Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Defending the Authentication Flow: Device Code Phishing with Selena Larson

Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint and Host of the DISCARDED podcast, joins host Caleb Tolin to detail the specific mechanics of device code phishing campaigns, revealing how adversaries exploit legitimate communication structures to capture administrative and enterprise access. The discussion centers on the rapid commercialization of cybercrime, highlighting the leak of specialized kits in late 2025 that catalyzed the democratization of sophisticated technical exploits.

From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

Throughout 2026, Arctic Wolf has investigated multiple Anubis ransomware intrusions. Although threat actor tradecraft differs between intrusions, key themes have emerged: abuse of VPN infrastructure, blending in with legitimate activity through the use of Remote Monitoring and Management (RMM) solutions, and using other legitimate binaries on victim devices.

Ep. 4: The Sony Playbook

It’s been nearly 12 years since North Korea launched its crippling attack on Sony Pictures Entertainment over a Seth Rogen film. Most Americans remember the celebrity leaks, the embarrassing emails, the Hollywood spectacle of it all. What they missed was the playbook: Why simply hack an organization when you can bleed reputations dry? Turn stolen data into psychological warfare. It was a model that would soon echo everywhere from Russian intelligence operations to modern ransomware gangs.

What Is BlackSuit Ransomware & How Could It Impact Your Organization?

The BlackSuit ransomware operation surfaced in early April/May 2023. This group engages in multi-faceted extortion, encrypting and exfiltrating data from victims while hosting public data leak sites for those who do not comply with their demands. BlackSuit has notably targeted entities in the healthcare and education sectors, as well as other critical industries. It operates privately, with no public affiliates.

Ransomware vs Backup:Can You Recover Your Clients After an Attack?

Modern ransomware doesn't just encrypt systems—it targets backups too. In this webinar, learn why recovery often fails even when backups exist, how attackers compromise backup environments, and what it takes to build a ransomware-resilient backup strategy. Ideal for MSPs and IT professionals looking to strengthen cyber resilience and recovery readiness.

The "Macs Don't Get Viruses" Myth Is Officially Dead in 2026

For many years, Apple users have believed that Mac computers are naturally protected from cyber threats. This perception was shaped by the relatively low number of attacks targeting macOS in the past. However, the cybersecurity environment in 2026 presents a very different reality. As Apple's global market share has expanded and Mac users have become increasingly valuable targets, cybercriminals have shifted their focus toward developing attacks specifically designed for macOS.

Amadey and StealC: Malware-as-a-Service Unavailable

On June 24, 2026, demonstrating the power of public-private collaboration, Europol and the Microsoft Digital Crimes Unit, alongside our team and other global partners, executed a coordinated disruption as part of Operation Endgame, impacting two of the most prolific commodity malware families on Windows: the Amadey loader/botnet and the StealC information stealer.

The Growing Threat of ShadowPad Malware and Its Business Impact

ShadowPad, a sophisticated modular malware, has emerged as a significant cybersecurity threat. Attributed initially to Chinese state-sponsored threat actors (APT41), this malware has evolved into a shared tool among various APTs. Its highly customizable nature allows attackers to adapt ShadowPad to specific targets, making it a versatile and persistent threat.

The Hidden Security Risks of Unstructured Data in File Shares

Most organisations have a data problem they rarely see clearly. It is not always inside databases, CRMs, finance systems, or other structured platforms. More often, it is hidden in shared drives, old project folders, exported spreadsheets, PDFs, email attachments, archived documents, and duplicate files saved across departments. This is unstructured data. It is easy to create, easy to copy, and difficult to control. Over time, it can become one of the biggest blind spots in an organisation's cybersecurity and compliance strategy.

Ep. 3: The Americans - Exclusive Interview: Laptop Farmer Facilitating N. Korea's IT Worker Scandal

All North Korean IT worker schemes hinge on one thing: a willing participant in America. We found one, and knocked on her door. Experts have dubbed some of these Americans “laptop farmers.” The North Koreans call them “facilitators” – people willing to host multiple laptops in their home and happy to not ask too many questions. But identifying these people can be hard: unless you have access to a private Discord channel where North Korean IT workers talk freely among themselves.

The Deep Dive: Kroll's Analysis of the GARUDA C2 Malware

Kroll identified a cross-platform malware framework, dubbed GARUDA C2, that uses public code-hosting platforms like GitHub for staging, redundancy and command distribution across Windows, macOS and Linux. Analysis links the campaign to an India-based operator supported by Hindi-language development artifacts, build logs, infrastructure indicators and evidence suggesting use of a locally hosted large language model (LLM) to accelerate malware development.

Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries

In mid-June 2026, security researchers identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, dubbed FortiBleed. Threat actors have been systematically extracting configuration files from internet-facing FortiGate devices and cracking the stored credential hashes, resulting in verified working administrator credentials for between 30,000 and 75,000 devices across 194 countries.

Securing Financial Portfolios Against Modern Malware

The rapid migration of wealth management to cloud platforms introduces significant convenience for private investors. Managing a diverse set of assets now requires constant interaction with web applications. Digital dependency exposes capital to aggressive groups operating malicious software. Hackers regularly build malicious tools targeting financial balances and personal identification records. Standard defenses frequently fail against targeted threats. Protecting private capital requires a shift toward active defense measures.

Cloud Security Threats: How Prevention Cloud Protects Data

It is more important than ever to keep your data secure. Malware, ransomware, and attacks on cloud-based assets pose a constant threat to businesses as more sensitive data moves to the cloud. A report by Cybersecurity Ventures projected global cybercrime costs to reach $10.5 trillion annually by 2025. Data breaches, ransomware, fraud, and operational disruption are major contributors to cybercrime losses.

Ep. 2: The Cell - Accessing the Hidden Discord Ecosystem Behind the North Korea IT Worker Scandal

For the first time ever, host and former lead cybersecurity and digital espionage reporter for The New York Times Nicole Perlroth partners with a team of private investigators as they infiltrate a North Korean worker cell.

Ransomware Detection: Master Modern Strategies 2026

In 2024, ransomware was publicly disclosed in more than 5,600 attacks worldwide, with over 2,600 victims in the United States alone. The same reporting says the FBI's 2024 IC3 report logged 3,156 ransomware complaints, an 11.7% increase from the prior year, which is a useful reminder that this isn't a niche malware problem. It's a persistent operational risk that keeps showing up across sectors and environments (Fortinet's ransomware statistics summary).

The Rise of Pony Malware and What it Means for Organizations

Pony, also recognized as Fareit or Siplog, operates as an information stealer and loader, serving as malware designed to gather data from compromised systems and facilitate the installation of other malicious programs. This particular virus made its initial appearance in the wild in 2011, primarily targeting users in Europe and North America.

Ransomware Attacks: Evolution, Impact, and Recent Cases

Ransomware is a type of malware that blocks access to a victim’s system or network. Once the attack runs, it can encrypt selected files, lock systems, or disrupt access to business operations. Then, they demand a ransom in exchange for restoring access or providing a decryption key. In many cases, ransomware encrypts files so the victim cannot use them. Some ransomware can also lock systems or disrupt access to business operations.

Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation

The Securonix Threat Research team has identified an ongoing espionage campaign, tracked as SHEETCREEP, where threat actors deliver a C# remote access trojan through a diplomatic-themed ISO phishing lure.

Five myths about YouTube to mp3 converters, checked against reality

Search for a way to pull audio off YouTube and you walk straight into a fog of warnings, half-truths, and scare stories. Some of it is fair. Most of it is recycled nonsense that keeps people clicking the wrong things. Here are the five claims I hear most, weighed against what actually happens.

3-2-1-1-0 backup rule: Strengthening data protection against ransomware

Data loss is no longer a rare event—it is an inevitability. From ransomware attacks to accidental deletions, organizations must be prepared not just to prevent incidents, but to recover from them quickly and reliably. Modern threats increasingly target backup environments, making recovery readiness a critical component of any data protection strategy.

Home-Field Disadvantage: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup

The 2026 FIFA World Cup is a once-in-a-generation opportunity, and threat actors have already begun capitalizing on it. The 2026 FIFA World Cup, set to kick off on June 11, has already broken records for the most host nations, the most matches, and the highest amount of prize money to date for winning teams. Arctic Wolf set out to proactively investigate the criminal ecosystem surrounding the tournament.

Ep. 1: Strange Things Are Happening - How North Korean Threat Actors Infiltrated U.S. Businesses

A new breed of worker is quietly clocking in across the United States. They’re writing code, managing your passwords, training the next generation of AI models. They’re gaining trust and access. On paper, they’re the dream hire: skilled, low maintenance, always remote, and often affordable. By most accounts, they’re doing the work. But strange things are happening.

FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts

The US Federal Bureau of Investigation (FBI) has warned that a new phishing-as-a-service (PhaaS) platform called “Kali365” is targeting OAuth tokens to gain direct access to users’ Microsoft 365 accounts without stealing credentials or multifactor authentication codes. “Through the Kali365 platform subscription, cyber threat actors can capture ‘OAuth’ tokens and gain persistent access to targeted individuals/entities' Microsoft 365 environments,” the Bureau says.

Lucid Stealer Deep Dive

A publication-safe corporate blog analysis of a Node.js SEA information stealer and remote-access trojan. Foresiet Threat Intel Team identified and statically analyzed a newly observed Lucid Stealer build promoted through Telegram-linked underground channels. The sample is not a generic packed executable: it is a Lucid-branded credential stealer, wallet stealer and remote-access toolkit packaged inside a legitimate Node.js Single Executable Application wrapper.

Why Unmanaged IoT Devices Create Hidden Security Gaps

Why did the seven-month dwell time inside that hospital surprise nobody on my team? A smart HVAC controller in a third-floor conference room sat on a US healthcare network for seven months. IT security had never inventoried it. The SOC had never seen its traffic. Within 72 hours of initial compromise, the attacker had pivoted to corporate systems and reached patient records. The final bill, as compiled in public breach reporting, lands at $12.4 million.

Crowdsourced Chaos: The Evolution of NoName057(16) and Why DDoS Resilience Matters

According to Bitsight Threat Intelligence, NoName057(16) remains one of the most visible pro-Russian hacktivist groups conducting distributed denial-of-service (DDoS) attacks against countries and organizations perceived as supporting Ukraine. This matters because the risk can extend beyond direct business ties to Ukraine, and the group may also target organizations that do business with vendors, suppliers, partners, or service providers perceived as supporting Ukraine.

GitHub "Megalodon" Malware, Malware-Slop robs Claude, 7-Eleven breach & cPanel vulnerability [328]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community. Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows.