Threats & incidents
-
SharePoint secrets move into the breach zone
CERT-FR has warned that exploited SharePoint flaws require urgent patching and secret rotation where compromise is suspected.
-
TfL attackers jailed after £29m recovery
Two men have received five-and-a-half-year prison sentences for the Transport for London intrusion, which disabled 148 systems and forced password resets for 27,000 employees.
-
Starland RAT hides inside familiar software
A Russian-speaking criminal operation is disguising malware as familiar administration, database, conferencing, and gaming software, with potential exposure identified in Germany and Romania.
-
ClickLock puts macOS identity stores at risk
A newly documented macOS stealer targets Keychain records, browser sessions, password managers, wallets, and developer credentials, with more than half of identified victims located in Europe.
-
Sandworm-linked activity adopts simpler access routes
CERT-UA says a threat cluster associated with Sandworm is combining trojanised torrent downloads, Signal conversations, fake CAPTCHA prompts, PowerShell, and legitimate remote-access tools.
-
Microsoft 365 phishing moves beyond passwords
Jalisco and OmegaLord target Microsoft 365 identities by abusing device-code authentication and collecting information that can support interception of weaker MFA methods.
-
Gemini CLI ran a live botnet migration
Trend Micro says a Russian-speaking operator used Gemini CLI to migrate, debug, and control a small botnet through natural-language instructions rather than direct technical commands.
-
Public exploit code brings attacks to LoadMaster
Attempts to exploit a critical Progress LoadMaster command-injection vulnerability began within hours of functional proof-of-concept code becoming publicly available.
-
Europe’s fraud machine ran like a multinational
Dutch police say an alleged investment-fraud network employed more than 700 people, operated approximately 20 call centres, and generated over €100 million a month.
-
US indicts alleged bulletproof hosting operators
US prosecutors have unsealed charges against three Russian nationals and two companies accused of providing infrastructure used in cybercrime affecting international victims.






