header security lab

Monthly Threat Reports

Welcome to our Monthly Threat Report Hub, your go-to resource for the latest insights on email security. Each month, explore in-depth analyses from Hornetsecurity’s Security Lab, specializing in forensic examinations of current and critical security threats. Tailored for CISOs, Microsoft 365 admins, and all cybersecurity enthusiasts, the Monthly Threat Reports will keep you one step ahead of hackers. Discover and download the latest reports to fortify your organization against evolving cyber threats.

Monthly Threat Report : August 2024
Threat Reports

Monthly Threat Report August 2024: A Month of Global Impact

Widespread cyberattacks dominated July 2024, highlighted by the severe CrowdStrike incident that caused significant disruptions across multiple businesses. New vulnerabilities in VMware ESXi and increased DDoS attacks from Anonymous Sudan further compounded the threat landscape.
Threat Reports

Monthly Threat Report July 2024: Snowflake(s) in July

This month’s email attacks: more spam, less targeted. Cloud storage provider Snowflake’s customers were breached. Change Healthcare revealed leaked data from their ransomware attack. Big news: Kaspersky banned in the US! Finally, good news – the FBI has Lockbit decryption keys (see Lockbit section if affected).
Threat Reports

Monthly Threat Report June 2024: New Threat Campaigns Involving Darkgate

This month, we detected a new Darkgate Malware campaign using pastejacking to distribute malware. Additionally, the successful dismantling of the 911 S5 Proxy Botnet marks a major milestone in cybersecurity. Furthermore, threat actors impersonating helpful community members on platforms like Stack Overflow distribute malicious PyPI packages, posing a new threat vector.
Threat Reports

Monthly Threat Report February 2024: A Month for Breaches and Ransomware

This month, we’ve witnessed a decline in low-effort high-volume email attacks, but a rise in targeted, sophisticated assaults. FedEx, Amazon, and Facebook were prime targets for brand impersonation. The breach of Microsoft’s executive emails by the ‘Midnight Blizzard’ group highlighted OAuth application security concerns. Additionally, AnyDesk reported a breach, and Johnson Controls faced a significant ransomware attack.
Threat Reports

Monthly Threat Report November 2023: Holiday Email Threat Increases and More Zero-Days

This month’s report highlights a slight increase in spam messages, a higher brand impersonation attempts in shipping and finance, ongoing security developments at Microsoft, a significant vulnerability in Citrix NetScalers, and legal actions against SolarWinds and their CISO for fraud and security lapses related to the 2020 SunBurst incident.
Threat Reports

Monthly Threat Report October 2023

This month’s report highlights high email threats, increased targeting of the Entertainment and Mining industries, ongoing Microsoft security incidents, a critical libwebp vulnerability, and gradual Storm-0558 breach revelations with email exfiltration.