ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?

That idea runs through this edition. Attackers use real tools, fake login … Continue reading ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories→

Posted in Uncategorized

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CV… Continue reading Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root→

Posted in Uncategorized

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

“Unlike the standard infostealer model, BraZe… Continue reading BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory→

Posted in Uncategorized

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in… Continue reading Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks→

Posted in Uncategorized

Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud… Continue reading Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means→

Posted in Uncategorized

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone

The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.

“Our analysis confirmed that an iMessage ze… Continue reading Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone→

Posted in Uncategorized

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon.

“FalconFlank is a 0day privilege esc… Continue reading Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon→

Posted in Uncategorized

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs.

The vulnerabilities are as follows –

CVE-2026… Continue reading CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners→

Posted in Uncategorized