// 3 CRITICAL · 2 ZERO-DAY · 3 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
phishing

ASCII Smuggling: From AI Attack to 2.37 Million Phishing Emails

A technique originally developed for prompt injection against language models has spawned a financial phishing campaign exceeding 2.37…

Sep 04, 2026views - 951

CYBERSEC

From AI to Inbox: The 'Invisible' Technique That Flooded Corporate Email

Microsoft detected a campaign sending over 2 million messages per day by embedding invisible Unicode characters inside financial keywo…

Sep 04, 2026views - 914

CYBERSEC

AI-Driven Attacks in Latin America: Unit 42 Exposes Two Operational Clusters

Palo Alto Networks' Unit 42 has uncovered two ongoing multi-stage intrusion campaigns across Mexico, Ecuador, and Brazil that leverage…

Sep 04, 2026views - 1k

CYBERSEC

ShinyHunters Tried to Hit ReliaQuest: Device-Trust Controls Stopped the Escalation

ReliaQuest confirms a contained social-engineering attack on August 22, 2026. Device-trust controls blocked lateral movement despite v…

Sep 03, 2026views - 1.1k

CYBERSEC

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript

The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

Sep 02, 2026views - 1.1k

CYBERSEC

Russian Extradited from Cyprus: Charged in Malware Campaign Targeting 80,000 Freelancers

Searzhudin Aktulaev was extradited to the U.S. for a 2016–2017 campaign that used malicious Excel files to infect freelancers. The mac…

Sep 02, 2026views - 1k

malware

Guildma's Brazilian Geofencing: Malware That Only Shows Up for Real Targets

A SANS researcher documented Guildma (Astaroth), a Latin American banking trojan active since 2017, delivering its payload exclusively…

Sep 02, 2026views - 1.1k

CYBERSEC

Spring Ring: The Teams Vishing Campaign That Jumps From Chat to Domain in Minutes

From January to April 2026, the Spring Ring campaign impersonated IT help desk staff on Microsoft Teams to trick employees into runnin…

Aug 31, 2026views - 1.1k

CYBERSEC

Infostealer on Attacker Workstation Exposes Blind Eagle Campaign

An information stealer infection on a suspected threat actor's workstation has laid bare the full infrastructure of a phishing campaig…

Aug 31, 2026views - 1.2k

CYBERSEC

Beacon CRM Breached, Robert Burns Trust Warns Donors: The Risk

A cyberattack on Beacon CRM, a SaaS provider for the non-profit sector, exposed contact data for over 1,000 organizations. The Robert…

Aug 31, 2026views - 1.2k

CYBERSEC

DOJ Corrects Record: NASA and Senate Were QTFY Targets, Not Victims

The U.S. Department of Justice revised its August 26 statement on August 29, 2026, clarifying that NASA, the U.S. Senate, and the Fede…

Aug 30, 2026views - 1.1k

CYBERSEC

TA4922 Launches PackClient Campaigns in Asia: Modular RAT Bought on Telegram

Chinese threat group TA4922 deployed the PackClient RAT framework across China and India via tax-themed phishing between May and July…

Aug 30, 2026views - 1.1k