Malicious APAC Gambling Sites Disguised to Deliver Chinese APT Malware

Executive Summary An Infoblox cybersecurity report, published on 15 September 2026, has revealed that online casinos are being used to disguise and deploy malicious threats targeting governments across Asia. Infoblox researchers discovered that a computer script known as PeckBirdy is being embedded into Chinese-language casino websites to avoid detection by targets and security software. These…

Read More

Passkey-Themed Social Engineering Lures Attempt to Compromise Identity and Cloud Platforms

Executive Summary Microsoft Security Research published in a report  on 9 September 2026 tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. The activity begins with identity-focused social engineering and impersonation infrastructure,…

Read More

Arctic Wolf Releases Cordial Spider/PREY-0058 Report of IT Help Desk Vishing for Cloud Data Theft and Extortion

Executive Summary Arctic Wolf is tracking a widespread data theft and extortion threat cluster designated as PREY-0058, also known as Cordial Spider and the previously-mentioned UNC667, above. This activity, detailed in a GitHub blog post published on 4 September 2026, targets Microsoft 365 and other SaaS services through IT help-desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins. Analysis of…

Read More

FBI Investigates Listing of 153M+ Drivers Licenses for Sale

Executive Summary A dark web marketplace is selling 153,000,000 American and Canadian driver’s licenses, reportedly siphoned from idscan[.]net, according to multiple social media posts. The illicit marketplace, dubbed Nexus, sells scans of IDs on over 170 million people in North America. This platform specializes in in-person identity verification and serves businesses such as major retail and shipping entities, marijuana…

Read More

TerminalFix Campaign Targets Multiple Critical Sectors with ClickFix Variant

Executive Summary On 28 August 2026, Microsoft Threat intelligence reported details of what they have dubbed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. The PowerShell command masquerades…

Read More