Phishing remains the most common initial attack vector, with campaigns growing more sophisticated through AI-generated content, deepfake technology, and real-time MFA bypass kits. defend.network tracks phishing campaigns that target enterprise environments, from business email compromise to credential harvesting at scale, with a focus on techniques that bypass traditional email security controls.
PEEP toolkit turns Chrome and Edge into post-compromise backdoors; Magento StyleSmuggler zero-day actively exploited to deploy Linux backdoors; BigBear phishing framework bypassed MFA at 258 organizations and stole 5,000+ Microsoft 365 credentials.
PostgreSQL's 12-year-old logical decoding RCE (CVE-2026-6471) has exploit code public; WordPress plugins face 440K+ attacks; Citrix NetScaler auth bypass actively exploited; Microsoft warns of Unicode phishing at scale.
Cisco patches critical Nexus 9000 unauthenticated RCE affecting 10 Silicon One switches; HPE releases 8 CVEs in ArubaOS-CX. Coder's Cloudflare infrastructure hijacked to distribute malicious Terraform modules. 153M+ driver licenses offered on dark web.
JFrog Artifactory CVE-2026-82329 (CVSS 9.8) exploited to mint admin tokens; Langflow CVE-2026-0768 RCE active for API key theft. Two alleged TeamPCP supply-chain attackers arrested in Australia. iOS spyware campaign harvesting wallet seeds.
$320/month subscription model.
Mirage2FA phishing toolkit has compromised 4,500 US/EU organizations via Microsoft 365 spoofing; Oracle Weblogic Server vulnerability (CVE-2026-21962) added to CISA KEV with 3-day patch deadline; NVIDIA NemoClaw vulnerable to unauthenticated model poisoning.
Android car head units infected via malware-laden firmware updates; 9,300+ AWS keys remain active; Snowflake extortionist pleads guilty after compromising 165+ organizations.
14 trojanized npm packages deliver RedC2 4.0 Linux backdoor; 9,300 active AWS keys exposed; Microsoft Defender boot driver weaponized for security software deletion.
Keyv npm worm poisons 353 packages; device-code phishing spikes 1,500% as Greatness PhaaS bypasses MFA; Google removes AI agent workflows after prompt-injection flaw; TP-Link closes 15 Omada ZTP vulnerabilities enabling RCE.
Microsoft patched record 570 vulnerabilities; Check Point SmartConsole and SharePoint RCE added to CISA KEV with July 25 federal deadline; BlueNoroff phishing kit profiles crypto wallets before malware delivery.
Russian intelligence phishing campaign now targets Signal backup recovery keys; Cisco vulnerability under active exploitation with CISA emergency deadline; KDDI email breach exposes 14.2M credentials across six ISPs.
Russian intelligence expanding Signal phishing to steal backup keys; Turla deploys StockStay malware against Ukraine; AI coding agents tricked into executing malware via GitHub repositories.
Russian intelligence phishing now targets Signal Backup Recovery Keys. Linux kernel privilege escalation (CVE-2026-46331) has working exploit. AWS Q flaw (CVE-2026-12957, CVSS 8.5) allows malicious repos to steal cloud credentials.
ChatGPT share links abused for malware delivery; Marimo CVE-2026-39987 exploited with LLM agents for post-compromise activity; Dutch authorities seize 800 Russian-linked servers and arrest hosting executives.
Microsoft disrupted Fox Tempest malware-signing service; Drupal critical patches May 20; OAuth phishing bypasses MFA on 340+ Microsoft 365 organizations. CVE-2026-31635 Linux PoC public.
Critical vulnerabilities in cPanel and MOVEit, widespread RMM-based phishing compromising 80+ organizations, and supply-chain malware in PyTorch Lightning demand immediate patching and credential rotation.
Critical vulnerabilities, state-sponsored token harvesting, large-scale phishing operations, and coordinated SaaS extortion attacks demand immediate defensive action across government and technology sectors.
Nation-state campaigns targeting European governments and supply chain infrastructure. TA416 resumes targeting with PlugX. North Korean UNC1069 compromises Axios npm. Device code phishing surges 37x.
AI-powered autonomous cyber espionage, device code phishing at 340+ organizations, and critical infrastructure vulnerabilities require immediate defensive action across all sectors.
Russian intelligence conducting mass Signal/WhatsApp phishing; critical Oracle RCE vulnerability; Trivy supply-chain attack spreads CanisterWorm across 47+ npm packages; VoidStealer bypasses Chrome encryption; Iran-backed wiper attacks on medical technology.
Critical Oracle RCE, Russian state-sponsored phishing, Trivy supply-chain worm, and Iran-backed healthcare wiper attacks demand immediate emergency response and patching across enterprise infrastructure.
Subscribe free and never miss a threat briefing.