- Services
- Products
- Compliance
- Markets
- Insights
- About
Threat Intel Update
This week’s threats highlight fast-evolving attacker tactics. Researchers found the first ransomware attack run entirely by AI, exploiting a vulnerability, stealing and deleting data, and demanding extortion with no human involved.
Social engineering is escalating too, with fake job interviews and IT support calls stealing credentials and spreading malware, plus phishing hidden until it decrypts in-browser to hit Microsoft 365 accounts. Separately, Chinese-linked actors are expanding a router botnet (LONGLEASH) to build infrastructure for future attacks.
AI-driven attacks, identity phishing, and unpatched systems are this week’s biggest risks.
Cybersecurity News
- AI Ransomware Attacks Without Human Help – Researchers at Sysdig found JadePuffer, the first ransomware campaign run start-to-finish by an AI model with no human operator. It exploited a Langflow flaw, hit an exposed MySQL/Nacos server, then stole data, deleted it, and issued an extortion note, adapting in real time to compromise the target in just 31 seconds. Dark Reading
- Fake Job Interviews Steal Google Credentials – A phishing campaign impersonating 30+ brands (Adobe, Netflix, Coca-Cola, OpenAI) is using fake job interviews to steal marketing professionals’ Google account credentials, risking exposure of business data and connected services. Bleeping Computer
- “Ghost Phishing” Hides From Email Security – The EvilTokens campaign encrypts phishing pages so they stay invisible to email scanners until decrypted in the victim’s browser, then uses Microsoft device code phishing to hijack accounts. It’s hitting multiple sectors across the U.S. and Europe, with consulting and financial services most exposed. The Hacker News
- Fake IT Calls on Teams Spread Malware – Attackers are impersonating IT support over Microsoft Teams calls to trick employees into installing EtherRAT malware, exploiting trust in internal support channels to gain network access. BleepingComputer
- Chinese Hackers Grow Router Botnet – A Chinese hacking group tracked as UAT-7810 has built new LONGLEASH malware to grow its Operational Relay Box (ORB) network, actively targeting internet-facing devices, especially unpatched Ruckus routers. By compromising more routers, the group expands its infrastructure and gains persistent footholds across many devices, putting organizations that use affected equipment at risk. BleepingComputer
Sign Up
To receive Threat Briefings by email.