Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Vulnerability · Securityaffairs

What happened

Symantec tracks the group behind Warlock ransomware as Longlegs, also known as Storm-2603, and reports that it continues exploiting unpatched SharePoint flaws for initial access. In the past two months, Longlegs reportedly hit at least four organizations—a water utility, telecom provider, regional government body, and university—in Portuguese- or Spanish-speaking countries.

Why it matters

In one critical-infrastructure intrusion, security-disabling tooling reached at least 40 hosts in about two hours, and Warlock was then deployed on at least 33 hosts through the domain’s SYSVOL share.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · Securityaffairs

What happened

Jamf Threat Labs identified CloudSyncD as a fake macOS Zoom installer that uses invisible zero-width Unicode characters to conceal a phished password. The disk image presents a Zoom-branded volume and instructs users to bypass Gatekeeper because the app is only ad-hoc signed.

Why it matters

The second-stage implant checks in every 8 to 16 seconds with a hardware identifier and can receive either a compressed archive or a complete executable to unpack or run.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

AI & Agents · The Hacker News

What happened

TA419, described as a China-nexus cyber espionage group, has been attributed to multiple credential-phishing campaigns targeting AI experts at U.S. think tanks, universities, and legal-sector organizations. The campaigns impersonated prominent economists, AI policymakers, and a prominent Anthropic employee to target an AI policy expert.

Why it matters

Impersonation of policy and research figures makes recipients’ professional context part of the targeting surface rather than a generic lure.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly