SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers

ReliaQuest stories

Flux result a694726b 7de5 48ce 9beb 896d40041b0f

Former Black Basta affiliates target executives in Teams

2 days ago
#
uc
#
mfa
#
phishing
ReliaQuest says suspected former Black Basta operators are bombarding staff with emails and posing as IT support in Microsoft Teams to reach senior executives.
Flux result ce4cb7f0 cf50 4830 a4ec b982992c1a8f

Attackers turn trusted tools into cyber weapon

This month
#
malware
#
ransomware
#
advanced persistent threat protection
Attackers abuse trusted tools, remote support software and stolen SSO sessions to breach systems, ReliaQuest says.
Flux result 6459960a 8b91 4ad1 9ab4 cab1e0e740d2

DeepLoad malware steals credentials via ClickFix campaign

This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.
Soc san francisco night ai cyber map wall minimalist scene

Corelight unveils AI triage to speed transparent SOC ops

Last month
#
firewalls
#
network security
#
advanced persistent threat protection
Corelight launches Agentic Triage, an AI-driven workflow to speed SOC investigations while exposing every step for transparent review.
Moody corporate night office fileless ransomware cloud lock reflection

LeakNet adopts ClickFix lures & Deno fileless loader

Last month
#
storage
#
uc
#
firewalls
Ransomware group LeakNet adopts ClickFix lures and a Deno-based fileless loader to scale attacks and evade traditional endpoint defences.
Smartphone suspicious call laptop fake login deceptive subdomain scene

ShinyHunters pivots to subdomain phishing & vishing

Fri, 27th Feb 2026
#
saas
#
mfa
#
cloud security
ShinyHunters shifts to subdomain-brand phishing and vishing on mobiles, bypassing domain checks to hijack SSO logins and SaaS sessions.
Dark server room ai cyber attack red network path spreading

AI-driven cyber attacks now breach networks in minutes

Thu, 26th Feb 2026
#
malware
#
firewalls
#
ransomware
AI-fuelled hackers can now spread across corporate networks in as little as four minutes, outpacing human defenders by hours.
Moody windows server room red rack cracked email lock binary

SmarterMail flaw exploited in China-linked ransomware push

Thu, 12th Feb 2026
#
firewalls
#
vpns
#
ransomware
China-linked Warlock ransomware group exploits SmarterMail flaw for admin takeovers, chaining features to gain full Windows control.
Moody corporate office night remote access malware attack scene

Screensaver phishing installs remote access tools covertly

Thu, 5th Feb 2026
#
storage
#
firewalls
#
ransomware
Attackers are abusing Windows screensaver files in a spearphishing campaign to stealthily install remote access tools on business systems.
Cinematic night city cyberattack red windows shattering locks

Fewer ransomware gangs, but more victims in late 2025

Thu, 29th Jan 2026
#
ransomware
#
digital transformation
#
advanced persistent threat protection
Ransomware gangs shrank in number but hit more victims in late 2025, with leak-site postings soaring despite fewer active groups.
Office pc social network warning suspicious file download cursor

LinkedIn DMs abused to spread Python-based malware

Wed, 21st Jan 2026
#
firewalls
#
endpoint protection
#
devops
Attackers are abusing LinkedIn private messages to deliver Python-based malware via booby-trapped archives, ReliaQuest has warned.
Malaysia office worker laptop warning social engineering cert abuse

ReliaQuest warns of BaoLoader surge & trust attacks

Thu, 15th Jan 2026
#
firewalls
#
ransomware
#
network security
ReliaQuest warns BaoLoader and trust-based lures are surging, as attackers ditch zero-days for social engineering and valid certificates.
Dark server room ransomware attack shadowy hacker hands locks

Storm-0249 hijacks security tools to fuel ransomware

Wed, 7th Jan 2026
#
malware
#
firewalls
#
ransomware
Storm-0249 hijacks trusted security and Windows tools to stealthily broker high-value network access for ransomware operators.
Covert cyber espionage software download bug warning china russia

Chinese hackers fake Teams downloads in false flag ploy

Thu, 18th Dec 2025
#
malware
#
uc
#
martech
Chinese state-backed hackers mimic Microsoft Teams downloads in a false flag campaign to infect Chinese speakers and blame Russian actors.
Cloud security multiple padlocks open broken people keys digital network

Cloud breaches driven by identity failures & process flaws

Thu, 6th Nov 2025
#
malware
#
cloud security
#
phishing
ReliaQuest reveals identity compromises and process flaws, not zero-day exploits, drive most cloud breaches, with 99% of cloud identities still over-privileged.
Hooded figure at computer red warnings on digital infrastructure global map

Ransomware surge in Q3 2025 as new alliances target more sectors

Thu, 9th Oct 2025
#
ransomware
#
encryption
#
cybersecurity
Ransomware attacks hit a record in Q3 2025 as new alliances broaden targets to sectors like healthcare and critical infrastructure worldwide.
Realistic illustration masked figure dark hoodie laptop dimly lit room cyber attack

Breakout time drops as new attacker tactics surge in cyber threat space

Thu, 25th Sep 2025
#
firewalls
#
ransomware
#
network security
ReliaQuest reports cyber attackers cut breakout time to 18 minutes, with surging threats from Oyster malware and rising abuse of USB and IP-KVM devices.
Detailed graphic network servers clouds hazard symbols cyber threat detection

ReliaQuest unveils GreyMatter Transit for real-time threat detection

Thu, 18th Sep 2025
#
firewalls
#
data analytics
#
siem
ReliaQuest launches GreyMatter Transit, enabling real-time cybersecurity threat detection as data moves, cutting delays of traditional storage-based methods.
Email phishing attack computer screen hook envelope cybersecurity threats

Axios-driven phishing soars 241% as attackers bypass defences

Fri, 12th Sep 2025
#
mfa
#
phishing
#
advanced persistent threat protection
Phishing attacks using the Axios user agent surged 241% by August 2025, bypassing defences with Microsoft Direct Send to steal credentials at high rates.
Illustration hooded cybercriminals typing shadowy servers cyber attacks cloud

ShinyHunters & Scattered Spider escalate attacks on Salesforce

Thu, 14th Aug 2025
#
mfa
#
cloud security
#
martech
Cybercriminal groups ShinyHunters and Scattered Spider have escalated phishing attacks on Salesforce and major firms like Google, signalling possible collaboration.