2026-07-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to…
P15
2026-07-30 07:40 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Managed cyber-fraud protection is the most overlooked growth line in the MSSP playbook, and most of the capability is already sitting in your SOC.
P0
2026-07-28 13:00 UTC
Vendor Research
Rapid7 · Mikayla Wyman · indexed 2026-08-15 18:55 UTC
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement conti…
P0
2026-07-27 09:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
P0
2026-07-23 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Meet Channel Account Manager Andrew Schlemmer, and learn how his personal experience with cybercrime fueled his mission to make enterprise-grade security attainable and accessible for businesses of all sizes.
P0
2026-07-21 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover what initial access brokers (IABs) are, how they compromise networks to sell their access to other attackers, and how to protect your business.
P0
2026-07-14 08:18 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB discovers a sophisticated multi-layered scam scheme targeting fans with fake ticket sales on two fronts: social network platforms and fraudulent websites impersonating official distributors.
P0
2026-07-13 07:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how Distributed Tokenization identifies compromised cards at pre-authorization without exposing raw card data — a technical deep-dive for fraud operations and risk teams.
P0
2026-07-08 12:31 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
P25
2026-07-07 08:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider.
P0
2026-07-03 12:36 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
P0
2026-06-29 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cybercriminals are hijacking Microsoft 365 accounts in seconds. Learn the 2026 hacker tactics, including ConsentFix, that bypass security training and exploit normal user behavior.
P0
2026-06-23 16:12 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.
P0
2026-06-18 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress was one of many vendors impacted by a recent incident at Klue. We dug into the incident to figure out what happened.
P0
2026-06-11 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
P0
2026-06-01 08:23 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn the most common crypto scam types and how they work in practice. Understand how financial institutions can detect fraud earlier and prevent losses at the fiat-to-crypto boundary.
P0
2026-06-01 07:15 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Merchants face $53B in card fraud losses but lack access to compromised card data. Discover the three barriers keeping merchants in the dark — and the solution.
P0
2026-05-27 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.
P0
2026-05-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal …
P0
2026-05-22 09:13 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn what payment fraud is, how it unfolds, and the practical controls that organizations can use at every step of the payment process to reduce losses without harming customer trust.
P0
2026-05-20 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
An increasing number of data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. But are they credible?
P0
2026-05-19 09:49 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A candid conversation on fraud disguised as iGaming growth with Sarah Psaila, Head of Gaming at Group-IB.
P0
2026-05-15 11:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Digital brand protection helps organizations detect and disrupt external threats, such as phishing sites, fake social profiles, counterfeit listings, and leaked credentials, before they become customer-facing fraud or reputational damage.
P0
2026-05-15 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
P0
2026-05-13 12:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
P0
2026-05-07 08:51 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
P0
2026-05-06 08:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog examines how threat actors use deepfake impersonation and social media to manipulate real stocks, how a network of 208 connected fake investment platforms steals millions in cryptocurrency, and what a new approach to defence can do about it.
P0
2026-04-27 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how Huntress EDR/ITDR Correlations stop infostealer-driven attacks before stolen credentials can be reused, linking endpoint compromise to cloud identities for one coordinated response.
P0
2026-04-22 06:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How corporate/retail accounts are exploited for financial fraud through sophisticated device fingerprinting and mule networks.
P0
2026-04-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany mo…
P15