Russia-affiliated Electrum hackers linked to cyberattack on Polish power grid
Dragos assessed that Electrum works closely with another threat cluster Kamacite that focuses on initial access.
Dragos assessed that Electrum works closely with another threat cluster Kamacite that focuses on initial access.
The flaw (CVE-2026-24858) was actively exploited in the wild by two malicious FortiCloud accounts.
The flaw, tracked as CVE-2025-8088, allows attackers to place malicious files on a victim’s system by tricking users into opening specially crafted RAR archives.
The campaigns, dubbed ‘Gopher Strike’ and ‘Sheet Attack,’ were discovered in September 2025.
Stanley is marketed as an easy-to-use phishing platform that works by hijacking user navigation and overlaying a full-screen iframe with attacker-controlled content.
PeckBirdy is JScript-based, which allows it to run across different environments using legitimate system tools.
The extensions share a common mechanism that hijacks ChatGPT session authentication tokens and sends them to a third-party backend.
The attack begins with a fake CAPTCHA verification that instructs victims to manually paste and run a command using the Windows Run dialog.
Patches are currently available for most supported versions, but updates for Office 2016 and Office 2019 have not yet been released.
CISA has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Showing elements 361 - 370