Cybersecurity Hub
This is a cybersecurity hub view of threat activity. For the full Threat Intelligence product area — including actor databases, campaign tracking, IOC feeds and monitoring tools — visit Threat Intelligence.
Active threat signals
VoidLock Collective claims new healthcare victims
The ransomware group posted redacted claims against two mock healthcare organizations. Defensive teams should review VPN exposure and phishing controls.
Phantom Crane infrastructure shift detected
Analysts observed Phantom Crane moving C2 infrastructure to new cloud regions. The shift correlates with expanded targeting of telecom providers.
NeonStealer campaign targeting e-commerce payment flows
Phishing kits deploying NeonStealer have increased in volume. The stealer harvests browser credentials and payment data from e-commerce sessions.
SilkGate Broker advertising VPN access to healthcare networks
Mock initial access broker listing claims VPN access to three healthcare organizations. All details are redacted and fictional.
Threat actor highlights
Threat coverage will appear here as articles are published.
Related product areas