Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no ...
Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no ...
Introduction In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the ...
In traditional virtual machines (like EC2), administrators deploy custom certificates via configuration management tools (Ansible, Chef) or golden AMI images. But AWS Lambda containers are ephemeral ...
AI-enabled attackers are accelerating reconnaissance, credential abuse, and lateral movement. See how Deception turns that automation into early detection.
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered ...
Microsoft's August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The ...
Zscaler and Anthropic redefine AI Security with Policy Enforcement. This transformative integration delivers unified Zero Trust enforcement directly inside Claude via inference hooks, eliminating ...
Introduction The CXO Monthly Roundup provides the latest Zscaler ThreatLabz research, alongside insights into other cyber-related subjects that matter to technology executives. This month’s roundup ...
To Be Continued In this campaign, a threat actor targeted government entities in the Middle East using a multi-stage attack chain with previously undocumented malware tooling including, TELESHIM, ...
Conclusion This ClickFix campaign distributing MacSync Stealer shows how threat actors are increasingly abusing trusted platforms for attacks. In this case, attackers used malvertising to direct users ...