Archive of

RedFlick technique lets Star Blizzard push CosmicPulse

Star Blizzard, a Russian state-backed threat actor, has adopted a new way of installing malware on victims' machines. Microsoft researchers call the method "RedFlick" and say the group is using it to deliver its signature CosmicPulse backdoor.

The technique itself is not new to the security world. What is new is that Star Blizzard now uses it. It lets the group automate more of each attack and cut down on what the victim has to do before the infection runs.

According to Microsoft, Star Blizzard expanded its phishing operations in 2026 and made its malware delivery more efficient. The group has been active since 2017. It has a history of trying out new ways to deliver payloads, including ClickFix and WhatsApp, and it keeps building and deploying new malware families.

Read More


SOC AI survey: entry-level analyst jobs getting harder

Security operations staff say AI has made their work more satisfying, but many of them expect the first step into the profession to become harder to reach, according to a new Swimlane survey.

The company polled 500 people working in security operations centers (SOCs), the teams that monitor an organization's systems and respond to security alerts. All respondents work at organizations that already use AI.

Nearly nine in ten said AI has made their jobs more satisfying. About a quarter said it has held back their ability to build security skills. Those analysts were just as happy as the rest: 91% reported higher satisfaction, compared with 92% among those who said AI helped them learn.

Read More


US Cyber Command ordered to act on operator mental health

The Pentagon has given U.S. Cyber Command a list of mandatory, time-bound steps to protect the well-being of its personnel. The order follows reports earlier this summer of a cluster of suicide deaths at the command.

The instructions are in an unclassified memo dated August 31, written by Katherine Sutton, the Pentagon's assistant secretary for cyber policy and principal cyber adviser. It is addressed to Army Gen. Joshua Rudd, who leads Cyber Command. Recorded Future News obtained the document exclusively.

"As we look to expand and enhance the long-term resilience and readiness of our cyber forces, we must establish formal, proactive structures to support our operators," Sutton wrote.

Read More


MetaMask discloses ongoing infrastructure security incident

Cryptocurrency wallet provider MetaMask has disclosed a security incident affecting part of its infrastructure. The company says the incident is still ongoing but that there is "no immediate threat to MetaMask wallets."

MetaMask made the announcement on Thursday. It said it is handling the incident internally, with support from external partners and security advisors. It has not said which systems were involved or what the attackers may have reached.

MetaMask is a non-custodial crypto wallet developed by Consensys, a blockchain software company. Non-custodial means that users hold their own keys, not the provider. The wallet lets people store and manage assets on Ethereum and on other blockchains compatible with it.

Read More


Employment scam victims triple at banks in 21 countries

The number of people reporting employment scams to banks has more than tripled in a year, according to new figures from fraud-detection vendor BioCatch. The company compiled reports from more than 370 banks and other financial institutions in 21 countries that use its software.

Employment scam victims rose 258% over the past 12 months. That was the fastest growth of any scam type. Total reported scams across the same institutions rose 35%.

The data also shows where these scams happen. Nine out of 10 scam sessions now begin on a mobile device. For traditional unauthorized fraud, where a criminal operates the account without the owner's involvement, mobile accounts for 75% of cases.

Read More