❌

Normal view

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

4 May 2026 at 18:06
An active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUS#HELPER, has impacted over 80 organizations, most of which are in the U.S., according to Securonix. It shares overlaps with clusters

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

4 May 2026 at 16:34
Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts.Β  The

Shadow IT has given way to shadow AI. Enter AI-BOMs

4 May 2026 at 15:04

'If you don't have visibility, you can't understand what to protect'

When it comes to securing enterprise supply chains, now heavily infused with AI applications and agents, a software bill of materials (SBOM) no longer provides a complete inventory of all the components in the environment. Enter AI-BOMs.…

DHS Demanded Google Surrender Data on Canadian’s Activity, Location Over Anti-ICE Posts

4 May 2026 at 14:45
Using a 1930s trade law, Homeland Security targeted the manβ€”who hasn’t entered the US in more than a decadeβ€”following posts on X condemning the killings of Renee Good and Alex Pretti.

⚑ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More

4 May 2026 at 14:23
This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling

2026: The Year of AI-Assisted Attacks

4 May 2026 at 11:58
On December 4, 2025, a 17-year-old was arrested in Osaka under Japan’s Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan's largest internet cafe chain. When asked, the young man shared his motivation for the hack: he wanted to buy PokΓ©mon cards. In a sense, this is a fairly conventional story.

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

4 May 2026 at 11:57
The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities. "Both waves followed a nearly identical

❌