Passkey-Themed Social Engineering Lures Attempt to Compromise Identity and Cloud Platforms

Executive Summary Microsoft Security Research published in a report  on 9 September 2026 tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. The activity begins with identity-focused social engineering and impersonation infrastructure,…

Read More

Arctic Wolf Releases Cordial Spider/PREY-0058 Report of IT Help Desk Vishing for Cloud Data Theft and Extortion

Executive Summary Arctic Wolf is tracking a widespread data theft and extortion threat cluster designated as PREY-0058, also known as Cordial Spider and the previously-mentioned UNC667, above. This activity, detailed in a GitHub blog post published on 4 September 2026, targets Microsoft 365 and other SaaS services through IT help-desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins. Analysis of…

Read More

FBI Investigates Listing of 153M+ Drivers Licenses for Sale

Executive Summary A dark web marketplace is selling 153,000,000 American and Canadian driver’s licenses, reportedly siphoned from idscan[.]net, according to multiple social media posts. The illicit marketplace, dubbed Nexus, sells scans of IDs on over 170 million people in North America. This platform specializes in in-person identity verification and serves businesses such as major retail and shipping entities, marijuana…

Read More

TerminalFix Campaign Targets Multiple Critical Sectors with ClickFix Variant

Executive Summary On 28 August 2026, Microsoft Threat intelligence reported details of what they have dubbed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. The PowerShell command masquerades…

Read More

Cyberattack on Manchester Airports Group Exposed Data of 8.7 Million Customers

Executive Summary Manchester Airports Group has disclosed on 27 August 2026 that an unauthorized third party accessed customer data belonging to approximately 8.7 million people across three of England’s busiest airports: Manchester, London Stansted, and East Midlands. The incident involved data related to parking lot, lounge and fast-track bookings and in-airport Wi-Fi sign-ups, and the hackers obtained email…

Read More

Lab539 Uncovers WordPress Campaign Utilizing PowerShell RAT to Target Entities

Executive Summary Researchers from Lab539 on 12 August 2026 observed a widespread campaign utilizing compromised WordPress sites to deliver a ClickFix verification flow that prompts users to execute a malicious PowerShell command. The injected JavaScript employs an EtherHiding mechanism, retrieving AES-encrypted code from an Ethereum smart contract on the Sepolia network rather than hardcoding the payload…

Read More

When Your Vendor’s Vendor Goes Down: What a Logistics Incident Teaches Retailers About Fourth-Party Risk

A Single Incident Ripples Across Industries In late July, a major global logistics and shipping provider was hit by a cyberattack that disrupted warehouse operations across Europe. The company, which operates more than 1,700 facilities in 170 countries, notified affected customers in early August that several European warehouses were unable to ship stored goods. Some…

Read More

Zombie Card Attack Exploits Contactless Payments for POS Terminals

Executive Summary Researchers at the University of Massachusetts Amherst report the technical details of an attack vector that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale terminal reads over near-field communication, without breaking any of the card’s cryptography. The attack, which the researchers named Zombie Card, requires physical…

Read More

When Your Vendor’s Vendor Goes Down: What a Logistics Incident Teaches Retailers About Fourth-Party Risk

A Single Incident Ripples Across Industries In late July, a major global logistics and shipping provider was hit by a cyberattack that disrupted warehouse operations across Europe. The company, which operates more than 1,700 facilities in 170 countries, notified affected customers in early August that several European warehouses were unable to ship stored goods. Some…

Read More

TheHatman Listing Major Retail and Hospitality Azure/Entra Records on Dark Web Forum

Executive Summary A threat actor known as TheHatman is currently selling massive internal employee directories belonging to major retail entities on Breached cybercrime forum. Starting on 31 July, TheHatman advertised data dumps allegedly downloaded directly from the organizations’ Azure and Entra portals utilizing compromised credentials. The campaign impacts multiple global retail and hospitality organizations, with the threat…

Read More