When Browsers Become the Attack Surface: Rethinking Security for Scattered Spider

Enterprise security is increasingly challenged by threats targeting web browsers, with over 80% of incidents originating from browser-based vulnerabilities. The cyber adversary Scattered Spider exemplifies sophisticated tactics such as credential theft and session hijacking, emphasizing the need for robust browser security strategies. #ScatteredSpider #BrowserSecurity…

Read More

[T1027.014 ] Obfuscated Files or Information: Polymorphic Code – Polymorphic code mutates its form on each execution to avoid signature-based detection, allowing malware to persist across Windows, Linux, and macOS environments by changing file content, metadata, or runtime behaviors. Detection requires behavior-based telemetry, file and application logs, and endpoint monitoring to spot anomalies in creation patterns, execution profiles, and mutation engine activity. #PolymorphicCode #DefenseEvasion

Read More
Dark Web Profile: Lynx Ransomware

Lynx is a Ransomware-as-a-Service group that emerged in mid-2024, likely rebranding or repurposing the INC ransomware source code to produce Windows and Linux (including ESXi) variants that use AES-128 CTR with Curve25519 and append a .lynx extension. The group operates via affiliates, practices double extortion through a public leak site, and by August 2025 had claimed nearly 300 victims concentrated in the United States and industries like Manufacturing and Business Services. #Lynx #INC

Read More
TINKYWINKEY KEYLOGGER

TinkyWinkey is a Windows keylogger composed of a service (svc.exe) and a keylogger payload (winkey.exe / keylogger.dll) that achieves persistence via a Windows service, injects a DLL into trusted processes, and captures keystrokes (including Unicode and media keys) alongside detailed system profiling. First observed June 24–25, 2025, components detected include svc.exe, winkey.exe, and keylogger.dll with corresponding SHA-256 hashes. #TinkyWinkey #svc.exe #winkey.exe #keylogger.dll

Read More
Hidden in Plain Sight: A Misconfigured Upload Path That Invited Trouble

A publicly exposed, unrestricted PHP file upload on a Linux webserver allowed a threat actor to upload an obfuscated PHP web shell and a mailer script, though the uploaded payloads were not externally reachable and broader exploitation was prevented. Varonis’ forensic investigation highlighted missing EDR, lack of centralized logs, unpatched high-severity…

Read More
China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years

The China-linked cyberespionage group Salt Typhoon has been targeting routers globally to maintain long-term access across various sectors, including government and telecom. This group exploits known vulnerabilities and employs sophisticated techniques to evade detection and exfiltrate data, posing a significant threat to international networks. #SaltTyphoon #GhostEmperor…

Read More
Hidden in Plain Sight: A Misconfigured Upload Path That Invited Trouble

Chinese state-sponsored APT actors have targeted telecommunications, government, transportation, lodging, and military networks worldwide by exploiting publicly known CVEs, compromising edge routers and using compromised devices and trusted provider links to pivot, persist, and exfiltrate data. Reported activity includes use of custom Go-based SFTP clients, on-box PCAP collection, Guest Shell/container abuse,…

Read More
Citrix Vulnerabilities Rising – When Gateways Give Way

Citrix disclosed three critical/high vulnerabilities in NetScaler ADC and Gateway (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424) that enable remote code execution, denial of service, and unauthorized management access; CVE-2025-7775 is already being actively exploited and all three are in CISA’s KEV catalog. Over 28,000 exposed NetScaler instances were observed online, increasing urgency to patch, restrict management interfaces, and hunt for post-exploitation artifacts. #CVE-2025-7775 #CVE-2025-7776

Read More
Malicious Screen Connect Campaign Abuses AI-Themed Lures for Xworm Delivery

Trustwave SpiderLabs discovered a deceptive campaign using fake AI-themed websites to trick users into installing a modified, digitally signed ScreenConnect installer that ultimately delivered an Xworm RAT via a multi-stage infection chain hosted on GitHub. The campaign used process hollowing, registry persistence, hidden remote sessions, and GitHub-hosted obfuscated Python scripts to evade EDR detection and enable credential theft and remote control. #ScreenConnect #XWorm

Read More
The Resurgence of IoT Malware: Inside the Mirai-Based “Gayfemboy” Botnet Campaign

FortiGuard Labs tracked the evolved “Gayfemboy” malware exploiting multiple vendor vulnerabilities (DrayTek, TP-Link, Raisecom, Cisco) to deliver a downloader that installs the botnet and coin miners across diverse sectors and countries. Campaign infrastructure included consistent attack source and download hosts, multiple C2 domains, UPX anti-unpacking tricks, sandbox evasion, process-killing of competitors, DDoS/backdoor capabilities, and explicit IOCs. #Gayfemboy #cross-compiling.org

Read More
Introducing Dashboard Feeds and Daily PTR Scanning

Validin introduced Dashboard Feeds (Threat Indicator Feed and Project Updates Feed) and daily PTR (reverse DNS) record scanning across IPv4 to improve analyst workflows and DNS visibility. These updates help surface newly reported IOCs, consolidate project activity, and capture short-lived PTR changes such as the rotation observed for 91.247.36[.]102 and free.friendhosting[.]net. #91.247.36.102 #free.friendhosting.net

Read More