Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift impossible to ignore. For organizations facing this growing threat,… Read More "Ransomware Incident Response Plan: 2025-2026 Threat Guide"
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed,… Read More "New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA"
OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards
The company said Astra has not yet been definitively classified at that level, but its early performance is “strong enough” that such a designation cannot be ruled out. Its earlier models, including GPT 5.6 Sol, “have been evaluated for frontier… Read More "OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards"
Go-Based macOS Malware Steals Crypto and Secrets
Security researchers have discovered new infostealing macOS malware delivered via ClickFix social engineering attacks. Managed detection and response (MDR) specialist Huntress said that it came across the malware in June 2026. “In a ClickFix attack, the computer’s user is presented… Read More "Go-Based macOS Malware Steals Crypto and Secrets"
New Jersey, Alabama Join States Targeted in Water Cyberattacks
New Jersey and Alabama have joined the list of US states that confirmed their water and wastewater facilities have been targeted in a hacking campaign that started in late July. At least 12 states have reportedly been hit, but not… Read More "New Jersey, Alabama Join States Targeted in Water Cyberattacks"
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co
Half of Fortune 500 companies are vulnerable to attacks enabled by their own AI agents bypassing firewall defenses, according to new research by Tenet Security. The technique, dubbed ‘Ghostjacking’, involves the use of an organization’s own AI agents to reroute… Read More "“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co"
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid. The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”. In late December 2025, threat actors linked to… Read More "Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility"
How to detect OAuth client ID spoofing in Microsoft Entra ID before account takeover
SigninLogs | where TimeGenerated > ago(1h) | where ResultType in (“50034”, “50126”, “700016”) or isempty(AppDisplayName) | summarize DistinctClientIDs = dcount(AppId), ResultCodes = make_set(ResultType), Usernames = make_set(UserPrincipalName) by SourceIPAddress, UserAgent, bin(TimeGenerated, 15m) | where DistinctClientIDs > 5 | where ResultCodes has… Read More "How to detect OAuth client ID spoofing in Microsoft Entra ID before account takeover"
US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
The US authorities have sanctioned an Iranian firm accused of moving over $6bn in illegal blockchain flows over the past two years. Shelbit was a crypto exchange in name only, argued blockchain analytics company TRM Labs, in a blog published… Read More "US Sanctions Iranian $6bn Crypto “Exchange” Shelbit"
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
The US cybersecurity agency CISA has urged federal agencies to immediately patch a critical-severity vulnerability in Progress Kemp LoadMaster that has been exploited in the wild. Tracked as CVE-2026-8037 (CVSS score of 9.6), the flaw is described as an OS… Read More "CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability"