Cybersecurity threats are surging as attackers leverage fake software repositories, trojanized installers, and sophisticated phishing toolkits to steal credentials, deploy ransomware, and conduct large-scale financial fraud globally.
Key Points
- Threat actors are distributing malware via 290+ fake GitHub repositories and malicious NuGet packages that impersonate legitimate developer and gaming tools.
- The UAT-11795 group is deploying Starland RAT and WLDR agents through trojanized installers for common enterprise software like Zoom and MobaXterm.
- CISA added two critical vulnerabilities, including an Oracle E-Business Suite flaw (CVE-2026-46817), to its Known Exploited Vulnerabilities catalog for immediate federal patching.
- New phishing toolkits like Jalisco and OmegaLord are bypassing multi-factor authentication by exploiting OAuth device codes and intercepting user credentials.
- European authorities dismantled massive fraud networks, including one operation involving 700 employees and another laundering €140 million through hundreds of bank accounts.