Category: Research
Supreme Court Location Ruling Could Reshape License Plate Camera Surveillance
A landmark Fourth Amendment decision on cell phone geofence warrants is fueling legal arguments that automated license plate reader networks like Flock…
RedHook Android Malware Abuses Wireless ADB to Gain Shell Access
A new RedHook variant tricks victims into enabling Wireless Debugging, then uses a Shizuku-based framework to run shell-level commands and expand its…
Dormant GitHub Ghost Accounts Fuel Mass Reconnaissance Campaign
Datadog researchers say over 50 dormant GitHub accounts, some registered years ago, are being used to systematically enumerate organizations, repositories, and users…
Balochistan Police Portal Compromised in Multi-Group Espionage Campaign
Researchers say suspected China- and India-aligned threat actors breached servers tied to a Pakistani police portal over more than two years, exposing…
China and India Linked Hackers Both Breached Pakistan’s Balochistan Police
SentinelLabs uncovered more than two years of overlapping espionage inside Pakistani law enforcement networks, with China linked and India linked groups independently…
Third Ex-Security Pro Sentenced for Feeding Data to BlackCat Ransomware Gang
Florida-based negotiator Angelo Martino received 70 months in prison for secretly helping BlackCat/Alphv extort at least five victims, marking the third such…
GigaWiper: Go-Based Backdoor Merges Wiper, Ransomware, and Remote Access
Microsoft details GigaWiper, a Go-based backdoor active since October 2025 that bundles destructive disk-wiping, file encryption, and full remote control into a…
Helix Vishing Group Targets SharePoint via Device Code Phishing
A newly identified extortion group called Helix is combining voice phishing, device code abuse, and MFA hijacking to steal and ransom data…
GigaWiper Backdoor Combines Disk Wiping, Fake Ransomware, and Spyware
Microsoft has analyzed a modular Windows backdoor called GigaWiper that fuses three distinct destructive capabilities into a single operator-controlled toolkit.
Dormant GitHub Accounts Used to Map Corporate Orgs via API Scraping
Datadog Security Labs has identified multiple overlapping campaigns systematically enumerating GitHub organizations, repositories, and user accounts, with attackers hiding behind aged ghost…
Fake Paysafe and Skrill SDKs on npm and PyPI harvest developer credentials
Seventeen malicious packages mimicking legitimate payment SDK APIs silently exfiltrate API keys, cloud tokens, and system metadata to an attacker-controlled AWS server.
Eight Greeks Sue Intellexa for $8.7M Over Predator Spyware Surveillance
Eight Greek nationals targeted by Predator spyware have filed a civil lawsuit against Intellexa and 13 associated individuals, seeking roughly 7.6 million…