The Covert Operator’s Playbook: Infiltration of Global Telecom Networks

Unit 42 has identified a nation-state linked threat cluster, CL-STA-0969, targeting telecommunications infrastructure in Southwest Asia using custom tools and advanced evasion techniques. The activity involves exploitation of mobile roaming networks and implements various backdoors and implants to maintain stealthy persistence without clear evidence of data exfiltration. #CL-STA-0969 #LiminalPanda #Cordscan…

Read More
Scattered Spider is targeting victims’ Snowflake data storage for quick exfiltration

The Scattered Spider hacking group is targeting data storage tools and using sophisticated social engineering tactics to access sensitive information of large organizations across various industries. Law enforcement efforts have not slowed their ongoing campaigns, which include data theft, malware deployment, and operational disruptions. #ScatteredSpider #Snowflake #DragonForceRansomware #Vishing #CybercriminalForums…

Read More
Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure

The cybercrime group known as Scattered Spider is targeting VMware ESXi hypervisors primarily through social engineering tactics rather than exploiting software vulnerabilities. Their campaign focuses on gaining deep access to critical systems, allowing for data theft and ransomware deployment, especially in North American sectors like retail and transportation. #ScatteredSpider #VMwareESXi #UNC3944…

Read More
Hunting Laundry Bear: Infrastructure Analysis Guide and Findings

Laundry Bear, also known as Void Blizzard, is a Russian state-sponsored APT active since April 2024 targeting NATO countries and Ukraine using spear phishing and credential theft. Using Validin’s advanced pivoting techniques, multiple additional malicious domains and infrastructure linked to Laundry Bear have been uncovered, expanding beyond initial Microsoft-reported indicators. #LaundryBear #VoidBlizzard #Validin

Read More
Surge in Phishing Attacks Exploiting Spoofed SharePoint Domains and Sneaky 2FA Tactics

Cybersecurity experts have detected a rise in sophisticated phishing campaigns that mimic Microsoft SharePoint through structurally similar domains and exploited hosting services. These campaigns employ advanced tactics like CAPTCHA challenges and credential theft to deceive users and bypass security measures. #SharePointPhishing #HostingAbuse…

Read More
Microsoft Sentinel data lake: Unify signals, cut costs, and power agentic AI

Microsoft Sentinel data lake introduces a modern, cost-effective data management architecture that unifies security data at scale, enabling faster detection and response with AI-powered capabilities. This solution addresses the challenges of managing massive datasets by breaking down data silos and integrating extensive threat intelligence across environments. #MicrosoftSentinel #SentinelDataLake #DefenderXDR

Read More
Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) 

LAMEHUG is the first known malware that integrates large language model (LLM) capabilities directly into its attack methodology, attributed with moderate confidence to APT28 targeting Ukrainian government officials. The malware uses the Qwen2.5-Coder-32B-Instruct LLM via Hugging Face API to dynamically generate and execute commands in real-time, demonstrating a proof-of-concept for AI-powered state-sponsored cyber operations. #LAMEHUG #APT28 #Qwen2.5-Coder

Read More
Disrupting Active Exploitation of On-Premises SharePoint Vulnerabilities

Microsoft reported ongoing exploits targeting on-premises SharePoint servers using vulnerabilities CVE-2025-49706 and CVE-2025-49704 by Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603. Immediate application of Microsoft’s security updates and recommended mitigations such as enabling AMSI and rotating machine keys are critical to protect affected systems. #CVE-2025-49706 #LinenTyphoon #VioletTyphoon #Storm-2603 #spinstall0.aspx

Read More
Back to Business: Lumma Stealer Returns with Stealthier Methods

Lumma Stealer malware has resurfaced soon after a major law enforcement takedown, utilizing stealthier tactics and diversified delivery methods to regain its reach. The threat actors behind it, including the group known as Water Kurita, continue to innovate their infrastructure and campaigns, posing ongoing risks to users and organizations. #LummaStealer #WaterKurita…

Read More
Substantial Upgrades to Crawling History, Artifact Collection

Validin has launched significant enhancements to its threat intelligence platform, including over 8 months of historical HTTPS banner data and on-demand access to full HTTP response artifacts. These upgrades enable deeper threat hunting, malware infrastructure analysis, and incident response capabilities, as demonstrated by uncovering additional Lazarus Group infrastructure linked to the Bybit heist. #Validin #TraderTraitor #LazarusGroup

Read More
Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief

Multiple critical vulnerabilities affecting on-premises Microsoft SharePoint servers have been actively exploited to bypass authentication and gain unauthorized access, leading to data exfiltration and persistent backdoors. Immediate patching, cryptographic material rotation, and professional incident response are strongly advised to mitigate these ongoing threats. #CVE-2025-49704 #CVE-2025-53770 #MicrosoftSharePoint…

Read More
The SOC files: Rumble in the jungle or APT41’s new target in Africa

Kaspersky MDR detected a sophisticated APT41 cyberespionage campaign targeting African government IT services, involving custom and publicly available tools such as Cobalt Strike, Pillager, and Mimikatz. The attackers leveraged internal infrastructure for command and control communication, performed credential dumping, lateral movement, and data exfiltration through a compromised SharePoint server. #APT41 #CobaltStrike #Pillager #SharePoint #Mimikatz

Read More