SeasonalInvite: The RMM Trap in eCards
A sophisticated six-month phishing campaign is exploiting legitimate RMM software via fake greeting cards to compromise systems.
Data breaches, ransomware payouts, and phishing operations rarely make the news until the damage is already done. This is where Xploitwire tracks the attackers — who they are, how they got in, and what it means for the organizations and people caught in the blast radius.
A sophisticated six-month phishing campaign is exploiting legitimate RMM software via fake greeting cards to compromise systems.
The US has sanctioned a VPN administrator and a cryptor vendor, escalating a crackdown on the ransomware supply chain.
Spanish police dismantle a sophisticated international network linked to over $160 million in investment and BEC-related fraud.
A Welsh man received a prison sentence for coordinating global swatting campaigns and creating propaganda to incite further attacks.
UK and EU officials link the December 2025 attack on Poland's power grid to Russian state operatives, prompting new sanctions.
A malicious campaign using hundreds of fake repositories is actively deploying the BoryptGrab infostealer to compromised machines.
A sophisticated new macOS threat masquerades as system crash reporting tools to siphon credentials through a notarized infection chain.
Treasury sanctions VPN and cryptor suppliers to disrupt the underlying network that supports global ransomware operations.
A breach at a third-party IT vendor has exposed personal data of Lidl customers, forcing a security alert across multiple countries.
A Telegram-based phishing service is lowering barriers to entry for M365 attacks by automating complex bypass and exfiltration workflows.
Five individuals are facing charges in connection with a sophisticated vishing operation that facilitated millions of fraudulent calls.
Compromised publishing credentials allowed attackers to inject malicious binaries into widely used Jscrambler NPM versions.
Federal authorities have sanctioned a specialized VPN provider and a malware cryptor vendor to disrupt ransomware supply chains.
Federal authorities are hunting two state-linked cyber groups behind a persistent, large-scale campaign targeting Signal and WhatsApp.
A deep dive into the operational identity and recruitment tactics driving one of the fastest-growing ransomware-as-a-service groups.
Authorities seized 800 servers in a probe targeting individuals accused of facilitating cyberattacks through sanctioned networks.
Researchers have identified a new vector where cloud-hosted AI infrastructure is being hijacked for illicit cryptocurrency operations.
Threat actors are weaponizing reservation-themed emails with container files to bypass modern Microsoft Office security protections.
A wide-ranging breakdown of recent cybersecurity disruptions, from intelligence agency offensives to critical enterprise data leaks.
A third-party security failure exposed customer data, forcing the retail giant to warn users about the heightened risk of phishing attacks.