- Services
- Products
- Compliance
- Markets
- Insights
- About
Threat Intel Update
This cyber threat roundup mixed enforcement wins with fresh attacker activity. Authorities dismantled Kratos, a phishing-as-a-service platform used to steal Microsoft credentials, while researchers flagged a Claude Cowork flaw that could let local AI agents reach files on a host Mac.
On the attack side: the FBI warned of AI-generated scams and fake IC3 sites targeting past fraud victims, and a separate campaign abused Claude Artifacts to spread SectopRAT malware via a fake download page. Arctic Wolf also reported Qilin ransomware affiliates exploiting a PAN-OS GlobalProtect bypass for initial access, underscoring the need to patch internet-facing remote access tools quickly.
Cybersecurity News
- Kratos Phishing Platform Seized in International Takedown – German and U.S. authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting its Indonesian developer. The service had roughly 1,800 customers running about 15,000 phishing campaigns a month across 35 countries, mainly targeting Microsoft credentials for use in BEC, account takeover, and data theft. BleepingComputer
- Claude Cowork Flaw Lets AI Agents Escape to Host Mac Filesystem – Researchers disclosed a sandbox escape (dubbed SharedRoot) in Claude Cowork for macOS that let an AI agent break out of its VM and access the entire host filesystem, including SSH keys and cloud credentials. Roughly 500,000 users running local sessions were exposed before Anthropic shifted new sessions to cloud execution by default; users who still opt for local execution remain at risk. The Hacker News
- FBI Warns Scammers Are Re-Targeting Fraud Victims with Fake IC3 Sites – The FBI warned that scammers are impersonating agents and spoofing the IC3.gov complaint site to re-victimize people who’ve already reported fraud, using AI-generated videos and fake profiles to steal money and personal data. Hack Read
- Fake Claude Download Page on claude.ai Spread SectopRAT Malware – Attackers hosted a fake Claude desktop app download page as a Claude Artifact, promoted via a sponsored Bing ad, tricking employees at 29 organizations into installing SectopRAT malware over two days before takedown. The page drew over 7,000 views and exploited trust in the claude.ai domain itself. Help Net Security
- Qilin Ransomware Exploits PAN-OS Bypass for VPN Access – Arctic Wolf reported Qilin ransomware affiliates exploiting a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to gain unauthenticated VPN access, then steal data and deploy ransomware, a reminder to patch internet-facing remote access systems promptly. The Hacker News
Sign Up
To receive Threat Briefings by email.