for user interaction or elevated permissions. This security vulnerability impacts FastJson versions 1.2.68 to 1.2.83 and is being utilized in attacks against various entities in the United States. The malicious activities were detected…
Attackers Take Advantage of Command Injection Vulnerability in Arista VeloCloud Orchestrator
A critical security vulnerability affecting on-premises versions of Arista VeloCloud Orchestrator (VCO) is currently being exploited in the wild. This vulnerability, identified as CVE-2026-16812 (with a CVSS score of 10.0), involves operating system command injection that could enable arbitrary code execution. According to an advisory released by Arista on Monday, “VeloCloud Orchestrator (VCO) on-prem has…
FakeGit Campaign Exploits 7,600 GitHub Repositories to Distribute SmartLoader Malware
Cybersecurity experts have identified close to 7,600 harmful GitHub repositories, with over 800 masquerading as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to disseminate a malware variant known as SmartLoader, as part of an ongoing initiative referred to as FakeGit. According to Oleg Zaytsev, the lead security researcher at Island, in a…
JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware
The autonomous AI agent known as JadePuffer has been enhanced with a custom malware named EncForge, which is designed to encrypt AI-related assets, including training datasets, vector databases, and model checkpoints. Earlier this month, JadePuffer was identified as an agentic threat actor (ATA) capable of autonomously executing all phases of a ransomware attack, from gaining…
Exploitation of SonicWall SMA1000 Vulnerabilities as Zero-Days to Deploy Custom Malware
Recently, two vulnerabilities in the SonicWall SMA1000 were revealed to have been exploited in zero-day attacks for several weeks, enabling threat actors to install tailored malware on affected VPN devices. Last week, SonicWall issued a warning regarding the active exploitation of two previously unknown vulnerabilities in an exploit chain impacting SMA1000 Secure Mobile Access appliances….
We created a vulnerability vending machine: AI tokens in, zero-days out
Artificial intelligence is transforming the landscape of vulnerability research, yet much of the discussion remains theoretical, focusing on the potential capabilities of models rather than their current practical applications. Our goal was to address a more pragmatic inquiry: with the models we currently have access to, how effectively can AI assist in identifying genuine, exploitable…
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
A malware framework known as OkoBot has been operational on Windows systems since April 2025, with one of its components designed to deceive hardware wallet users into revealing their recovery phrases. On a compromised computer, the request originates from the wallet’s own desktop application. At times, it waits until the device is connected. The page…
