New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps
Aggiornamento Statuto Associativo Berghem-in-the-Middle
Ciao a tutti! 👋 Grazie al via libera dei soci nell’ultima assemblea, abbiamo ufficialmente depositato il nuovo statuto associativo, in …
Anatomy of a Fraud Operation: Mule Account Creation on B2B Fintech Platforms in France
How corporate/retail accounts are exploited for financial fraud through sophisticated device fingerprinting and mule networks.
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
The Architecture of Deception: How a $187 Million Fraud Ecosystem Exploits Trust Across Australia and the United States
Group-IB Digital Risk Protection Integrates with Google SecOps: Brand Threat Intelligence, Now In Your SOC
Your SOC was half prepared for brand threats, but this integration changes that. Group-IB Digital Risk Protection meets Google SecOps, bringing external brand intelligence directly into your SIEM/SOAR and closing the signal gap your analysts might’ve missed.
The French 2-Step: Exposing a Multi-stage Scam Targeting the National Railway Company in France
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
Digital Brand Protection in Cybersecurity: Why It Matters in 2026
Learn why digital brand protection matters in 2026, how threats like phishing, impersonation, counterfeits, and leaked credentials target brands online, and how organizations can detect and stop them early.
What Is an Incident Response Retainer? (And Why Waiting Until a Breach Is Too Late)
Learn what an incident response retainer is, how it works, and why having one before a cyberattack helps companies reduce response time, contain threats faster, and limit business impact.
The Secret Scriptorium: A Medieval Tale of the Shadow Shop that Forged Identities
The First Whisper – How the Quest Began It was a quiet evening in the citadel of cyber‑defence when a single alert flickered on the watch‑tower’s crystal screen. The Cyber Threat Intelligence Brotherhood, ever‑vigilant guardians of the kingdom’s data, spotted a match: a client’s official…
Unusual Data Exfiltration Paths: Leveraging Rclone for SharePoint Data Theft
Premise As Yarix’s Incident Response Team, our responsibilities are to manage critical issues related to cyber-attacks carried out by cybercriminals, intervening promptly in order to guarantee security to victim companies and to minimize latent risks, analyzing the systems within their infrastructures and indicating precise remediation…
Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
Alleged Dream Market admin arrested in Germany after US indictment
ODNI taps officials to coordinate response to foreign election threats
OpenAI asks macOS users to update after TanStack npm supply chain attack
CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday
More than $10 million stolen from crypto platform THORChain
Sintesi riepilogativa delle campagne malevole nella settimana del 18 – 24 aprile
GitHub e GitHub Enterprise Server: vulnerabilità RCE CVE-2026-3854
Sintesi riepilogativa delle campagne malevole nella settimana del 25 – 30 aprile
Sintesi riepilogativa delle campagne malevole nella settimana del 2 – 8 maggio
Smishing a tema INPS: falso “bonus carburante”
Sintesi riepilogativa delle campagne malevole nella settimana del 9 – 15 maggio
Why U.S. Critical Infrastructure Is the Highest-Value Target in the Global Cyber War
Explore how a critical infrastructure cyberattack and rising nation-state threats are reshaping US cybersecurity risks in 2026.
ANZ Organizations Are in the Ransomware Crosshairs— What the Dark Web Is Telling Us
ANZ ransomware threats surge as attackers scale via dark web, targeting high-value sectors with data theft, RaaS models, and brokered access.
How Cyble Blaze AI Turns Billions of Threat Signals into Actionable Intelligence
Cyble Blaze AI uses cyber threat intelligence, AI security analytics, and automation to detect, predict, and stop threats in real time.
The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws
Cyble weekly vulnerability report tracks 1,095 issues, active exploits, KEV additions, PoCs and real-world attacks across enterprise systems.
Cyble Named a Challenger in the 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence
Cyble has been recognized as a Challenger in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies.
Third-Party Breaches Without Breaches: How Attackers Use Trusted Access to Bypass US Enterprise Defenses
Explore how supply chain attack tactics abuse trusted access and browsers. Learn how to prevent supply chain attack risks effectively.
Operation HumanitarianBait: An Infostealer Campaign in Disguise
Cyble analyzes Operation HumanitarianBait, a stealthy espionage campaign using aid-themed lures to deploy a fileless Python infostealer.