Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
Multiple cybersecurity firms have identified expanding ClickFix campaigns deploying three distinct malware loaders—BabaDeda Loader, Lorem Ipsum Loader, and Potemkin—using fake update lures to compromise targets. BabaDeda Loader attacks observed in April 2026 have specifically targeted education and financial sector organizations. These campaigns represent an evolution in social engineering tactics
AISprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection
FishMonger, a China-linked threat actor, has deployed a previously undocumented Windows variant of the SprySOCKS backdoor that leverages kernel drivers to evade detection. The malware campaign has targeted government entities across Honduras, Taiwan, Thailand, and Pakistan, representing a significant evolution from the original Linux-based version.
AI'Lorem Ipsum' Malware Pivots to ClickFix Delivery
A malware campaign utilizing compromised WordPress sites has shifted its delivery method to ClickFix techniques. Security researchers have identified potential connections between this campaign and Vice Society, a known ransomware and data extortion group, raising concerns about escalating threat sophistication.
AISurvey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive
A recent survey reveals that 94% of security incidents involve anonymized infrastructure, highlighting a critical challenge for security teams. Despite having access to extensive IP data, enrichment feeds, and threat intelligence, organizations struggle to identify threat actors behind anonymized IP addresses, forcing teams to remain in reactive rather than proactive security postures.
AIGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
Google has filed a lawsuit against a Chinese cybercrime network for allegedly weaponizing its Gemini AI to facilitate SMS phishing (smishing) attacks targeting Americans. The network reportedly operates a phishing-as-a-service (PhaaS) platform called Outsider, demonstrating how threat actors are exploiting generative AI tools for malicious purposes.
AIPhishing Attack Volume Down 20%, but Risk Still Rising
Despite a 20% decrease in overall phishing attack volume, the threat landscape remains increasingly dangerous as cybercriminals shift their strategy from mass campaigns to more sophisticated, targeted attacks. Hackers are leveraging AI technologies to enhance the quality and effectiveness of their phishing attempts, making them harder to detect and more likely to succeed. This evolution represents
AIThe Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
The Gentlemen ransomware operation has claimed 478 victims and initially functioned as an affiliate conducting double extortion attacks using multiple ransomware-as-a-service (RaaS) platforms. The threat group leveraged resources from established RaaS schemes including LockBit, Qilin, and Medusa before evolving its operations. The ransomware notably possesses worm-like capabilities that enable it
AIThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories
The cybersecurity landscape is evolving with increasingly sophisticated threats, including publicly leaked supply chain attack tools, premium remote access trojans with browser-cloning capabilities, and demonstrated vulnerabilities in AI agents that can be exploited to extract credentials. The professionalization of cybercrime infrastructure, with mule networks operating as polished SaaS-like serv
AIWho Runs the Ransomware Group ‘The Gentlemen?’
The Gentlemen ransomware group has become the second most active ransomware operation by victim count, attracting affiliates with an unprecedented 90/10 revenue split. Security researchers have traced the group's administrator, known as Hastalamuerte/Zeta88, to Alexander Andreevich Yapaev, a 36-year-old from Izhevsk, Russia, who also works in B2B marketing for an electrical products company. The i
AIRussian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Russian threat actors are actively exploiting CVE-2025-8088, a WinRAR vulnerability patched in July, through two distinct campaigns targeting Ukrainian military and government organizations. The attacks focus on data exfiltration and cyberespionage operations, demonstrating continued targeting of critical Ukrainian infrastructure through known software vulnerabilities.
AIResearchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
University of Toronto researchers have developed a proof-of-concept AI worm that autonomously navigates networks, generates customized attack strategies, and self-replicates using only locally hosted open-weight language models. The system operates independently without human intervention or reliance on commercial AI services, demonstrating significant cybersecurity implications for enterprise env
AIDefend against frontier cyber models: Cloudflare's architecture as customer zero
Cloudflare details its defense architecture against AI-powered cyber threats, emphasizing that architectural design matters more than patching speed when facing frontier AI models like Mythos. The company operates as 'customer zero' for its own security products, using its visibility into ~20% of global web traffic to detect and block threats in real-time through integrated WAF and threat intellig
AITurning Cloudflare’s threat indicators into real-time WAF rules
Cloudflare has introduced a new integration that allows security teams to automatically translate threat intelligence from its Threat Events platform into proactive WAF rules, eliminating the manual process of configuring blocks for known malicious IPs. The solution leverages an 'always-on' detection framework that enriches HTTP requests with real-time threat metadata, enabling organizations to fi
AI⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
A turbulent week in cybersecurity saw multiple significant incidents including Instagram account compromises, an Android zero-day vulnerability, and a GitHub worm spreading through repositories. Despite advanced threats, attackers continue succeeding with basic tactics like chatbot manipulation, leaked bot tokens, and prolonged email account compromise campaigns that operate undetected for months.
AIThe Hardest Fork
The Mythos vulnerability represents a significant security threat that goes beyond typical code vulnerabilities, involving novel chains of dozens of existing issues that SAST scanners identify but don't flag as critical when combined. Despite industry skepticism dismissing it as marketing hype, the findings reveal sophisticated attack vectors created through creative exploitation of multiple seemi
AIUNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Google Mandiant and GTIG have identified UNC3753, a financially motivated threat actor conducting a sophisticated data theft extortion campaign targeting U.S. professional, legal, and financial services organizations from January to May 2026. The campaign notably combines vishing (voice phishing) tactics with physical intrusion methods to compromise target organizations.
AIAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
ESET has identified a new Android spyware called Asin specifically targeting Arabic-speaking users through deceptive distribution methods. The malware campaigns, detected in early 2025, utilize fake websites impersonating utilities, war-related information sources, and government news platforms to distribute the spyware to unsuspecting victims.
AINew Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
A newly identified threat cluster designated OP-512 has been discovered targeting Microsoft IIS servers with a custom web shell framework for espionage purposes. ReliaQuest researchers assess with moderate to high confidence that the activity is linked to China-based threat actors, representing a significant risk to organizations running IIS infrastructure.
AIChina's TA4922 Expands Cybercrime Attacks Globally
Chinese cybercrime group TA4922, characterized by its diverse and unfocused attack methodology, is expanding its operations beyond its traditional East Asian targets to establish a global presence. This expansion represents a significant shift in the threat landscape as the group broadens its geographic scope and potential victim base.
