Attackers are constantly looking for ways to inject malware into systems and execute it profitably without raising the suspicion of security solutions or users. This article explains how various methods interact, how different browsers handle their cache, and why this is relevant to defense.
Files recovered from a compromised server trace a Qilin intrusion from Exchange mailbox collection to backup destruction, wiper deployment, and the first reported executions of the ransomware.
When the European Central Bank sent a letter to the CEOs of the institutions it supervises on July 7, 2026, its message was clear: Under the title “Addressing AI-enabled cybersecurity threats,” the ECB requires institutions to seriously and demonstrably address AI-enabled cybersecurity threats and to submit an action plan to their respective Joint Supervisory Teams by October 31, 2026.
On August 7, 2026, Fox News published an article with the sensational headline “Russian hackers can steal emails without a click.” It sounds like clickbait, but technically speaking, it’s hardly that. Because that’s exactly the point of the article.
LAUNDRY BEAR, a Russian, state-sponsored hacking group whose latest campaign doesn’t even require a click on a malicious link anymore. All they need is for you to open an email.
Cyberattacks on hospitals are a prime example of how vulnerable critical infrastructure has become. Unlike in many other industries, these attacks can have not only economic consequences but also potentially direct impacts on human lives.
A call from the CEO requesting urgent payment approval. A video conference with familiar faces. A voice message from a colleague asking for quick assistance. For a long time, these very forms of communication were considered trustworthy. But with the advancement of generative AI, the reality of digital communication is changing fundamentally.
Security Operations Centers are under immense pressure. The number of security-related incidents is rising steadily, while there is a shortage of qualified analysts. At the same time, IT environments are becoming more complex, hybrid, and dynamic.
Many companies are therefore investing in additional security tools. But this is precisely where a common misconception arises: More technology does not automatically mean greater security.
As part of an incident response operation, the SECUINFRA Falcon team identified an interesting malware sample codenamed "CommieLoader" masquerading as an application form.
CommieLoader installed a Cobalt Strike Beacon, which was used by the attacker for command-and-control communication
In March 2026, a previously unknown zero-day exploit was discovered in Adobe Reader that is being actively exploited via a specially crafted PDF document. Building on the initial findings of security researcher Haifei Li, this article provides a detailed analysis of the technical structure and functionality of the malicious PDF. It reveals a highly obfuscated attack chain featuring sophisticated obfuscation techniques, fingerprinting mechanisms, and unusual command-and-control communication via RSS feeds.
Alertness and vigilance are crucial in cybersecurity. When repeating this truism, most of us think about social engineering attacks and educating the user how to recognize a phishing mail or a scam call. However, an attentive user can also provide valuable insights on a more technical aspect.
A recent incident response case was started, when the user noticed „strange black windows” on the desktop and took screenshots of them. This was accompanied by PayPal transfers from the user’s account, not authorized by the user.