Visualização de leitura

Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures

Pegasus, Pegasus Spyware, Serbia, Serbia Protests, Smartphone screen forming an eye shape against an abstract protest crowd, illustrating spyware targeting of Serbian student activists.

At least 14 people connected to Serbia's student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country.

The group said the cohort includes student movement members, civil society activists, a member of parliament and a local councilor. Forensic analysis was independently confirmed by the Citizen Lab at the University of Toronto and by Amnesty International's Security Lab.

Citizen Lab, in its own findings, said it verified an infection with NSO Group's Pegasus on the iPhone of a student activist who asked not to be named. High-confidence infection indicators span December 2025 through January 2026, delivered by a zero-click iMessage exploit that required no interaction from the target. Apple has since patched the underlying flaw; the fix shipped in iOS 18.4.1. Pegasus grants an operator access to notes, photographs and messages decrypted on the device, and can silently activate the microphone and camera.

Amnesty's Security Lab confirmed a new variant of NoviSpy, an Android implant first identified in Serbia in 2024, on two additional devices. SHARE said the rebuilt version was designed to evade the detection methods that exposed its predecessor.

Also read: Investigative Journalists in Serbia Hit by Advanced Spyware Attack

The circumstances of two infections are what elevate the findings beyond routine spyware reporting. SHARE said one NoviSpy infection appeared after police seized a student's phone during questioning, and another after private messages from that device were published by a pro-government media outlet. Donncha Ó Cearbhaill, who heads Amnesty's Security Lab, said the evidence suggests "infections are being carried out during detention by Serbian authorities."

Suspicion centers on Serbia's Security Information Agency, or BIA. Amnesty's December 2024 report "A Digital Prison" found earlier NoviSpy samples configured to send collected data to IP addresses associated with BIA servers, and documented the agency's parallel use of Cellebrite extraction tools on journalists and activists. In March 2025, Amnesty reported that two journalists at the Balkan Investigative Reporting Network were targeted with Pegasus.

The current cases surfaced through Apple's threat notification wave of Aug. 13, which reached users in 110 countries. The timing is politically loaded. The targeting overlaps with protests that followed the November 2024 collapse of a railway station canopy in Novi Sad, spans local elections held March 29 in 10 municipalities, and precedes October parliamentary elections widely read as a test of the ruling Serbian Progressive Party.

Ana Toskic Cvetinovic, a legal expert cited in the reporting, noted that deploying intrusive software without judicial authorization is unlawful under Serbian law. SHARE published an analysis of the domestic legal framework in January arguing the same. Criminal complaints filed over the 2024 cases remain pending before Serbian courts, with no resolution.

Also read: 7 New Pegasus Infections Found on Media and Activists’ Devices in the EU

NSO has been on the U.S. Commerce Department's Entity List since 2021.

Serbia is an accession candidate, the European Parliament has previously questioned the Commission over unlawful spyware use in the country, and the Commission published its 2026 enlargement country report in July. Amnesty's submission for that package raised surveillance directly.

Both groups urged at-risk users to enable Lockdown Mode on iOS or Advanced Protection on Android.

Point72 Among Major Hedge Funds Targeted in Cyberattack on Wall Street Through Voice Phishing Campaign

Point72

A cyberattack on Wall Street recently targeted several leading hedge funds, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers used voice phishing, or "vishing," to trick employees into revealing sensitive information or granting access to internal systems.  Cybersecurity experts say such attempts are common because financial institutions store highly sensitive data. However, the latest incidents highlight how cybercriminals are increasingly combining traditional social engineering tactics with artificial intelligence to make impersonation attempts more convincing. 

Point72 Says No Client Data Was Compromised 

According to reports, Point72 Asset Management informed investors on August 5 that it had been targeted in the latest cyberattack on Wall Street. Bloomberg first reported the communication, citing a source familiar with the matter.  The firm said it was reviewing the incident and that no client information had been stolen. Point72 declined to comment publicly.  The campaign extended beyond Point72, with hackers also attempting to breach the information systems of Millennium Management, Two Sigma Investments, and Citadel, according to sources. 

Voice Phishing Remains an Effective Attack Method 

The attackers relied on voice phishing, a social engineering technique in which criminals impersonate trusted individuals—often IT support staff—to persuade employees to disclose confidential information or provide system access.  Cybersecurity experts told Reuters that these attacks are routine because of the valuable information held by financial firms. Rather than exploiting software vulnerabilities, voice phishing succeeds by manipulating human behaviour.  The tactic has also been used successfully by the cybercriminal group "Scattered Spider," a loosely organized network of young hackers that has targeted numerous companies in recent years. 

AI Is Increasing the Sophistication of Cyberattacks 

Security experts say the attempted cyberattack on Wall Street demonstrates how artificial intelligence is making social engineering campaigns more persuasive and difficult to detect.  A similar trend was highlighted in June, when Google's cybersecurity unit published a report detailing a campaign targeting U.S. law firms and other professional and financial services organizations.   According to the report, attackers posed as IT support personnel through voice phishing calls and, in some cases, even visited offices while pretending to be IT maintenance staff. 

Growing Cyber Risks for Financial Firms 

The attempted cyberattack on Wall Street comes as organizations worldwide face a rise in AI-powered cyberattacks and ransomware incidents that disrupt operations and steal sensitive data.  In response to the growing threat, the White House announced a working group earlier this year that brings together AI developers and critical infrastructure operators to share threat intelligence and strengthen cyber defenses.  Although Point72 said no customer information was compromised, the attempted attacks on several prominent hedge funds underscore the persistent cybersecurity risks facing the financial sector and the increasing use of AI-enhanced social engineering by threat actors. 

Tanaka Dominates Data Leak Landscape With 25 Leak Posts

Tanaka

Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.  Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publishing stolen information, Tanaka emerged as the most active, accounting for 25 distinct leak posts — more than double the activity of several other major actors. 

A Data Leak Operation Without Industry Boundaries 

Unlike threat actors that specialize in a single vertical, Tanaka followed a broad targeting approach across multiple industries and regions. The actor’s campaigns showed no strict preference for a specific sector, instead focusing on organizations where stolen information could hold financial or strategic value.  The Banking, Financial Services, and Insurance (BFSI) sector remained the most targeted industry globally, accounting for 38 breach incidents during the reporting period. Financial organizations continue to attract attackers due to the value of customer information, account data, and personally identifiable information (PII).  Government and Technology organizations were also frequent targets, reflecting the wider value of sensitive records, intellectual property, and institutional data. 

Regional Presence Across Major Markets 

Tanaka’s activity was visible across multiple regions. In North America, the actor was responsible for seven leak posts, making it the most active data leak actor in the region alongside other prominent sellers.  Europe and the UK also saw significant activity, with Tanaka linked to six leak posts during H1 2026. The region’s BFSI, Telecommunications, and Retail sectors faced heightened exposure due to the amount of valuable customer and financial data they hold.  The actor’s global footprint demonstrates how modern data leak operations can function independently of geography. Instead of focusing on a single country or industry, operators like Tanaka exploit opportunities wherever valuable information becomes available. 

The Rise of the Data Leak Marketplace 

Tanaka’s activity reflects a broader shift in the cybercrime ecosystem. Data leaks are no longer only a byproduct of ransomware attacks; they have become a standalone business model.  Threat actors monetize stolen information through underground marketplaces, using leaked databases for fraud, extortion, intelligence gathering, or resale. This specialization mirrors other parts of the cybercrime economy, where access brokers, ransomware affiliates, and data sellers perform separate roles.  For organizations, this means a breach does not always begin with a ransomware demand. A stolen database appearing in underground channels may indicate an earlier compromise that requires immediate investigation. 

Staying Ahead of Data Exposure Risks 

Security teams must treat underground data exposure monitoring as part of their broader defense strategy. Identifying leaked credentials, compromised databases, or mentions in cybercrime marketplaces can provide early warning before stolen information is weaponized.  To understand the 2026 data breach landscape, including the most active threat actors, targeted industries, and regional trends, access the full Cyble H1 2026 Cyber Threat Landscape Report. 

Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT

Minnesota Medicaid fraud

Four Minnesota men have pleaded guilty to a Minnesota Medicaid fraud scheme that allegedly stole approximately $2.2 million from the state’s Housing Stabilization Services (HSS) program and used artificial intelligence to fabricate records when insurance companies requested documentation. The defendants admitted to submitting thousands of claims for services they never provided or significantly inflating claims to obtain higher reimbursements. The case involves four Twin Cities-area men who operated Brilliant Minds Services LLC from the Griggs-Midway Building in St. Paul, Minnesota. According to court documents, the business enrolled as a Medicaid program provider and claimed to help people with disabilities, including seniors and individuals with mental illnesses and substance use disorders, find and maintain housing through the now-defunct HSS program.

Minnesota Medicaid Fraud Scheme Targeted 350 Recipients

According to prosecutors, Moktar Hassan Aden, 31, Mustafa Dayib Ali, 29, Khalid Ahmed Dayib, 26, and Abdifitah Mohamud Mohamed, 27, signed up approximately 350 people for HSS. The defendants then billed Medicaid for services they allegedly did not provide to those recipients. The scheme reportedly operated from April 2022 through April 2025. During that period, the four men allegedly submitted thousands of HSS claims and fraudulently obtained approximately $2.2 million from Minnesota Medicaid. The case highlights the alleged misuse of a government program designed to provide housing-related support to vulnerable people. Authorities said the defendants exploited the program by claiming reimbursements for services that were never delivered or by submitting inflated claims.

Artificial Intelligence Used to Fabricate Records

The case also highlights the use of artificial intelligence in an alleged effort to conceal healthcare fraud. When insurance companies requested supporting documentation for the claims, the defendants used ChatGPT to fabricate records, according to court documents. The use of ChatGPT to create fake documentation adds another dimension to the health care fraud case, as authorities continue to investigate alleged schemes involving government-funded programs. The defendants allegedly used the fabricated records to conceal the fraudulent claims and support services they had claimed to provide. Assistant Attorney General Colin M. McDonald of the Justice Department’s National Fraud Enforcement Division said the defendants exploited vulnerable people and a vulnerable program for financial gain. U.S. Attorney for the District of Minnesota Daniel N. Rosen said Medicaid fraud carries serious consequences and that the funds involved were intended to support vulnerable Minnesotans relying on housing and recovery services.

Four Defendants Plead Guilty to Wire Fraud

In separate hearings held between July 7 and July 23, 2026, all four defendants pleaded guilty to one count of wire fraud. Each faces a maximum penalty of 20 years in prison. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors. Sentencing dates have not yet been set. The FBI, the U.S. Internal Revenue Service, Criminal Investigation, and the U.S. Department of Health and Human Services, Office of Inspector General, are investigating the case. Trial Attorney Raymond E. Beckering III of the Criminal Division’s Fraud Section and Assistant U.S. Attorney Matthew Murphy for the District of Minnesota are prosecuting the case.

Health Care Fraud Strike Force Continues Investigations

The case is part of the ongoing collaboration between the U.S. Attorney’s Office for the District of Minnesota and the Health Care Fraud Strike Force to combat fraud targeting government programs. The Department of Justice’s Health Care Fraud Strike Force Program currently includes nine strike forces operating across federal districts. Since 2007, the program has charged more than 6,200 defendants who collectively billed federal health care programs and private insurers more than $45 billion. The case also comes as the Justice Department’s National Fraud Enforcement Division focuses on investigating and prosecuting fraud against the American people. Authorities said efforts to combat fraud remain part of broader work targeting fraud, waste, and abuse within federal benefit programs.

One Country Absorbed Nearly Half of the World’s Ransomware Attacks in Just Six Months – The United States

Ransomware Attacks, Qilin, US, Ransomware Attacks on US

Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else: 1,721. That's how many ransomware attacks hit organizations in the United States between January and June, according to new research from Cyble Research and Intelligence Labs (CRIL). It's not just the highest total of any country tracked in the report — it's more than the next nine most-targeted countries combined.

Canada, in second place worldwide, recorded 179 attacks. Germany logged 155. The United Kingdom, 138. Add up the rest of the global top 10 — France, Italy, Spain, Thailand, India and Brazil — and the total still falls more than 600 attacks short of the U.S. figure alone. Out of 3,836 ransomware attacks CRIL tracked worldwide this half, roughly 45% landed on American soil.

Also read: Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

A Single Region, an Outsized Share

Widen the lens slightly and the picture holds. North America as a whole recorded 1,981 ransomware attacks in H1 2026 — more than half of every ransomware incident Cyble observed globally — alongside 35 data breach and leak incidents and 9 initial access sale listings. The report describes the region as home to "a mature, persistently active RaaS ecosystem operating at high volume across a wide range of industries and geographies."

Two ransomware-as-a-service operators did much of the damage. Qilin, the single most prolific gang worldwide, claimed 370 of those North American attacks on its own — nearly 19% of the regional total. Akira followed with 268, and INC Ransom added another 164. Together, Qilin and Akira alone accounted for more than half of all recorded ransomware activity across the region, a level of concentration that points to a small number of highly organized affiliate networks doing the bulk of the damage rather than a diffuse swarm of opportunists.

Also read: Qilin Ransomware Group’s TTPs Examined by Researchers

Where the Pressure Lands

Professional Services bore the brunt of North American ransomware activity, with INC Ransom showing a marked preference for law firms and other high-value services with sensitive client data. Construction, Manufacturing and Healthcare followed close behind.

One operator, AiLock, stood out for a coordinated wave of victim disclosures that all landed on the same day — March 3 — a pattern consistent with a mass-exploitation campaign rather than isolated intrusions. LockBit, despite years of law enforcement pressure and takedown attempts, kept up a steady tempo against public-sector and educational targets throughout the period, showcasing how difficult the group has been to fully dismantle.

On the data breach side, Technology and financial services (BFSI) were the most frequently targeted sectors in North America, together accounting for roughly 43% of incidents — a reflection of how much intellectual property and monetizable personal data those industries hold.

Notably, Agriculture & Livestock emerged as a significant target for initial access brokers, accounting for a third of all access listings tied to the region. Cyble flags this as a sign of "growing risk in the food supply chain," an area that has historically drawn less attention from ransomware operators than finance or healthcare.

The initial access market itself was strikingly concentrated: two sellers, tracked under the handles "redpin" and "xpl0itrs," accounted for nearly all listings targeting North American organizations. Threat actors also continued to lean on known and zero-day vulnerabilities in widely deployed enterprise platforms — including products from Ivanti and Palo Alto Networks — as their preferred way into corporate networks.

Hacktivism Blurs into Cybercrime

North America wasn't spared the hacktivism wave sweeping the rest of the world either. Collectives including SOLDADOS DIGITALES – UNIÓN AMERICANA and LYSTIC TEAM #ID drove roughly 56 data leak or dump posts and touched about 360 unique domains across the region, with Government, Technology, financial services and telecommunications entities most frequently in the crosshairs.

Cyble's broader findings suggest many groups marketing themselves as ideologically driven hacktivists are, in practice, running side businesses in stolen data brokerage and DDoS-for-hire services — a blurring of motive that complicates how defenders triage the threat.

The scale of the U.S. numbers doesn't necessarily mean American companies have weaker defenses than their global peers — the concentration also reflects the sheer size and digital density of the U.S. economy, and its outsized share of the high-value targets ransomware affiliates chase. But the data does argue for a shift in posture.

Cyble's broader recommendations — treating data exfiltration, not just encryption, as the primary risk; prioritizing patches for the recurring vendor list; and monitoring initial access markets as a leading indicator rather than an afterthought — apply nowhere more urgently than in a country absorbing this much of the world's ransomware volume on its own.

CVE-2026-48907 and LiteSpeed cPanel Plugin Flaws Come Under Active Attack

CVE-2026-48907

Security researchers and software vendors warn that attackers are actively exploiting vulnerabilities in both Joomla and the LiteSpeed cPanel plugin, posing significant risks to website administrators and shared hosting environments.  One of the most urgent issues is CVE-2026-48907, a critical vulnerability affecting the Joomla Content Editor (JCE). The flaw stems from an improper access-control weakness that allows unauthenticated attackers to upload editor profiles and, ultimately, execute arbitrary PHP code on vulnerable servers. Security experts say threat actors are already abusing the bug in real-world attacks.  The JCE security update was first released on June 3, 2026, with JCE version 2.9.99.5 addressing the vulnerability. A second release, version 2.9.99.6, followed on June 6 and introduced additional hardening measures. All JCE Pro versions before 2.9.99.5 are affected.  Over the weekend, Joomla urged administrators to update immediately, warning that CVE-2026-48907 is being exploited in the wild. The project stated: “The vulnerability is being actively exploited, working exploit code is public, and the attacks are automated, so a site with no public registration is not safe.” 

How CVE-2026-48907 Works 

According to the JCE security update advisory, attackers exploit the flaw by importing a malicious editor profile that permits uploads of executable files. Once the profile is installed, arbitrary PHP files can be uploaded and executed on the server.  Administrators are advised to review Components → JCE Editor → Editor Profiles for unfamiliar profiles, particularly those with randomly generated names or configurations allowing PHP uploads through plugins such as Image Manager or File Browser. Another warning sign is a front-end editor displaying a stripped-down toolbar.  The most reliable evidence of compromise is found in web server logs. Administrators should search for unauthenticated requests targeting index.php?option=com_jce&task=profiles.import. The earliest matching request can help determine when an intrusion began and identify a safe backup point for restoration. 

Indicators of Compromise and Response Steps 

The JCE security update guidance warns administrators to investigate any unexpected PHP files located in images, media, or tmp directories. Files containing “php” in their names, such as foo.php.xml, should also be treated as suspicious.  If compromise is suspected, administrators should preserve suspicious files for forensic analysis, install JCE 2.9.99.6 or later, remove rogue profiles, delete malicious uploads, change administrator, database, hosting, and FTP passwords, and perform a full server-side malware scan.  The advisory stresses that updating alone does not remove malicious files already planted on a compromised system. Closing the vulnerability prevents reinfection but does not clean an existing breach. 

Legacy Sites and LiteSpeed Risks 

For older deployments unable to meet the requirements of JCE 2.9.99.6—PHP 7.4 and 3.10 or later—a free patch is available for JCE 2.7.x, 2.8.x, and 2.9.x branches. However, the patch only fixes CVE-2026-48907 and does not include the additional hardening found in the latest release.  Separately, attackers are also targeting a vulnerability in the LiteSpeed cPanel plugin. The flaw can be exploited for privilege escalation, potentially allowing attackers to obtain root-level access on shared hosting servers. Together, the Joomla and LiteSpeed cPanel plugin vulnerabilities highlight the growing threat posed by actively exploited web hosting and content management system weaknesses. 

Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests

cyberattacks on Tempo

A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed denial-of-service (DDoS) assault designed to overwhelm the company's infrastructure and hinder public access to its journalism. According to Tempo's technology team, the attacks generated an extraordinary volume of fake internet traffic, placing significant pressure on the organization's servers and temporarily affecting the availability of the website for readers in Indonesia and elsewhere.

24.9 Million Requests Recorded During Cyberattacks on Tempo 

Tempo Digital Chief Technology Officer Heru Tjatur Tjahja said the cyberattacks on Tempo had reached an unprecedented scale. By Monday, June 8, 2026, the company's monitoring systems had logged a total of 24.9 million requests aimed at its servers.  “The total attacks flooding our website as of June 8 reached 24.9 million requests,” Tjahja said on Monday, June 8, 2026.  The Tempo cyberattack relied on bot-generated traffic, a common tactic used in DDoS incidents. Such attacks typically involve networks of compromised devices sending enormous numbers of requests simultaneously, overwhelming targeted systems and making websites difficult or impossible to access.  Tjahja explained that preliminary findings indicated the attacks occurred intermittently but intensified dramatically during certain periods. 

Largest Wave Hit During Evening Hours 

The investigation into the cyberattacks on Tempo revealed a pattern in the timing of the attacks. According to Tjahja, the attackers frequently launched their operations during evening and early morning hours, when activity surged sharply.  One of the most significant attack waves occurred between 8:30 p.m. and midnight. During that period alone, Tempo recorded 12.97 million attack requests within a span of just two hours.  “For example, the first major wave consisted of 12.97 million attacks in only two hours. From 8:30 p.m. until midnight, the attackers carried out a digital assault,” he said.  The intensity of the attack highlighted the scale of resources being used against the Indonesian media organization. 

Attack Traffic Traced Beyond Indonesia 

Early analysis conducted by Tempo's technology team suggested that the sources of the malicious traffic extended well beyond Indonesia's borders.  While the exact identities of those responsible remain unclear, investigators traced attack activity to multiple countries. According to Tempo, traffic associated with the cyberattacks on Tempo originated from Colombia, the United States, the Philippines, Bangladesh, Mexico, and Indonesia.  The international nature of the attack traffic reflects the complexity of modern DDoS operations, which often use distributed networks of compromised devices globally to conceal the origin of an attack. 

Possible Link to Earlier CMS Breach Attempt 

Tjahja believes the Tempo cyberattack may be connected to an earlier security incident that targeted the organization's content management system (CMS) at the end of May 2026.  During that earlier intrusion attempt, attackers managed to unpublish several articles that had already been published on the website. According to Tjahja, the content affected by the breach involved corruption-related reporting.  However, the CMS architecture limited the level of access available to unauthorized users. As a result, the attackers were unable to permanently remove the articles and could only temporarily unpublish them.  According to Tjahja, the sequence of events suggests a possible connection between the two incidents.  “It appears that those behind the attacks were unhappy and then proceeded with the DDoS attack,” he said. 

CERT-In Warns of AI-Driven Cyber Threat Surge, MSMEs at Highest Risk

CERT-In advisory

India’s cybersecurity watchdog, CERT-In, has raised concerns of the nature of modern cyber threats, particularly those driven by artificial intelligence. In its latest advisory, the cybersecurity watchdog has highlighted how frontier AI technologies are reshaping the threat landscape, making cyberattacks faster, more scalable, and far more accessible, even to less skilled attackers. The warning places a special emphasis on Micro, Small, and Medium Enterprises (MSMEs), which are becoming prime targets due to their comparatively weaker security frameworks.  According to CERT-In, the rise of AI-powered tools marks a significant turning point in how cyberattacks are conceived and executed. What once required advanced technical expertise and hours of manual effort can now be accomplished in a fraction of the time through automation. The cybersecurity watchdog noted that modern AI systems are capable of independently scanning large volumes of source code, identifying deeply embedded vulnerabilities, and even launching coordinated, multi-stage cyberattacks. This shift has introduced what the agency describes as an era of “automation and scale” in cybercrime. 

From Manual Intrusion to AI-led Cyberattacks 

CERT-In’s advisory explains that traditional hacking methods involve painstaking manual processes and highly specialized knowledge. Attackers would typically spend hours, if not days, probing systems for weaknesses before exploiting them. However, AI has fundamentally altered this dynamic. Frontier AI systems can now detect “zero-day” vulnerabilities, previously unknown flaws, in mere seconds.  More concerning is the ability of these systems to “chain” multiple vulnerabilities together. By linking weaknesses across different applications or platforms, attackers can orchestrate comprehensive attacks that compromise entire networks from end to end. This level of sophistication was once limited to highly skilled professionals or state-sponsored actors. Today, however, the cybersecurity watchdog warns that such capabilities are accessible, effectively lowering the barrier to entry for cybercriminals. 

MSMEs Under Heightened Risk 

The advisory stresses that MSMEs are particularly vulnerable in this new threat environment. Unlike large enterprises, MSMEs often operate with limited budgets and lack dedicated cybersecurity teams or advanced monitoring systems. This makes it easier for attackers to leverage AI-driven tools.  CERT-In has pointed out that because AI simplifies and automates many aspects of cyberattacks, even individuals with minimal technical expertise can now carry out highly precise and damaging operations. As a result, MSMEs face a disproportionate level of risk. A successful breach could lead to severe consequences, including data theft, operational disruptions, or ransomware attacks that many smaller businesses are ill-prepared to manage.  The cybersecurity watchdog has cautioned that without immediate and meaningful improvements in their security posture, MSMEs could suffer significant financial and reputational damage. The growing accessibility of AI-powered attack tools means that the threat is no longer hypothetical but immediate and widespread. 

Recommended Security Measures 

In response to these emerging risks, CERT-In has outlined several critical steps that organizations, especially MSMEs, should take to strengthen their defenses. One of the primary recommendations is the deployment of robust threat detection systems combined with continuous network monitoring. These measures can help identify unusual activity early and prevent attacks from escalating.  Another key focus area highlighted by the cybersecurity watchdog is patch management. As AI tools enable attackers to quickly identify and exploit unpatched vulnerabilities, delays in updating software can create significant security gaps. CERT-In stresses that the timely application of patches is essential to minimizing exposure.  Additionally, maintaining comprehensive system logs is strongly advised. Detailed logs play a crucial role in forensic investigations, helping organizations understand how an attack occurred and what vulnerabilities were exploited. This information is vital for preventing future incidents and strengthening overall cybersecurity resilience. 

Hacker Active Well Beyond Context.ai Compromise, Says Vercel CEO

Vercel, Vercel Breach, APIs, npm Packages

Vercel CEO Guillermo Rauch, in an update today said that after scanning through petabytes of logs of the company's networks and APIs, his security team concluded that the threat actor behind the Vercel breach had been active well beyond Context.ai's compromise. Rauch said that the "threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers. Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables." Researchers at Hudson Rock had earlier confirmed that the attack actually initiated in February itself when a Context.ai employee’s computer was infected with Lumma Stealer malware after they searched for Roblox game exploits, a common vector for infostealer deployments. What the latest findings mean is that there could be a wider net of victims that the threat actor may have phished for and what we know is just the tip of the iceberg - or not.
Also read: Vercel Incident Linked to AI Tool Hack, Internal Access Gained

Vercel Finds Customers Breached in Separate Malware, Social Engineering Attacks

In an official update, the company also stated that initially it identified a limited subset of customers whose non-sensitive environment variables stored on Vercel were compromised. However, a deeper assessment of the their network, as well as environment variable read events in the company's logs uncovered two additional findings.

"First, we have identified a small number of additional accounts that were compromised as part of this incident," the company noted.

But the main concern is the next finding: "Second, we have uncovered a small number of customer accounts with evidence of prior compromise that is independent of and predates this incident, potentially as a result of social engineering, malware, or other methods." 

The company did not disclose who were the attackers, what was the motive, or the impact on customers, and is yet to respond to these queries from The Cyber Express. It only stated: "In both cases, we have notified the affected customers."

Meanwhile, Rauch said, Vercel had notified other suspected victims and encouraged them to rotate credentials and adopt best practices.

No Compromise of npm Packages

The news of npm packages being compromised has surfaced a lot in recent times. To cover that front, Vercel's security team in collaboration with GitHub, Microsoft, npm, and Socket, confirmed that no npm packages published by Vercel had been compromised. "There is no evidence of tampering, and we believe the supply chain remains safe," the company said.

EU Rolls Out NCAF 2.0 Framework to Boost National Cybersecurity Readiness

NCAF 2.0

The European Union Agency for Cybersecurity (ENISA) has released the updated version of the National Capabilities Assessment Framework (NCAF 2.0), providing EU Member States with a structured, adaptable methodology to evaluate and enhance their national cybersecurity capabilities. This revised framework is designed to support national authorities in assessing the maturity of their National Cybersecurity Strategies (NCSSs), ultimately strengthening the EU's collective cybersecurity posture.  The National Capabilities Assessment Framework (NCAF) 2.0 offers EU Member States a comprehensive tool for evaluating their cybersecurity preparedness and progress. Through this framework, countries can assess the maturity of their National Cybersecurity Strategies (NCSSs), identify strengths and weaknesses, and make targeted improvements. NCAF 2.0 is built around a flexible, evidence-based approach that provides valuable insights into both strategic and operational cybersecurity initiatives. 

How is NCAF 2.0 Different?

NCAF 2.0 is a refined maturity model that helps countries assess their cybersecurity efforts across various stages of development. This model evaluates both the process and outcomes of national cybersecurity strategies, offering Member States an ongoing opportunity to track progress and align with EU cybersecurity standards.  NCAF 2.0 builds upon the success of its predecessor by introducing several key updates aimed at strengthening the cybersecurity capabilities of EU Member States. These updates include: 
  • New descriptions of maturity levels reflect the dynamic nature of cybersecurity challenges, enabling more accurate assessments of national capabilities.  
  • The framework includes updated goals that address emerging cybersecurity threats and align with evolving EU policies, such as the NIS2 Directive, which came into force in January 2023.  
  • A set of comprehensive questions designed to assess the maturity of various cybersecurity areas, including governance, risk management, and incident response 
NCAF 2.0 is crucial in supporting the EU’s broader cybersecurity agenda, especially in helping Member States comply with regulatory frameworks such as the NIS2 Directive. This directive requires countries to establish robust NCSSs, setting clear goals for addressing current and future cybersecurity risks. 

Who Can Benefit from NCAF 2.0? 

The primary beneficiaries of NCAF 2.0 are policymakers, cybersecurity experts, and government officials responsible for shaping and implementing NCSSs. The framework offers a valuable self-assessment tool for evaluating a country’s progress and improving national cybersecurity strategies.   By providing a structured methodology for assessing cybersecurity efforts, NCAF 2.0 enables national authorities to make data-driven decisions that enhance their overall security posture.  Additionally, the framework promotes mutual learning and best practice sharing among EU Member States, fostering collaboration on key cybersecurity issues. By aligning national strategies with EU-wide cybersecurity goals, NCAF 2.0 contributes to strengthening the EU’s collective defense against cyber threats. 

The EU Cybersecurity Landscape 

The release of NCAF 2.0 marks a significant step forward in enhancing EU cybersecurity. For over a decade, ENISA has supported EU Member States in developing and refining their national cybersecurity strategies. NCAF 2.0 builds this legacy, offering an updated tool for assessing progress and adapting to emerging threats.  As the EU cybersecurity landscape evolves, NCAF 2.0 ensures that national cybersecurity strategies remain relevant and effective. By continuously updating the framework in response to new developments in technology and legislation, ENISA helps Member States stay ahead of cyber threats and maintain a good defense against modern cyber risks.

Challenges in Assessing National Cybersecurity Strategies 

Developing and evaluating effective National Cybersecurity Strategies (NCSSs) is a complex task that presents numerous challenges for EU Member States. Some of the most common difficulties include: 
  • Coordination Across Stakeholders: Ensuring effective collaboration between government agencies, businesses, and cybersecurity experts can be difficult, especially in countries with fragmented governance structures.  
  • Adapting to Evolving Threats: As cyber threats continue to evolve, national strategies must be flexible and adaptive. Member States must continuously update their plans to address emerging risks.  
  • Measuring Effectiveness: It is not enough to track the implementation of cybersecurity measures; it is also important to assess the long-term impact and success of these efforts. This requires a comprehensive evaluation of outcomes, not just outputs.  
NCAF 2.0 helps address these challenges by providing a clear, structured framework for evaluating cybersecurity capabilities. The maturity model allows countries to track progress over time, identify gaps, and ensure their strategies are evolving to meet new challenges. 

The Benefits of Using NCAF 2.0 

NCAF 2.0 offers several advantages for EU Member States: 
  1. Self-Assessment and Continuous Improvement: The framework provides a voluntary tool for Member States to evaluate their cybersecurity maturity and track progress over time. By identifying gaps and areas for improvement, countries can strengthen their cybersecurity capabilities.  
  2. Alignment with EU Regulations: NCAF 2.0 is aligned with key EU legislation, including the NIS2 Directive and the Cyber Resilience Act. This ensures that national strategies comply with EU-wide cybersecurity standards.  
  3. Support for Peer Reviews: NCAF 2.0 can be used as part of the voluntary peer review process established under NIS2. This allows Member States to collaborate, share best practices, and enhance their collective cybersecurity efforts.  
Through these benefits, NCAF 2.0 plays a crucial role in strengthening the cybersecurity posture of EU Member States and enhancing their resilience to cyber threats. 

Maturity Levels in NCAF 

The maturity model in NCAF 2.0 is structured around five levels, each representing a stage of development in national cybersecurity capabilities: 
  • Level 1: Foundation: Countries at this level have begun their cybersecurity journey but lack a comprehensive, coordinated approach.  
  • Level 2: Developing: At this stage, national strategies are in place, but implementation is still in the early stages.  
  • Level 3: Established: Member States at this level have a well-established cybersecurity framework with clear governance structures and resource allocation. 
  • Level 4: Mature: A mature cybersecurity strategy is aligned across all sectors, with ongoing evaluations and adjustments based on performance data 
  • Level 5: Advanced: Countries at this level demonstrate an adaptive, forward-looking cybersecurity strategy that is responsive to emerging threats and technological advancements.  
While reaching Level 5 may be an idealized goal for many countries, the model provides a clear roadmap for progress, helping Member States identify where they currently stand and where they should aim to be. 

March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets

2026 threat landscape

The 2026 threat landscape continued to intensify in March, with ransomware attacks, expanding data breach activity, and a growing underground market for compromised access shaping the global cybersecurity environment. According to analysis from CRIL (Cyble Research & Intelligence Labs), organizations worldwide faced a highly active and coordinated threat ecosystem throughout the month.  CRIL’s findings point to a cybercriminal landscape driven by financial extortion, credential theft, and operational disruption. Attackers consistently targeted industries that rely heavily on uptime or store large volumes of sensitive data, reinforcing the urgency for stronger defensive strategies. 

Ransomware Attacks Dominate the 2026 Threat Landscape 

Top five ransomware actors (Data Source: Cyble Blaze AI) One of the most defining aspects of the March 2026 threat landscape was the scale of ransomware attacks. CRIL recorded 702 ransomware incidents globally, underscoring the continued dominance of ransomware as a primary attack vector.  Among the most active threat groups were Qilin, Akira, The Gentlemen, Dragonforce, and INC Ransom. Collectively, these actors were responsible for over 56% of all observed ransomware activity, reflecting their operational maturity and extensive affiliate networks.  Industries most affected by ransomware attacks included: 
  • Construction  
  • Professional Services  
  • Manufacturing  
  • Healthcare  
  • Energy & Utilities  
Attackers frequently employed double-extortion tactics, combining data theft with system disruption to increase pressure on victims. Geographically, the United States remained the primary target, influenced in part by ongoing geopolitical tensions, including those involving Iran. 

Rise of Access Brokers in the CRIL Threat Analysis 

Another notable trend in the 2026 threat landscape, as identified by CRIL, was the continued growth of the compromised access market. During March, 20 separate incidents involving the sale of unauthorized network access were tracked across cybercrime forums.  The most targeted sectors for access sales were: 
  • Professional Services (25%)  
  • Retail (20%)  
  • IT & ITES  
  • Manufacturing  
A small group of threat actors, vexin, holyduxy, and algoyim, dominated this space, accounting for more than 55% of observed listings. These access brokers play a critical upstream role, enabling ransomware attacks, espionage campaigns, and financial fraud operations. 

Data Breaches and Leak Markets Stay Active 

CRIL also documented 54 significant data breach and leak incidents in March, further highlighting the scale of data exposure risks in the current 2026 threat landscape.  The most targeted sectors for data breaches included: 
  • Government & Law Enforcement  
  • Retail  
  • Technology  
Several incidents stood out: 
  • A threat actor known as “nightly” claimed to have stolen over 5TB of data from Hospitality Holdings, including biometric data, CCTV footage, and financial records. 
  • Another actor, XP95, advertised 3.8TB of allegedly stolen South African government data for sale.  
  • A separate breach exposed more than 95,000 travel-related records, including passport and payment information.  

Exploitation of Critical Vulnerabilities Accelerates 

The 2026 threat landscape also saw increased exploitation of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.  Key vulnerabilities targeted included: 
  • CVE-2026-20131 (Cisco Secure Firewall Management Center)  
  • CVE-2025-53521 (F5 BIG-IP APM)  
  • CVE-2026-20963 (Microsoft SharePoint Server)  
  • CVE-2026-33017 (Langflow AI)  
  • CVE-2021-22681 (Rockwell Automation ICS 
CRIL observed attackers exploiting both newly disclosed zero-day vulnerabilities and older, unpatched flaws. This trend reflects persistent gaps in patch management and exposure mitigation across organizations. 

Emerging Threat Developments in March 2026 

Beyond ransomware attacks and data breaches, CRIL identified several strategic developments shaping the 2026 threat landscape: 
  • AI-Driven Attacks: Threat actors reportedly leveraged an open-source framework called CyberStrikeAI to target Fortinet FortiGate devices across 55 countries, compromising more than 600 systems. 
  • Supply Chain RisksNorth Korean-linked actors were associated with 26 malicious npm packages distributing remote access trojans (RATs) via infrastructure hosted on Pastebin and Vercel. 
  • Geopolitical Cyber Activity: Iran-linked cyber operations are expected to increase, with potential ransomware attacks and hacktivist campaigns targeting organizations in the Middle East. 

Dark Web Article Contest Offers $10,000 for Exploit Writing on TierOne Forum

dark web article contest

In an unusual development within the underground cyber world, a dark web article contest has been announced on a well-known dark web forum, TierOne forum. The initiative is backed by a $10,000 prize pool. The contest places a spotlight on technical writing centered around vulnerability exploitation, offering insight into how knowledge is shared and rewarded in these spaces.  Traditionally, dark web forums have been linked to illicit activities such as trading stolen data, coordinating ransomware attacks, and distributing malware. However, this contest introduces a different dynamic, one that mirrors legitimate cybersecurity ecosystems, where researchers document findings and share exploit techniques.  

The Dark Web Article Contest Overview and Prize Structure 

According to an official announcement shared by an administrator on the forum, the post states: “Всем привет! Мы рады сообщить T1 erone [КОНКУРС СТАТЕЙ #1 - 2026]. Победители конкурса получают призы: 1 место 5.000$, 2 место - 3.000$, 3 место - 2.000$, [Призовой фонд 10.000$]. Прием статей начинается 13.04.2026 и заканчивается 14.05.2026.”   The announcement indicates that the dark web article contest will run from April 13, 2026, to May 14, 2026, with prize amounts set at $5,000 for first place, $3,000 for second place, and $2,000 for third place, making up a total prize pool of $10,000, reportedly sponsored by the ransomware group cry0. 

Topics Focused on Vulnerability Exploitation 

The contest invites submissions covering a wide range of advanced topics related to vulnerability exploitation with real-world applicability. These include: 
  • Remote Code Execution (RCE) through deserialization flaws in React and Node.js frameworks. 
  • Command injection attacks in APIs and backend systems. 
  • Insecure Direct Object Reference (IDOR) vulnerabilities in SaaS platforms. 
  • Server-Side Template Injection (SSTI) in modern templating engines. 
  • Exploitation of insecure deserialization in PHP and Java. 
  • Client-side RCE via Markdown or Office file rendering. 
  • Firmware attacks targeting routers and cameras. 
  • Privilege escalation techniques in RouterOS and similar systems. 
  • Exploitation methods for products from Cisco, MikroTik, Oracle, and Ubiquiti. 
  • Zero-day discovery in browser components like WebGPU and Blink. 
  • AI-assisted vulnerability discovery and reverse engineering. 
  • Techniques for bypassing AV and EDR security systems. 
  • Exploitation of Remote Procedure Call (RPC) mechanisms. 
For context, vulnerabilities such as RCE, IDOR, and SSTI allow attackers to execute arbitrary code or access restricted data, while firmware attacks enable persistent control over hardware devices. Similarly, AV/EDR bypass techniques are designed to evade detection by modern security solutions. 

Participation Rules and Requirements 

The TierOne forum has outlined strict guidelines for participants. Articles must be published within the forum’s designated section and include a specific prefix to qualify: 
  • Submissions must be posted under the Articles section with the prefix “[Contest]”. 
  • A link to the article must be shared in the contest thread with a participation note. 
  • All users are eligible, regardless of registration date or activity level. 
  • The use of multiple accounts is strictly prohibited. 
In addition, the contest enforces content quality standards: 
  • Articles must be original and based on the author’s own experience. 
  • Copy-pasted or reposted material is not allowed. 
  • Submissions should comprehensively cover the chosen topic, including tools, techniques, and methodologies. 
  • Minimum length requirement is at least one A4 page. 
  • Excessive filler content is discouraged. 
  • Including video demonstrations may improve chances of winning. 

A Glimpse into Dark Web Knowledge Sharing 

While the existence of such a contest may seem surprising, it notes a bigger trend within dark web forums. Beyond illegal marketplaces and data trading, these platforms also function as hubs for technical exchange, where members document and refine vulnerability exploitation techniques. In many ways, the structure resembles legitimate bug bounty programs and penetration testing workflows, where cybersecurity professionals publish detailed reports on discovered flaws. The key difference lies in the intent and environment in which this knowledge is applied. It is important to note that this article does not endorse participation in such activities. Instead, it aims to shed light on how these underground ecosystems operate. The TierOne forum contest highlights that even within the dark web, there are organized efforts to produce structured, experience-based technical content, albeit in a context that raises ethical and legal concerns.
❌