The United States Federal Bureau of Investigation (FBI) has issued an urgent warning about an emerging phishing-as-a-service (PhaaS) platform known as Kali365, which enables cybercriminals to hijack Microsoft 365 accounts while bypassing traditional multi-factor authentication (MFA) protections. According to the FBI, Kali365 first appeared in April 2026 and is primarilyContinue Reading

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where “feasible” to safeguard against potential threats stemming from threat actors’ abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerabilityContinue Reading

The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following the joint U.S.-Israeli military campaign against the country in late February 2026. TheContinue Reading

A Singapore-based company has reportedly lost more than US$36 million in a sophisticated business email compromise (BEC) scam after fraudsters impersonated the chairman of the company’s headquarters and manipulated senior executives into authorizing massive fund transfers. According to Singapore authorities, the incident was among the major cases uncovered during “OperationContinue Reading

International law enforcement agency INTERPOL has announced the arrest of more than 200 suspected cybercriminals during a major multinational crackdown dubbed “Operation Ramz,” targeting phishing scams, malware attacks, and online fraud networks across the Middle East and North Africa (MENA). The operation, carried out in collaboration with national police agenciesContinue Reading