Archive
769–780 of 851 items
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing wit...
May 25, 2026 · StaffOriginally on Wedgetail
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compro...
May 25, 2026 · StaffOriginally on Wedgetail
Webworm: New burrowing techniques
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
May 20, 2026 · StaffOriginally on Wedgetail
Risky Business #838 -- GitHub investigates possible breach
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: GitHub announced a possible breach ...
May 20, 2026 · StaffOriginally on Wedgetail
The quest for greater tech independence
A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reasse...
May 19, 2026 · StaffOriginally on Wedgetail
Welcome to BlackFile: Inside a Vishing Extortion Operation
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an e...
May 15, 2026 · StaffOriginally on Wedgetail
FrostyNeighbor: Fresh mischief and digital shenanigans
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage ...
May 14, 2026 · StaffOriginally on Wedgetail
Risky Business #837 -- GitHub Actions footgun claims TanStack
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Mini Shai-Hulud and the TanStack co...
May 13, 2026 · StaffOriginally on Wedgetail
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a matur...
May 11, 2026 · StaffOriginally on Wedgetail
Fake call logs, real payments: How CallPhantom tricks Android users
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than se...
May 07, 2026 · StaffOriginally on Wedgetail
Risky Business #836 -- You can't patch the bugpocalypse
On this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, includi...
May 06, 2026 · StaffOriginally on Wedgetail
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android...
May 05, 2026 · StaffOriginally on Wedgetail