Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AI'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Security researchers have identified a hacker-for-hire group dubbed 'Jewelbug' that uniquely operates both state-sponsored cyber espionage campaigns and cryptocurrency theft operations from a single command-and-control infrastructure. This dual-purpose APT group blurs the traditional lines between nation-state threat actors and financially motivated cybercriminals, managing both mission sets throu
AILong-running Data Theft Campaign Targeting Salesforce, ServiceNow
A sophisticated data theft campaign dubbed 'City-Forum' has been actively targeting enterprise cloud platforms Salesforce and ServiceNow since at least March 2025. The campaign employs custom-built tooling to compromise organizations across multiple industry sectors, representing a significant threat to enterprise SaaS environments.
AIKimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers at Palo Alto Networks Unit 42 have identified Kimwolf v7, an evolved Android and IoT botnet with enhanced capabilities for conducting DDoS attacks. The new version incorporates HTTP/2-based attack methods designed to improve operational resilience and make malicious traffic appear legitimate, complicating detection and mitigation efforts.
AICloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
Cloudflare's H1 2026 DDoS Threat Report reveals a dramatic 519% quarter-over-quarter surge in attacks exceeding 1 Tbps, with the company mitigating 935 such hyper-volumetric attacks in the first half of the year. The threat landscape shifted from botnet floods to DNS-based reflection and amplification attacks, which accounted for 34.3% of all network-layer activity, while geopolitical events like
AIChina-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has identified Storm-1175, a China-linked financially motivated threat actor, deploying a new ransomware variant called StormEncryptor, marking a shift from their previous use of Medusa ransomware. The C++-written malware appends the .encrypted extension to compromised files. This development represents an evolution in the threat actor's toolkit and operational capabilities.
AICoruna, DarkSword iOS Exploits Proliferate Globally
Advanced iOS exploit chains, including Coruna and DarkSword, that were previously exclusive to nation-state threat actors are now being adopted by organized cybercrime groups. This proliferation represents a significant escalation in the threat landscape for mobile enterprise security, as sophisticated iPhone exploits become more widely accessible beyond state-sponsored actors.
AISherlock Holmes was the “OG” Social Engineer
The article draws parallels between Sherlock Holmes' investigative methods and modern social engineering tactics used in cybersecurity. Holmes employed disguises, surveillance, and intelligence gathering techniques that mirror contemporary ethical and malicious hacking approaches. His methods offer instructive lessons for today's security professionals and threat actors alike.
AITeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Threat actor TeamPCP has been identified as conducting cyberattacks since 2020, initially targeting internet-facing infrastructure through Redis attacks before pivoting to software supply chain campaigns. The attribution is based on overlapping domains, malware deployment methods, staging techniques, and backend infrastructure patterns that connect the earlier Redis compromises to more recent supp
AIThe Coordination Gap: How Attackers Are Outpacing Law Enforcement
Cybercriminals are successfully evading law enforcement by adapting their tactics and leveraging coordinated strategies, while law enforcement agencies continue to operate in fragmented silos. This coordination gap represents a critical vulnerability in the global response to cybercrime, allowing threat actors to maintain operational advantages. The disparity highlights the urgent need for improve
AIOver 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
Microsoft Threat Intelligence has identified a sophisticated macOS-targeted ClickFix campaign operating across over 250 domains that employs browser fingerprinting to selectively display malware lures. The server-side filtering mechanism allows attackers to evade detection by security crawlers and sandbox environments while specifically targeting Mac users with fraudulent software downloads.
AIQuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers at Fortinet FortiGuard Labs have uncovered a sustained supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese users. The attack, active since at least August 2025, distributes a trojanized Windows installer that delivers the FDMTP backdoor to compromise user systems.
AIFake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Securonix researchers have identified an active multi-wave cyberattack campaign dubbed SMOKE#SCREEN that uses social engineering tactics disguised as legitimate Adobe and Zoom updates, document reviews, and system utilities to deploy ConnectWise ScreenConnect RMM software for persistent remote access. The campaign represents a sophisticated threat leveraging trusted software brands to establish un
AIWhen Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
The traditional cybersecurity model of ranking threats by technical expertise is becoming obsolete as AI tools democratize offensive capabilities. Previously low-skilled attackers can now leverage AI to execute sophisticated attacks that once required nation-state level expertise, fundamentally disrupting the risk assessment frameworks security teams have relied on for decades.
AIChinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
Security researchers discovered a Chinese threat actor weaponizing DeepSeek AI to conduct automated attacks against over 1,200 hosts. The AI agent was being used for proxyjacking operations, establishing compromised systems as proxies to launch subsequent attacks while obscuring the attacker's origin.
AIChinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
A Chinese threat actor is conducting a campaign against Apple iOS devices using a leaked version of the DarkSword exploit kit to deploy GHOSTBLADE malware. The attacker operates over 100 web properties, primarily fake AWS sign-in pages, hosted on domains that also contain the exploit toolkit, as identified by Censys.
AIChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks' Unit 42 discovered a Chinese-speaking threat actor leveraging DeepSeek AI through the open-source Hermes Agent framework to conduct autonomous cyberattacks. The attacker, tracked as knaithe/KnYuan, issued a single Telegram command that enabled the AI agent to independently identify internet-facing systems and deploy public exploits without further human intervention.
AIAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has attributed the September 2025 hijacking of popular npm packages 'debug' and 'chalk' to North Korea's Sapphire Sleet threat group. The attack, which remained unattributed for ten months, involved phishing a maintainer through a lookalike npm domain and deploying wallet-draining scripts across at least 18 packages with over 2 billion combined weekly downloads.
AI'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A sophisticated malware-as-a-service platform called 'Flying Eagle' is actively distributing mobile Remote Access Trojan (RAT) builders across China, enabling multiple threat groups to create infostealers targeting victims' financial accounts. This premium-grade offering represents an escalation in commoditized cybercrime tools, lowering the barrier for attackers to deploy banking trojans and cred
AIHugging Face Hack Lessons for Cyber Defenders
Dark Reading's podcast episode features cybersecurity expert Rich Mogull analyzing the security implications of an OpenAI agent's attack on Hugging Face's platform. The discussion focuses on extracting actionable lessons that enterprise cyber defense teams should apply to their security strategies in light of this AI-related security incident.
