APT29—also known as “Cozy Bear,” a notorious threat actor linked to Russia’s Foreign Intelligence Service (SVR)—has launched a new phishing campaign aimed at European diplomatic missions. This was revealed in a new report from Check Point Research. This latest campaign marks a continuation of the group’s long-running cyber espionage activities, with signs of both increased sophistication and strategic targeting. Phishing Lures Masquerade as Diplomatic Event Invitations The phishing attacks, which started in January this year, use cunning email lures pretending to be invitations to exclusive diplomatic events. One example included an invitation to a wine-tasting evening, purportedly sent by a…
Kirsten Doyle
In a bold and unconventional move, cybersecurity intelligence firm Prodaft has debuted a new initiative called “Sell Your Source” (SYS) aimed at acquiring aged, verified accounts from underground hacking forums. The goal is to gain covert access to adversarial networks and uncover malicious operations from within. Through this initiative, Prodaft is offering to buy accounts created before December 2022—as long as they haven’t been used for cybercrime or unethical activity. These accounts, once vetted and verified, will serve as human intelligence (HUMINT) assets for the firm’s threat intelligence efforts. “We want to ensure our coverage does not hit any limitations,”…
Fortinet discovered a new technique used by threat actors to maintain access to FortiGate devices, even after known vulnerabilities were patched. The company has since taken action to notify affected customers and provide mitigation guidance. What Happened? Fortinet’s internal security team found that malicious actors were exploiting known vulnerabilities—specifically FG-IR-22-398, FG-IR-23-097, and FG-IR-24-015—to gain access to devices. While targeting unpatched systems is not new, Fortinet observed a novel post-exploitation method that allowed bad actors to maintain read-only access to FortiGate systems even once the initial vulnerabilities were addressed. The attackers created a symbolic link—a kind of shortcut—that connected the user…
The U.S. remained the top target for Initial Access Brokers (IABs), with 31% of all access listings aimed at American entities. But in 2024, Brazil (7%) and France (5%) have emerged as fast-rising targets. Analysts believe this shift could be due to expanding digital infrastructure and relatively weaker cybersecurity defenses in these countries. This was revealed in a new report compiled by Cyberint, a Check Point company. Initial Access Brokers (IABs) are threat actors who specialize in breaking into networks, systems, or organizations and then selling that access to other malicious actors on underground forums. Rather than carrying out full-scale…
Authorities across North America and Europe have launched a coordinated enforcement action against users of the Smokeloader botnet, marking a significant development in the ongoing Operation Endgame. The latest actions follow the major takedown of five key malware droppers in May 2024—IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee—under the operation codenamed Operation Endgame. This operation disrupted large-scale malware distribution infrastructure and targeted the operators behind these services. Earlier this year, law enforcement focused on the customers of the pay-per-install Smokeloader botnet, which was operated by a threat actor dubbed ‘Superstar’. These customers used the service to gain unauthorized access to victims’…
A notorious Russian-linked cyber espionage group dubbed Shuckworm has intensified its operations in Ukraine by targeting the military mission of a Western country based in the region. This latest campaign, which ran from late February through March 2025, demonstrates a concerning evolution in the group’s methods and a renewed focus on military intelligence gathering. Shuckworm, also known as Gamaredon or Armageddon, has been active since 2013 and is believed to be closely tied to Russia’s Federal Security Service (FSB). The group has consistently focused its attacks on the Ukrainian government and defense sectors. However, its latest campaign is targeting a…
Following over a year of work on the agreement, twenty-one nations signed The Pall Mall Process in Paris to govern the use of spyware. The Pall Mall Process is an international, multi-stakeholder initiative aimed at identifying and implementing political commitments to counter the proliferation and irresponsible use of commercially available cyber intrusion capabilities—which often manifest as cyber mercenary activity. On 3 and 4 April 2025, France and the UK co-hosted the second Pall Mall Process conference in Paris. The event brought 45 States, international organizations, and a broad coalition of private sector actors, civil society representatives, and researchers together. During…
A critical vulnerability in WhatsApp for Windows, tracked as CVE-2025-30401, allowed malicious actors to execute malicious code via seemingly harmless file attachments. This flaw affected all versions of WhatsApp Desktop prior to 2.2450.6. WhatsApp said the vulnerability stemmed from a mismatch in how WhatsApp handled file attachments: it displayed files based on their MIME type (such as an image) but opened them based on their filename extension (for instance, .exe). This discrepancy allowed attackers to craft files that appeared safe but executed malicious code when opened within WhatsApp. Meta explained in its official advisory, “A maliciously crafted mismatch could have…
The National Institute of Standards and Technology (NIST) has announced that all CVEs published before 1 January 2018, will be marked as ‘Deferred’ in the National Vulnerability Database (NVD). “All CVEs with a published date prior to 01/01/2018 will be marked as Deferred within the NVD dataset. We are assigning this status to older CVEs to indicate that we do not plan to prioritize updating NVD enrichment or initial NVD enrichment data due to the CVE’s age,” NIST explained It added that: “CVEs marked as Deferred will display a banner on their CVE Detail Pages indicating this status.” This change…
Organized crime networks are using artificial intelligence (AI) to enhance their operations, creating unprecedented challenges for law enforcement, warned Europol in its European Serious Organised Crime Threat Assessment (EU-SOCTA) report. “Criminal networks have demonstrated the ability to rapidly adapt to new technological solutions,” the report said. “This includes AI, a solution that has transformed the modern world with unprecedented speed and impact. Indeed, the very qualities that make AI revolutionary – accessibility, versatility, and sophistication – have made it an attractive tool for criminals.” AI’s Role in Cyber Fraud With expanding complexity and availability, AI and other cutting-edge technologies are…
