top of page

Weekly INK
Each week we compile an advisory on the latest threats, trends and newsworthy topics from the cyber security industry affecting small and medium enterprises. Join our subscribers below and help us prevent cybersecurity breaches.

Issue #191 - March 23, 2026
FBI Links Signal Phishing Attacks to Russian Intelligence Services Source: BleepingComputer The FBI issued a public service announcement directly attributing widespread campaigns that hijack Signal and WhatsApp accounts to Russian intelligence-linked threat actors, making it the first formal US government attribution of these attacks. Rather than breaking end-to-end encryption, the campaign exploits legitimate device-linking features to silently add attacker-controlled device

Weekly INK
Mar 233 min read
Issue #190 - March 16, 2026
FBI Seizes Handala Data Leak Site After Stryker Cyberattack Source: BleepingComputer The FBI has seized two websites operated by the Handala hacktivist group following the group's destructive cyberattack on medical technology giant Stryker, which remotely wiped approximately 80,000 devices. Both the group's clearnet domains now display a federal seizure notice issued under a warrant from the US District Court for the District of Maryland. The seizure follows confirmation that

Weekly INK
Mar 163 min read
Issue #189 - March 9, 2026
Medtech giant Stryker offline after Iran-linked wiper malware attack Source: BleepingComputer Iranian-backed hacktivist group Handala claimed responsibility for a devastating wiper malware attack against medical technology giant Stryker, reportedly wiping over 200,000 systems, servers, and mobile devices across offices in 79 countries. The group also claims to have stolen 50 terabytes of data before triggering the destructive wipe. Stryker confirmed the incident in an SEC fil

Weekly INK
Mar 92 min read
Issue #188 - March 2, 2026
Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets Source: The Hacker News Attackers are abusing legitimate OAuth redirection behavior to route victims from seemingly trusted identity-provider URLs to attacker-controlled pages. Campaigns target public-sector organizations and use links that trigger malware delivery via ZIP payloads, PowerShell execution, and DLL sideloading. Key mitigations include tightening user consent and reviewing OAuth app permi

Weekly INK
Mar 22 min read
Issue #187 - February 23, 2026
Attackers Now Need Just 29 Minutes to Own a Network Source: Dark Reading Attack chains are compressing. This piece highlights how modern intrusions move from initial access to full environment control in under an hour by abusing stolen credentials, remote tools, and weak identity controls. For SMBs, the takeaway is clear: focus on MFA, credential hygiene, monitoring, and fast containment playbooks. Link to article CISA: BeyondTrust RCE flaw now exploited in ransomware attacks

Weekly INK
Feb 232 min read
Issue #186 - February 16, 2026
Supply Chain Attack Embeds Malware in Android Devices Source: Dark Reading Researchers found malware embedded at the Android firmware level through a supply chain compromise. The threat can copy itself into apps and then pull down additional payloads for ad fraud, browser hijacking, and other remote actions. The key risk is that users may receive devices or updates already compromised. Link to article Flaws in popular VSCode extensions expose developers to attacks Source: Ble

Weekly INK
Feb 162 min read
Issue #185 - February 9, 2026
Shai-hulud: The Hidden Costs of Supply Chain Attacks Source: Dark Reading A new breed of self propagating supply chain malware in open source ecosystems can rapidly alter thousands of software packages and create downstream damage well beyond the initial victim. The article explains how these campaigns spread, why detection is difficult, and what organizations must do to reduce software dependency risk. Link to article CISA warns of SmarterMail RCE flaw used in ransomware att

Weekly INK
Feb 92 min read
Issue #184 - February 2, 2026
Harvard, UPenn Data Leaked in ShinyHunters Shakedown Source: Data Breach Today Leaked Financial and Admissions Data Includes Contact Details for 'Top Donors’. Cyber extortion group ShinyHunters claimed responsibility Wednesday for late 2025 attacks against Harvard University and the University of Pennsylvania, publishing on a darkweb leak site what they claimed were more than 2 million records stolen from the two Ivy League schools. Link to article Russia’s APT28 Rapidly Weap

Weekly INK
Feb 22 min read
Issue #183 - January 26, 2026
Social Engineering Hackers Target Okta Single Sign On Source: Data Breach Today Single sign-on customers of identity provider Okta should be on alert against attackers seeking to gain access to their corporate network, steal data and hold it to ransom, security experts warn. A surge in social engineering attacks has targeted users of Okta's SSO tools, leading the company to directly warn customers last week about this campaign. Link to article Chrome, Edge Extensions Caught S

Weekly INK
Jan 262 min read
Help us Prevent Breaches.
Subscribe to our Weekly INK newsletter. We will never share your information.
bottom of page

