
Month: October 2025
-
The ClickFix Factory: First Exposure of IUAM ClickFix Generator
We have uncovered a phishing kit named the IUAM ClickFix Generator that automates the creation of these attacks. The kit…
-
Crimson Collective: A New Threat Group Observed Operating in the Cloud
Over the past few weeks, Rapid7 has observed increased activity of a new threat group attacking AWS cloud environments with…
-
Blog Anatomy of a Hacktivist Attack: RussianAligned Group Targets OT/ICS
Forescout honeypot caught hacktivist activity targeting a decoy water treatment plant in Sept. 2025. A Russian-aligned group, TwoNet, claimed responsibility…
-
The Crown Prince, Nezha: A New Tool Favored by ChinaNexus Threat Actors
A sophisticated cyber intrusion campaign utilizing log poisoning and a new tool called Nezha has been uncovered. The attackers exploited…
-
The Crown Prince, Nezha: A New Tool Favored by ChinaNexus Threat Actors
A sophisticated cyber intrusion campaign utilizing log poisoning and a new tool called Nezha has been uncovered. The attackers exploited…
-
The Crown Prince, Nezha: A New Tool Favored by ChinaNexus Threat Actors
A sophisticated cyber intrusion campaign utilizing log poisoning and a new tool called Nezha has been uncovered. The attackers exploited…
-
Attackers Actively Exploiting Critical Vulnerability in Service Finder Bookings Plugin
On June 8th, 2025, we received a submission through our Bug Bounty Program for an Authentication Bypass vulnerability in Service…
-
Velociraptor leveraged in ransomware attacks
Ransomware operators are using Velociraptor, an open-source digital forensics tool, in their attacks. The activity is attributed to Storm-2603, a…
-
Velociraptor leveraged in ransomware attacks
Ransomware operators are using Velociraptor, an open-source digital forensics tool, in their attacks. The activity is attributed to Storm-2603, a…
-
APT Meets GPT: Targeted Operations with Untamed LLMs
Over the course of three months, Volexity observed UTA0388 using various themes and fictional identities across dozens of spear phishing…

