Cybersecurity News
Filters
Filtered by tag: threat intelligence × Clear
New Windows malware lays dormant until a custom command activates it like a sleeper agent
SLEEPWALKER is a newly discovered Windows malware implant that contains no malicious code, instead lying dormant until receiving a specially crafted network signal. Disguised as ESET's Management Agent, it evades security software entirely. Once activated, it can schedule tasks, communicate with remote systems, and execute code. Researcher Dominik Reichel believes it's likely a nation-state tool targeting specific victims, though no active campaigns or confirmed victims have been identified.
17th August – Threat Intelligence Report
Colombia's Ministry of Justice suffered a ransomware attack disrupting technology infrastructure and public services tied to drug monitoring and legal processes, with officials confirming file compromise. Other notable incidents include additional breaches and cyberattacks detailed in Check Point Research's weekly Threat Intelligence Bulletin, covering top attacks, emerging vulnerabilities, and threat actor activity for the week of 17th August.
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
Matched: cryptocurrency
China-linked threat actor Jewelbug conducts cyber espionage against governments and militaries while also running cryptocurrency fraud operations. Both activities are managed through a single control panel called XG-Web, a browser-based framework that converts victims' browsers into remote-control tools for data theft and access.
The State of Ransomware Q2 2026
Ransomware activity in Q2 2026 shows signs of shifting dynamics, according to Check Point Research. While dominant ransomware-as-a-service operations continue leading the space, the previously consolidating landscape is beginning to fragment. Established groups maintain their dominance, but emerging players are increasingly challenging the concentration of power that has defined the ransomware ecosystem over the past year.
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Matched: cryptocurrency
Researchers have identified a threat actor dubbed "Jewelbug," a hackers-for-hire group conducting both state-sponsored espionage and cryptocurrency theft through the same infrastructure. The dual-purpose operation — mixing intelligence gathering with financial crime — is unusual, suggesting the group serves government clients while simultaneously running independent profit-driven attacks, blurring the line between nation-state and cybercriminal activity.
10th August – Threat Intelligence Report
North Carolina Ports suffered a cyberattack disrupting operations at Wilmington, Morehead City and other ports, forcing some processes to revert to manual operation. The authority says the incident has been contained. Additional details on other attacks, breaches, vulnerabilities, and threat intelligence findings are available in Check Point Research's full Threat Intelligence Bulletin for the week of 10th August.
3rd August – Threat Intelligence Report
Minnesota IT Services confirmed coordinated cyberattacks on over 30 community water utilities, briefly disrupting a treatment plant in Braham and affecting industrial control systems. The incidents highlight ongoing vulnerabilities in critical infrastructure. Further details on this and other threats are available in Check Point Research's weekly Threat Intelligence Bulletin for the week of 27th July.
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Attackers are abusing Microsoft 365's device code authentication flow to steal tokens without needing credentials. Victims are tricked into entering attacker-generated codes at legitimate Microsoft login pages, granting persistent access. The technique bypasses MFA and leaves minimal obvious indicators. Huntress advises monitoring for unusual device code authentication requests, unexpected token grants, and sign-ins from unfamiliar locations or clients.
27th July – Threat Intelligence Report
Nichirei, a Japanese frozen-food and logistics company, suffered a ransomware attack disrupting shipping operations and affecting around 5,000 customers, with KFC Japan warning of possible shortages. Personal data theft was confirmed. The incident is among several attacks and breaches covered in Check Point Research's Threat Intelligence Bulletin for the week of 27th July.
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
A malvertising campaign discovered in late July used a fake Claude AI artifact hosted on Anthropic's legitimate domain to trick users into downloading malware. The attack, dubbed FakeAgent, infected 29 organizations with SectopRAT, an information-stealing trojan capable of harvesting credentials and sensitive data. The campaign exploited user trust in the authentic Claude domain to bypass suspicion.
20th July – Threat Intelligence Report
Ernst & Young disclosed a data breach via a compromised third-party IT support platform, potentially exposing client documents and tax information in support tickets. The report also covers other notable attacks and breaches from the week of 20th July, with full details available in Check Point Research's Threat Intelligence Bulletin.
It’s Not Safe To Pay SafePa
Huntress researchers have observed multiple ransomware groups, including Akira, ReadText34, and INC, deploying attacks through SafePay. The findings highlight how ransomware affiliates are actively leveraging the platform to conduct operations, raising significant security concerns for organizations potentially exposed to these threat actors.
Every Ransomware Attack Has a Backstory
Ransomware attacks don't begin with encryption — they start long before, often with access brokers selling stolen credentials or network entry points to attackers. Criminals then use legitimate tools already present in the environment to move quietly through systems, avoiding detection. By the time ransomware deploys, attackers may have been inside for weeks. Stopping them requires catching intrusions early, before the final stage.
Who Runs the Ransomware Group ‘The Gentlemen?’
A ransomware group called The Gentlemen has quickly become the second most active such gang, luring hackers with a 90% affiliate payout. An investigation into the group's administrator reveals clues pointing to a real-world identity behind the operation, though the group's rapid rise and recruitment success make it a significant emerging cybercrime threat.
