Entry Thumbnail

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional […]

Posted by
Entry Thumbnail

The State of Ransomware Q2 2026

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The […]

Posted by
Entry Thumbnail

Microsoft Windows TCPIP.SYS IppQualifyAddresses Out-of-Bounds Read Vulnerability

TALOS-2026-2427 CVE-2026-49177 An out-of-bounds read vulnerability exists in the IppQualifyAddresses function of the Microsoft Windows tcpip.sys driver. A specially crafted I/O request packet (IRP) can cause an arbitrary out-of-bounds read, potentially leading to information disclosure or a denial-of-service condition. The versions below were either tested or verified to be vulnerable […]

Posted by
Entry Thumbnail

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Since early 2026, Check Point Research has tracked a wave of the **Operation Dream Job** campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded […]

Posted by
Entry Thumbnail

CSS:the bomb inside your inbox

Researcher **Published:** Thursday, 6 August 2026 at 22:00 UTC **Updated:** Thursday, 6 August 2026 at 22:00 UTC Gareth Heyes – gareth.heyes@portswigger.net – @garethheyes **It’s quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper I’m […]

Posted by