Scattered Spider Targets Airlines: How a Notorious Hacking Group Is Exploiting Aviation During Peak Travel Season
|

Scattered Spider Targets Airlines: How a Notorious Hacking Group Is Exploiting Aviation During Peak Travel Season

Summer travel season is supposed to be a time of excitement—adventures, family reunions, and business trips that cross continents. But in 2025, as travelers packed their bags, a chilling warning rippled through the aviation industry: the infamous Scattered Spider hacking group had set its sights on airlines. Major carriers like Hawaiian Airlines, WestJet, and now…

Scattered Spider Hacker Arrests: Why Security Teams Can’t Let Their Guard Down Yet
|

Scattered Spider Hacker Arrests: Why Security Teams Can’t Let Their Guard Down Yet

What happens when one of the world’s most notorious hacking groups suddenly goes quiet? Relief, maybe—a little—but also anxiety. Because when cybercriminals disappear from the headlines, that rarely means the threat is gone. Instead, it signals a critical moment for every organization: an opportunity to learn, adapt, and outpace the next wave of attacks. If…

Hackers Are Weaponizing PDFs to Impersonate Microsoft, DocuSign, and More: How Callback Phishing Campaigns Are Evolving
|

Hackers Are Weaponizing PDFs to Impersonate Microsoft, DocuSign, and More: How Callback Phishing Campaigns Are Evolving

Imagine opening your inbox and spotting an urgent email from Microsoft or DocuSign. You trust these brands, so you open the attached PDF and—before you know it—you’re on the phone with “support,” unknowingly handing over sensitive information to a scammer. Sound far-fetched? Unfortunately, this exact scenario is playing out in inboxes around the globe right…

Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign
|

Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

In a rapidly evolving digital landscape, cybersecurity threats continue to grow in complexity and sophistication. A recent revelation by Google’s Threat Intelligence Group (GTIG) and the Citizen Lab has shed light on a new threat actor campaign linked to the notorious Russian state-sponsored hacking group APT29. This campaign exploits Google’s application-specific passwords (ASPs) to bypass…