PROBABLYPWNED
Home/Threat Intel

Threat Intel

155 articles

FBI Warns Kali365 PhaaS Steals Microsoft 365 Tokens at Scale
Threat Intelligence4 min read

FBI Warns Kali365 PhaaS Steals Microsoft 365 Tokens at Scale

New phishing-as-a-service platform bypasses MFA via OAuth device code flow. FBI PSA details how Kali365's AI-generated lures and $250/month pricing are enabling widespread credential theft.

Alex KowalskiMay 24, 2026
DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause
Threat Intelligence4 min read

DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause

Verizon's 2026 Data Breach Investigations Report reveals vulnerability exploitation surpassed credential theft as the leading breach vector for the first time in 19 years. Only 26% of KEV flaws get patched.

Alex KowalskiMay 20, 2026
Microsoft Dismantles Fox Tempest Malware-Signing Operation
Threat Intelligence3 min read

Microsoft Dismantles Fox Tempest Malware-Signing Operation

Microsoft's Digital Crimes Unit seizes infrastructure behind Fox Tempest, a malware-signing service that helped Rhysida, Akira, and Qilin ransomware gangs disguise malicious code as legitimate software.

Alex KowalskiMay 20, 2026
Turla's Kazuar Backdoor Evolves Into Modular P2P Botnet
Threat Intelligence4 min read

Turla's Kazuar Backdoor Evolves Into Modular P2P Botnet

Microsoft exposes how Russia's FSB-linked Secret Blizzard transformed Kazuar from a monolithic backdoor into a three-module P2P botnet with advanced anti-detection capabilities.

Alex KowalskiMay 16, 2026
APT28's PRISMEX Malware Targets NATO Supply Chains
Threat Intelligence4 min read

APT28's PRISMEX Malware Targets NATO Supply Chains

Russian military hackers deployed PRISMEX steganography malware against Ukraine and NATO logistics networks, exploiting zero-days CVE-2026-21509 and CVE-2026-21513 weeks before patches.

Alex KowalskiApr 30, 2026
APT37 Exploits Facebook Friendships to Deploy RokRAT
Threat Intelligence4 min read

APT37 Exploits Facebook Friendships to Deploy RokRAT

North Korean threat actors are befriending targets on Facebook, building trust over weeks, then delivering RokRAT malware through trojanized PDF readers. Military and government officials targeted.

Alex KowalskiApr 29, 2026
Silk Typhoon Hacker Extradited to U.S. for COVID Vaccine Theft
Threat Intelligence4 min read

Silk Typhoon Hacker Extradited to U.S. for COVID Vaccine Theft

Chinese national Xu Zewei faces nine federal counts after extradition from Italy for alleged role in Silk Typhoon attacks stealing COVID-19 vaccine research from U.S. universities and research institutions.

Alex KowalskiApr 28, 2026
PhantomCore Exploits TrueConf Flaws to Breach Russian Networks
Threat Intelligence4 min read

PhantomCore Exploits TrueConf Flaws to Breach Russian Networks

Pro-Ukrainian hacktivist group PhantomCore chains three TrueConf vulnerabilities including CVSS 9.8 command injection to infiltrate Russian government and private organizations since September 2025.

Alex KowalskiApr 27, 2026
FBI: Cybercrime Losses Hit $20.9B in 2025, Up 26%
Threat Intelligence4 min read

FBI: Cybercrime Losses Hit $20.9B in 2025, Up 26%

FBI IC3 2025 report reveals record $20.9 billion in cybercrime losses. Investment fraud tops $8.6B, cryptocurrency scams reach $11.4B, and ransomware losses surge 259%.

Alex KowalskiApr 13, 2026
FBI, CISA Warn Iran Is Attacking US Water and Energy PLCs
Threat Intelligence5 min read

FBI, CISA Warn Iran Is Attacking US Water and Energy PLCs

Joint advisory AA26-097A details Iranian APT targeting Rockwell Allen-Bradley controllers across critical infrastructure. Attacks caused operational disruptions since March 2026.

Alex KowalskiApr 8, 2026
Iran-Linked Hackers Spray 300+ Israeli M365 Tenants
Threat Intelligence4 min read

Iran-Linked Hackers Spray 300+ Israeli M365 Tenants

Check Point tracks an Iran-nexus campaign targeting Microsoft 365 accounts across 300+ Israeli organizations and 25+ UAE entities. Attackers use Tor exit nodes and Israeli VPNs to evade detection.

Alex KowalskiApr 7, 2026
Storm-1175 Deploys Medusa Ransomware Within 24 Hours of Access
Threat Intelligence4 min read

Storm-1175 Deploys Medusa Ransomware Within 24 Hours of Access

Microsoft links China-based Storm-1175 to high-velocity Medusa ransomware attacks exploiting zero-day vulnerabilities. Healthcare, education, and finance sectors hit across Australia, UK, and US.

Alex KowalskiApr 7, 2026
Phantom Taurus Deploys Net-Star Backdoors Across Africa
Threat Intelligence3 min read

Phantom Taurus Deploys Net-Star Backdoors Across Africa

Unit 42 exposes Phantom Taurus, a Chinese APT targeting embassies and foreign ministries with fileless NET-STAR malware. The group resurfaces within hours after discovery.

Alex KowalskiApr 4, 2026