Cybercrime
FBI and Google Disrupt NetNut Residential-Proxy Network Spanning Two Million Devices
A scale-significant proxy-network takedown — law-enforcement coverage and defender awareness this week.
Actionable insights into the global threat landscape. Analysis of TTPs, Indicators of Compromise (IoCs), and emerging attack patterns.
Cybercrime
A scale-significant proxy-network takedown — law-enforcement coverage and defender awareness this week.
Threat Intelligence
Vendor-driven proxy-network disruption continues — defender teams review perimeter-detection posture this week.
Ransomware
Threat-cluster convergence between FortiBleed and two ransomware families — defender teams stay in credential-verification posture this week.
Threat Intelligence
An APT-tooling disclosure with corporate-Gmail implications — defender teams review OAuth-token hygiene this week.
Phishing
Two vendor-documented hospitality-sector phishing campaigns land the same week — sector-advisory work for hotel-industry defenders this week.
Microsoft 365
A scale-significant Azure CLI credential-attack campaign — defender teams stay in account-hardening posture this week.
Data Breaches
One confirmed victim, a reported 99 more not yet named — Oracle PeopleSoft customers stay in patch-verification posture this week.
Vulnerabilities
A critical remote monitoring and management vulnerability is under active exploitation to deliver an infostealer that hunts cloud and AI development credentials — and it is now on CISA's KEV list.
Threat Intelligence
Browser-extension enforcement action at scale from Microsoft. The company pulled 119 Edge add-ons that concealed payloads inside image and font files, with a combined install base reported at up to 2.6 million, and suspended the developer accounts behind them.
Supply Chain Attack
Another JavaScript-ecosystem supply-chain disclosure puts developer-secret rotation and GitHub Actions auditing back at the top of the defender to-do list — this time as a fresh wave of the ongoing Miasma cluster.
Nation-State Cyber Threats
Another Russia-linked backdoor lands on defenders' desks for review. Google Threat Intelligence Group and Mandiant have detailed STOCKSTAY, a .NET implant Turla has deployed against Ukrainian government and military networks since at least 2022.
Cybercrime
A retrospective frame on the most consequential law-enforcement effort against cybercrime infrastructure, as Operation Endgame's coordinators recast a string of 2026 takedowns as one sustained assault on the criminal supply chain.