Microsoft ends Exchange 2016/2019 ESU support

Microsoft has announced it will terminate Extended Security Update support for Exchange Server 2016 and 2019 in October 2025, marking the final end of security patches for these widely deployed email server versions. This article has been indexed from CyberMaterial…

Google Launches Unified Cryptonym-Based Naming System for Threat Actors

Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate inconsistencies between legacy tracking conventions used across Google’s security teams. The initiative follows the integration…

Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials

A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that…

Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks

Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion.…