Inside wp2shell: How Two WordPress Core Bugs Became a Critical RCE Chain

Blog Analyzing CVE-2026-63030 and CVE-2026-60137 When WordPress quietly pushed emergency security updates on July 17, 2026, it wasn’t addressing just another isolated vulnerability. Instead, the patches closed two separate flaws that, when chained together, created something far more serious than either issue on its own. Researchers quickly began referring to the attack chain as wp2shell a […]
The Middle East’s Cyber Threat Picture in 2026: What 170 Incidents Tell Us

Blog If you only looked at the headline number, 2026 in the Middle East would seem like a fairly typical ransomware year. 170 ransomware and extortion incidents across 17 countries, most of them hitting manufacturing, healthcare, finance, and government. Criminals chasing money, in other words. Business as usual. But spend some time inside the data […]
How a Data-Theft Crew Became a Business

Blog There’s a particular kind of breach story that’s become almost routine at this point. A company sends out an email, apologizes, offers a year of credit monitoring, and life goes on. But every so often, the same name keeps showing up at the bottom of these stories, over and over, across companies that have […]
ClickFix: How a Fake Error Turns Users Into Their Own Attackers

Blog ClickFix: How a Fake Error Turns Users Into Their Own Attackers ClickFix is a social engineering technique that has spread rapidly over the last couple of years. There is no attachment to open and no obvious file for the victim to download. The victim ends up doing the attacker’s work, often without realizing anything […]
The Doors Were Already Open May 2026 Ransomware in Review

Blog Every month the ransomware reports look roughly the same, and every month there’s something underneath the averages worth pausing on. May 2026 is no exception. ThreatMon counted 747 victims across the month, nine groups did the heavy lifting in the ten headline cases, and depending on how you read one odd statistic at the […]
What Was a 45-GPU Cracking Farm Built For?

Blog Most credential leaks are messy. Someone dumps a pile of raw data, half of it stale, and walks away. What ThreatMon’s research team pulled apart in June 2026 was the opposite: a clean, sorted, validated inventory of network access, put together by an operator who clearly knew what they were doing right up until […]
Why Would an Adversary Collect 74,000 FortiGate

Blog ThreatMon Analysis of a Global FortiGate Access Collection Operation Executive Summary In June 2026, security researcher Volodymyr “Bob” Diachenko disclosed the existence of a large dataset associated with internet-facing FortiGate deployments worldwide. The disclosure immediately attracted attention due to the scale of the exposed information and the number of organizations represented within the records. […]
The Cyber War Nobody’s Talking About at the FIFA World Cup

The pipelines keep running. The rigs keep drilling. But somewhere in the background, threat actors are quietly doing their own kind of work stealing credentials, probing control systems, and waiting for the right moment to pull the trigger on a ransomware payload. The 2026 threat intelligence picture for the oil and gas sector is not pretty, and if you’re involved in energy security, it deserves your full attention.
Oil & Gas Under Siege: What the 2026 Cyber Threat Landscape Actually Looks Like

The pipelines keep running. The rigs keep drilling. But somewhere in the background, threat actors are quietly doing their own kind of work stealing credentials, probing control systems, and waiting for the right moment to pull the trigger on a ransomware payload. The 2026 threat intelligence picture for the oil and gas sector is not pretty, and if you’re involved in energy security, it deserves your full attention.
GitHub’s Source Code Is for Sale And They’ve Confirmed It

Blog GitHub’s Source Code Is for Sale And They’ve Confirmed It On May 19, 2026, a threat actor going by the handle TeamPCP posted a sale listing on the Breached cybercrime forum offering roughly 4,000 private GitHub repositories including the company’s core Rails application for a starting price of $50,000. By the time researchers caught […]