Defending against an active threat to Siemens S7 Series PLCs

This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their Read More …

‘Proactive SIM’ cards can hijack smartphones, IoT devices and even EV chargers

A malicious SIM card can instruct the device it sits in to run commands of an attacker’s choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the Read More …

Mitigating large-scale credential attacks

Identity has effectively become the new perimeter, where cybercriminals are increasingly choosing to log in rather than break in. To accomplish this, attackers frequently gather previously leaked username and password pairs. Gathering these credentials can then allow them to pivot Read More …

Hunting MacSync Stealer infrastructure through behavioral pivots

MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement Read More …

CISA gives feds 3 days to fix actively exploited Ray RCE bug

CISA says attackers are exploiting a critical 2025 vulnerability in Ray, the widely used open source framework for scaling Python and machine-learning workloads. Tracked as CVE-2025-62593 and rated 9.4 under CVSS v4, the bug was first disclosed in November 2025. Read More …

‘Unprecedented’ number of Apple users received recent spyware alert, say investigators

An unprecedented number of Apple customers have reported receiving a recent threat notification alerting them to suspected spyware attacks targeting their devices, according to experts who investigate these types of incidents. Several people publicly and privately reported receiving Apple’s spyware Read More …

Update your Mac: Screen Sharing vulnerability exploited in the wild

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers. The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is Read More …

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Read More …

McDonald’s, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials

A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a Read More …