A phishing campaign targeting Kuwait’s critical sectors has been exposed due to the reused SSH keys across multiple attack servers. Active as of May 2025, it employs over 100 domains impersonating local businesses, particularly in the fisheries sector. The operational security lapse allowed researchers to identify the campaign despite its sophisticated techniques, highlighting a need for improved security measures.

PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files
Cybersecurity researchers have discovered a new information-stealing malware named PupkinStealer. The malware, first identified in April 2025, steals browser credentials, messaging app sessions, and desktop