Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Attackers Use Vishing Attacks to Distribute New Android Malware

Attackers are distributing a new Android malware called “WindRelay” via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employees and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.

Steps to Recover from Ransomware Attacks Efficiently

A ransomware attack can stop business operations in a very short time. Files may become locked, systems may go offline, and employees may lose access to important tools. In some cases, attackers may also steal data before blocking access to it. Recovering from ransomware takes more than simply restarting computers. Businesses need a clear plan for containment, investigation, data recovery, system repair, and future protection. A rushed response may make the damage worse or allow attackers to return.
Featured Post

How Geopolitics is Driving Modern Cybercrime

Ransomware attacks no longer rely on traditional encryption methods. With today's advanced technology, threat actors are developing 'encryption-less extortion', focusing solely on data exfiltration and the threat of leaking or selling stolen sensitive information. Often used as part of double and even triple extortion strategies, ransomware has now evolved into a fragmented, competitive, and increasingly strategic threat landscape that employs divergent attack strategies, laser-focused on high-value targets.

Donation Forms Attract Card Testing Attacks

A charity notices something odd in its payment dashboard. Hundreds of one dollar donations attempted overnight. Almost all declined. A handful approved. Nobody donated anything. The organization was being used as a validation service. Donation forms have become a preferred target for card testing, and the reasons are structural rather than accidental. Here is how the attack works, why nonprofit payment pages are disproportionately attractive, and what actually stops it.

Living Off the Land Attacks: Detection and Response Guide

The most popular advice about living off the land attacks is also the least useful when it stands alone: hunt for suspicious PowerShell, block LOLBins, and alert whenever a signed Microsoft binary behaves unexpectedly. Those controls have value, but they don't solve the operational problem. PowerShell, WMI, certutil.exe, and bitsadmin.exe are legitimate administrative utilities, and attackers abuse them precisely because security teams can't remove them without disrupting normal work.

AI Isn't Creating New Cyberattacks. It's Changing How They Operate

Artificial Intelligence has quickly become one of the most important conversations in cybersecurity. Much of that conversation focuses on what attackers might create next: AI-generated malware, deepfakes, autonomous attacks, or entirely new categories of threats. Those risks matter, but focusing only on new attack techniques misses a much larger transformation already taking place. The real impact of AI is not only what attackers can create. It is how efficiently they can operate.

Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer

Phishing is a form of social engineering that has evolved beyond simple lures into complex, multi-stage attacks exploiting trusted software, cloud identities and business platforms to bypass traditional security. Attackers leverage these campaigns to deliver trojans capable of stealing credentials and also establishing remote code execution, which might serve as a gateway for lateral movement.

Report: One-Quarter of Breaches Are Enabled by AI-Driven Attacks

A new report commissioned by IBM has found that one in four breaches is now AI-enabled, up 56% from last year. “Most AI-driven attacks reported in the study targeted critical infrastructure sectors (62%), with financial services and energy organizations experiencing the highest concentration, raising the risk of broader systemic disruption,” the report says. “Financial services breaches were reported to cost on average $6.3 million, while energy breaches cost on average $5.2 million.