logo

The democratisation of business email compromise fraud

ID: 0cb34398-5a57-5241-a241-df37544823d4

STIX ID: report--0cb34398-5a57-5241-a241-df37544823d4

Feed Name: Cisco Talos

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-27

Author: Martin Lee

...
...

This Cisco Talos newsletter summarizes multiple active security issues: a large-scale automated credential-harvesting campaign exploiting React2Shell (CVE-2025-55182) via a "NEXUS Listener", active exploitation of an F5 BIG-IP RCE, a Chrome zero-day in the wild, an Amazon cloud account breach, ongoing Qilin ransomware activity, and published malware IOCs; it provides mitigation recommendations (patching, credential rotation, IMDSv2, tuned WAF/RASP, least-privilege controls) and warns that BEC scams are increasingly automated and targeting small organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.