BlueNoroff uses fake Zoom and Teams meetings to profile crypto wallets, hijack Telegram accounts, and deliver Windows and macOS malware.
AgentForger could let a phishing link forge, publish, and schedule a rogue ChatGPT Workspace Agent with access to connected apps.
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future’s Insikt Group is tracking the group under the moniker TAG-195.
TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling has been previously linked to TAG-127 as an operator and customer. The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands.
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026–12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.
As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail.
Cybersecurity company ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as other regions of the world, such as India and Saudi Arabia.
Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services.
The outage began at 10:44 AM ET on Thursday, July 23, and mostly affected customers accessing Microsoft 365 services through network infrastructure connected to Microsoft’s West US Azure region.
At 11:11 AM ET, Downdetector had recorded 2,403 outage reports, sharply above its normal baseline of 29. SharePoint accounted for 78% of the complaints, followed by Excel at 11% and the Microsoft 365 Admin Center at 6%.
One of the strongest findings involved a variant in CCNG1, which was associated with an earlier age of dementia onset. Carriers of the risk allele developed dementia roughly a decade earlier than those without it.
The same variant was also linked to higher levels of TDP-43, a protein implicated in several neurodegenerative diseases, and signs of accelerated brain aging on MRI scans.
The researchers also found that a variant in RHOJ was associated with biological markers of more severe Alzheimer’s disease. Individuals carrying the risk allele had higher levels of total tau and phosphorylated tau 181 in cerebrospinal fluid and a lower Aβ42/Aβ40 ratio—changes commonly associated with Alzheimer’s pathology.
Complete resection of skull base meningiomas (SBMs) is often limited by their proximity to critical neurovascular structures, potentially increasing the risk of postoperative progression. This study quantified long-term progression risk after SBM resection, identified predictors of progression, and developed a data-driven MRI surveillance protocol using Bayesian methods.
Patients undergoing SBM resection between 2002 and 2020 at two neurosurgical centres were analysed. Kaplan–Meier and Cox regression analyses were used to estimate intervention-free survival (IFS). Conditional probability modelling was used to derive an MRI surveillance schedule that maintained a ≤ 3% risk of progression requiring intervention, stratified by extent of resection.
A total of 358 SBMs were included. Median age at diagnosis was 57 years (IQR 18), and 76.0% of patients were female. WHO Grade 1 tumours accounted for 80.3% of cases and Grade 2 for 19.7%. Median follow-up was 97 months (IQR 64–128). Progression requiring re-intervention occurred in 14.1% of patients. Subtotal resection (STR) increased the risk of re-intervention (HR 2.62, 95% CI 1.30–5.30, p = 0.009), whereas higher comorbidity burden (HR 0.78, 95% CI 0.62–0.98, p = 0.038) and incidental presentation (HR 0.11, 95% CI 0.01–0.88, p = 0.038) were associated with lower risk. Conditional probability modelling demonstrated higher annual progression risk following STR, supporting more intensive imaging surveillance. Recommended MRI schedules were: gross total resection (GTR), scans at 3 months, 2, 5, 8, and 10 years; STR, scans at 3 months, 1 year, 18 months, annually from years 2–8, and at 10 years.