Google researchers have discovered a Kremlin-backed operation using malware to target potential recruits for the Ukrainian military. The malware, spread primarily via Telegram and a website known as Civil Defense, appears to offer free software for locating military recruiters but instead installs information-stealing software on Windows and Android devices. The operation uses a variant of CraxsRat for Android and a custom version of Pronsis Loader for Windows.

Exposed credentials are giving attackers a head start many organizations don’t see
Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential


