Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Pikabot Malware: Delivery Methods, Evasion, and Impact

Originating in early 2023, Pikabot emerged as a significant malware loader. Over the past year, ThreatLabz has diligently monitored its development and operational methods. Notably, there was a surge in Pikabot’s usage in the latter part of 2023, attributed to a BlackBasta ransomware affiliate adopting Pikabot post the FBI-led Qakbot takedown. However, Pikabot’s activity ceased shortly after Christmas 2023, with version 1.1.19 marking its endpoint.

Mini Shai-Hulud hits openapi-react-query-codegen: 10 malicious npm versions

On August 28, 2026, ten malicious versions of @7nohe/openapi-react-query-codegen were published to npm between 20:00 and 20:21 UTC. The package generates React Query hooks from an OpenAPI schema and draws roughly 150,000 weekly downloads. The latest tag pointed at the malicious 3.0.4 for the duration of the window. Eight of the ten releases carry a multi-stage loader that reaches for cloud, registry, and developer credentials. The attacker needed no stolen npm token and no hijacked maintainer account.

Does It Make Sense to Pay a Ransom? A C-Suite Guide to DevOps Resilience

When ransomware hits, decision makers face an impossible ultimatum: pay the ransom or lose business operations. In software development, data criticality also comes to the forefront. That’s because source code isn’t just some trivial data, but primary intellectual property and a revenue driver. Let’s see what’s exactly at stake and how you can minimize the risk of paying a ransom for your tech business.

ESP32 Marauder tutorial for WPA2 deauthentication and handshake capture

Wireless networks are often assumed to be secure once WPA2 is enabled. In practice, that assumption is only partly true. While WPA2 remains widely used and is not inherently broken, the real security of a wireless network depends heavily on how it is configured, how client devices behave, and how strong the Pre-Shared Key (PSK) actually is. As a result, the protocol label alone can sometimes create a misleading sense of security.

Dark Caracal Reloaded: New Malware, Same Hunting Grounds

Arctic Wolf Labs exposes Dark Caracal’s evolving tradecraft, linking 249 samples to two operational build profiles and a resilient Ethereum-based C2 architecture targeting Latin America. In June 2026, Arctic Wolf Labs investigated a targeted intrusion affecting a communications organization in Venezuela.

Attackers Use Vishing Attacks to Distribute New Android Malware

Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

'The Gentlemen' Profile: Why This Ransomware Group Wants In Before It Locks You Out

The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.

What Campaigns Like Grandoreiro Teach Us About Threat Detection

The recent Grandoreiro campaign detected by the WatchGuard Threat Lab team is a clear example of how today’s threats combine different techniques to make detection more difficult and operate more discreetly. In this case, the attack begins with a phishing email designed to persuade the user to click a link. From there, the victim is taken through several redirects and eventually downloads a compressed file from well-known services such as Dropbox or MediaFire.

Threat Actors to Watch: Akira and Storm-1175

From a ransomware-as-a-service group that can move from initial access to full encryption in under four hours, to a China-linked affiliate that has quietly pivoted to its own encryptor, these two threat actors show how mature the ransomware ecosystem has become. CYJAX breaks down what each group does, why they matter, and what security teams should know.

Steps to Recover from Ransomware Attacks Efficiently

A ransomware attack can stop business operations in a very short time. Files may become locked, systems may go offline, and employees may lose access to important tools. In some cases, attackers may also steal data before blocking access to it. Recovering from ransomware takes more than simply restarting computers. Businesses need a clear plan for containment, investigation, data recovery, system repair, and future protection. A rushed response may make the damage worse or allow attackers to return.
Featured Post

How Geopolitics is Driving Modern Cybercrime

Ransomware attacks no longer rely on traditional encryption methods. With today's advanced technology, threat actors are developing 'encryption-less extortion', focusing solely on data exfiltration and the threat of leaking or selling stolen sensitive information. Often used as part of double and even triple extortion strategies, ransomware has now evolved into a fragmented, competitive, and increasingly strategic threat landscape that employs divergent attack strategies, laser-focused on high-value targets.

Cato CTRL Insights: When Trust Becomes the Payload in a Fake Codex ClickFix Campaign

Attackers are using a fake Codex download experience to trick macOS users into pasting a malicious command into Terminal. This technique, known as ClickFix, relies on social engineering rather than a conventional malware download: the victim is persuaded to perform the execution step themselves. We analyzed sponsored search results leading to convincing Google Sites pages, a no-code website-building and hosting service provided by Google.

Shai-Hulud was the best thing to happen to supply chain security

npm launched Package Provenance in late 2022. For two years, adoption averaged 20-50 packages per week. Followed by Trusted Publishing in 2024. Blog posts were written. CISA advisories were issued. The line barely moved. Eventually Trusted Publishing with OIDC was made Generally Available in July 2025 Then Shai-Hulud hit. Weekly adoption jumped to 430 packages. In 18 months, cumulative adoption grew 3.4x.

PoshC2 Explained: Capabilities, Indicators, and Detection

PoshC2 version 6.0, an open-source command and control framework, is notable for its robust capabilities in managing compromised hosts. Accompanying its release, a comprehensive list of Indicators of Compromise (IoCs) and a dedicated GitHub repository have been provided. These resources are designed to assist cybersecurity teams in detecting PoshC2, especially when deployed with its default settings, which less sophisticated attackers often utilize.

Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business

Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.

They Paid Medusa's Ransom. A Second Medusa Actor Called and Demanded Half Again.

The FBI documented a Medusa ransomware victim who paid the ransom—and was then contacted by a second, separate Medusa actor, claiming the original negotiator had stolen the payment and demanding half the ransom again for the "true" decryptor. That's triple extortion, and it's the strongest argument in the whole CISA/FBI/MS-ISAC advisory (AA25-071A) against paying at all. There is no guarantee the extortion stops when the money moves.

Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer

Phishing is a form of social engineering that has evolved beyond simple lures into complex, multi-stage attacks exploiting trusted software, cloud identities and business platforms to bypass traditional security. Attackers leverage these campaigns to deliver trojans capable of stealing credentials and also establishing remote code execution, which might serve as a gateway for lateral movement.

Ransomware Has Changed and Your Defenses Need to Change With It

For years, ransomware was treated mostly as a malware problem. A user clicked something bad, files were encrypted, a ransom note appeared and everyone had a very bad week. That version still exists, of course, because cybercriminals love recycling old hits. But ransomware has changed significantly over the last year.

How to prevent ransomware damage: a 12-step checklist for IT teams and MSPs

No combination of controls guarantees that ransomware actors will never gain access or cause any impact. What the 12 controls below do is reduce the attacker's opportunities, accelerate containment and preserve the ability to restore operations without relying on ransom payment. Think of ransomware resilience as a continuous lifecycle rather than a fixed sequence: govern and identify, harden and prevent, detect and contain, roll back and recover, and improve and patch.

Ransomware protection for businesses and MSPs: the complete guide

Ransomware protection is a coordinated set of controls that reduces the likelihood of compromise, detects and contains malicious activity, protects recovery infrastructure and restores operations when an attack succeeds. It spans identity security, vulnerability and patch management, endpoint protection, EDR or XDR, incident response, targeted rollback, immutable backup and disaster recovery. No single control covers the complete ransomware lifecycle.

Rubrik MSP Unscripted - Episode 3 - Featuring Eddie Wlazlowski

In this episode of MSP Unscripted, Nawaz Ali sits down with Eddie Wlazlowski to discuss the evolution of Microsoft 365 Cyber Resilience. They explore why managing Microsoft 365 is no longer enough, what’s driving the shift toward cyber resilience, the gaps many organizations still have in protecting Microsoft 365, and how MSPs can evolve their offerings to deliver greater value. The conversation concludes with practical advice for MSPs looking to build differentiated, resilient Microsoft 365 services.

Warning: Vishing Attacks Open the Door to Ransomware Gangs

An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz. “From January through June 2026, ThreatLabz examined a cluster of related campaigns that used Microsoft Teams vishing and Quick Assist for initial access, followed by PowerShell-based staging,” the researchers write.

Rubrik MSP Unscripted - Episode 2 - Featuring Mallika Swaminathan

In this episode of MSP Unscripted, Nawaz Ali sits down with Mallika Swaminathan to discuss why Identity Resilience has become a critical component of cyber resilience. They explore why identity is increasingly targeted by attackers, the difference between identity security and identity resilience, common misconceptions organizations have, and what MSPs can do to help customers strengthen their identity recovery strategy.

ClickFix campaign abuses Deno runtime for infostealer delivery

Counter Threat Unit (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command. This command initiated an MSI-based staging process that installed Deno and enabled retrieval and execution of remote JavaScript.

Cl0p-Linked Activity Targets PTC Windchill and FlexPLM in Data Theft Campaign

Foresiet reviewed a batch of 42 masked victim listings associated with the Cl0p extortion operation. The listings describe alleged exposure of project repositories, databases, CAD files, engineering drawings, backups, software and Windchill-related files. Those references recur with unusual consistency across the batch. The pattern resembles the type of information commonly managed within product lifecycle management (PLM) environments more than the contents of a general file share.

Intel Chat: Shai-Hulud is back, model pinning & the token spend problem [343]

Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two. No prep doc, no script: just what Matt and Chris were actually hearing on the floor. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.

Best Ransomware Protection Tools to Protect Your Business

Ransomware attacks remain one of the most damaging cyber threats facing businesses today. These attacks mostly begin through phishing links, malicious downloads, exposed services, or stolen credentials. Once attackers gain access, they begin encrypting data to demand ransom and disrupt overall business operations. To mitigate this risk, organizations need to implement strong ransomware protection that blocks malicious activity early and detects suspicious behavior.

You Can't Buy Your Way Out of Downtime

A ransomware note doesn’t take down a business. The weeks of downtime after it does. That’s the distinction I hear missed most in boardroom conversations about cyber risk. Leaders ask what it costs to stop an attack. The harder question, and the one that actually decides whether a business comes out the other side, is what it takes to keep operating while you recover from one.

Havoc Malware: Techniques, Targets, and Threat Overview

Security analysts have noticed a trend among threat actors shifting towards adopting a novel open-source command and control (C2) framework called Havoc as an alternative to paid solutions like Cobalt Strike and Brute Ratel. Developed in the C language and introduced in 2022, Havoc’s Main branch received updates in 2023.