Search, Click, Steal: The Hidden Threat of Spoofed Ivanti VPN Client Sites

Zscaler Threat Hunting observed an SEO poisoning campaign on Bing distributing a signed, trojanized Ivanti Pulse Secure MSI to steal VPN credentials and exfiltrate them to a Microsoft Azure-hosted C2. The campaign uses lookalike domains, referrer-based conditional content delivery, and a credential-stealing DLL that targets connectionstore.dat; detected artifacts include the Ivanti-VPN.msi hash 6e258deec1e176516d180d758044c019 and C2 IP 4.239.95.1. #Ivanti-Pulse-Secure #Akira

Read More
Cybersecurity News | Daily Recap [14 Oct 2025]

Daily Recap, A new 8-byte write called RMPocalypse targets AMD SEV-SNP and an array of exploits including CVE-2025-61927 and a CL0P-linked Oracle EBS zero-day affecting Harvard, while threats persist across NTDS.dit credential harvesting and geo-mapping persistence. Threat actors also exploit SonicWall VPNs, mass RDP botnets target the US, and a UK rise in nationally significant attacks highlights evolving risk in critical infrastructure #RMPocalypse #CVE-2025-61927 #NTDSdit #OracleEBS #Harvard #SonicWall #RDPBotnet #UKAttacks

Read More

Proofpoint researchers identified TA585, a cybercriminal actor that manages its own infrastructure and delivery to install third-party malware such as MonsterV2, which acts as a RAT, stealer, and loader. The report details TA585’s ClickFix web-inject delivery, GitHub notification lures, SonicCrypt crypter usage, and multiple MonsterV2 indicators including file hashes and C2…

Read More
When geopolitics goes digital: NATO, Russia, and state-backed cyber attacks

Threat actors (including APT28, APT29, Sandworm, and Gamaredon) use a range of living-off-the-land binaries, DLL side‑loading, scheduled task and autorun persistence, credential dumping (Mimikatz, LSASS access), lateral tools (PsExec, Impacket), and cloud/file-host exfiltration to conduct reconnaissance, lateral movement, and C2. Detection recommendations include targeted hunting alerts and queries (for masqueraded XML scheduled tasks, autorun key modifications, unsigned DLL loads, PowerShell/web requests, OAuth abuse in Microsoft 365, and more) plus broader controls like EDR/NDR, defense-in-depth, patching, and logging. #APT28 #APT29

Read More
Fake Microsoft Teams Installers Distribute Oyster Backdoor – SOCRadar® Cyber Intelligence Inc

Attackers used SEO poisoning and malicious ads to distribute fake Microsoft Teams installers that drop the Oyster (Broomstick) backdoor, providing persistent C2 access via a malicious DLL, scheduled task CaptureService, and rundll32.exe execution. Key IOCs include domains like teams-install.icu and nickbush24.com, IPs such as 185.28.119.228, and multiple malicious file hashes. #Oyster #nickbush24.com

Read More
Exploring Invoice Fraud Email Attempts with Validin

A highly convincing invoice-and-W9 phishing email targeted a Validin employee and used a realistic company identity (Ignitecore Consulting LLC) and reply-to domain to try to collect payments. Investigators pivoted on HTML/CSS template hashes, registration and hosting patterns, self-signed certificates, and Cloudflare origin IPs to identify ~40 related domains and multiple origin IP addresses to block. #ignitecoreconsulting #Cloudflare

Read More
Investigating targeted payroll pirate attacks affecting US universities

Microsoft observed a financially motivated group tracked as Storm-2657 using AITM phishing to steal MFA codes, compromise employee Exchange Online accounts, create inbox rules to hide Workday notifications, and redirect payroll to attacker-controlled bank accounts. The campaign targeted US universities and higher-education staff via tailored phishing themes and succeeded where phishing-resistant MFA was not enforced. #Storm-2657 #Workday

Read More
New Rust Malware “ChaosBot” Uses Discord for Command and Control

eSentire’s TRU discovered a novel Rust-based backdoor named ChaosBot that uses Discord for command-and-control, leverages compromised VPN and over-privileged Active Directory credentials, and can side-load via msedge_elf.dll. Observed capabilities include remote command execution via PowerShell, file transfer, screenshots, FRP-based reverse proxying, VM/ETW evasion, and attempted VS Code Tunnel deployment. #ChaosBot #frp

Read More
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits

Trend Research and ZDI Threat Hunters have identified a large-scale RondoDox botnet campaign using an “exploit shotgun” that targets over 50 vulnerabilities across more than 30 vendors to compromise internet-exposed routers, DVRs, NVRs, CCTV systems, and web servers. Active exploitation has been observed globally since mid-2025, leveraging vulnerabilities including CVE-2023-1389, CVE-2024-3721,…

Read More
Oracle EBS Unauthenticated RCE Exploit

Oracle released a Security Alert for CVE-2025-61882, a remotely exploitable unauthenticated vulnerability in Oracle E-Business Suite’s Concurrent Processing (BI Publisher Integration) that can lead to remote code execution; customers are urged to apply provided updates and ensure prerequisite October 2023 Critical Patch Update is installed. Indicators of compromise and detection details (IPs, observed commands, and file hashes) are provided to support immediate hunting and containment. #CVE-2025-61882 #Oracle_E-Business_Suite

Read More
Detecting DLL hijacking with machine learning: real-world cases

Kaspersky integrated a machine-learning model for detecting DLL-hijacking (DLL sideloading) into its SIEM (Kaspersky SIEM), which analyzes loaded libraries with local attributes and Kaspersky Security Network validation to improve detection and reduce false positives. During pilot MDR testing the model detected multiple real incidents — including ToddyCat using Cobalt Strike via DLL sideloading, an infostealer masquerading as policymanager.dll, and a malicious loader (wsc.dll) on a USB drive — and flagged related IOCs. #ToddyCat #CobaltStrike #SystemSettings.dll #policymanager.dll #wsc.dll

Read More