In a newly seen phishing campaign, malicious actors have exploited URL manipulation techniques to obfuscate their malicious links, compromising businesses and individuals worldwide. Check Point researchers identified a whopping 200,000 phishing emails abusing URL information to hide phishing links, with the first instance recorded on 21 January. The campaign is still active but has shown a gradual decline in the volume of daily threats. Who’s in the Crosshairs? The US has been the favored target of these attacks, making up three-quarters (75%) of the email distribution. EMEA region follows with 17%, and Canada has 5% of the total attack volume. …
Kirsten Doyle
A recent analysis by cybersecurity firm Hudson Rock on its Infostealers site has uncovered alarming vulnerabilities within the US military and its defense contractors due to widespread info stealer malware infections. According to the company, these infections have compromised sensitive data across several high-profile entities, including Lockheed Martin, Boeing, Honeywell, the US Army, Navy, FBI, and the Government Accountability Office (GAO). The compromised data encompasses VPN credentials, email systems, and access to classified procurement portals, raising significant concerns about national security. Oops, I Did It Again “Each one of these infected employees is a real person — it could be an engineer working…
Cybercrime-as-a-Service (CaaS) is more than just a trend—it’s here to stay. As sophisticated attack tools become widely (and easily) available, even less experienced cybercriminals can now carry out highly disruptive campaigns. In fact, Malware-as-a-Service (MaaS) now makes up 57% of detected threats—a 17% increase from the first half of last nyear. This surge makes it clear that CaaS models, particularly Ransomware-as-a-Service (RaaS) and MaaS, continue to fuel cybercrime at scale, arming adversaries with the tools they need to launch more frequent and complex attacks with minimal effort. This was one of the findings of Darktrace’s 2024 Annual Threat Report, which…
Researchers from Trend Micro’s Threat Hunting team have uncovered a new technique employed by the advanced persistent threat (APT) group dubbed Mustang Panda or Earth Preta. The cyberespionage group has been abusing the Microsoft Application Virtualization Injector (MAVInject.exe) to stealthily inject malicious payloads into waitfor.exe when it detects an ESET antivirus application running. This discovery is a sign of the group’s evolving tactics to bypass security defenses and maintain a foothold in compromised systems. Sophisticated Evasion Tactics Earth Preta’s latest campaign uses Setup Factory, an installer builder, to drop and execute malicious payloads while evading detection. The attack chain starts…
The Qualys Threat Research Unit (TRU) has uncovered two significant vulnerabilities in OpenSSH, a widely used open-source implementation of the Secure Shell (SSH) protocol. These flaws, tracked as CVE-2025-26465 and CVE-2025-26466, pose substantial security risks to enterprise infrastructure and encrypted communications. Details of the Vulnerabilities CVE-2025-26465: The researhers said the OpenSSH client is vulnerable to an active machine-in-the-middle (MITM) attack if the VerifyHostKeyDNS option is enabled (it is disabled by default): when a vulnerable client connects to a server, an active machine-in-the-middle can mimic the server by fully bypassing the client’s checks of the server’s identity. The issue was introduced…
South Korea has formally suspended new downloads of the Chinese AI chatbot DeepSeek, citing concerns over data privacy and compliance with domestic regulations. The suspension took effect on 15 February, according to the Personal Information Protection Commission (PIPC). While downloads are currently restricted in domestic app marketplaces, the web-based service remains accessible. The decision follows PIPC’s analysis of DeepSeek’s data handling practices, which revealed deficiencies in communication functions and personal information processing procedures with third-party service providers. Shortly after its launch, DeepSeek was found to have inadequately addressed South Korea’s data protection laws, which saw regulators issue a formal order…
Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that targets users by infecting Xcode projects. While the latest variant has only been observed in limited attacks, security researchers warn that its enhanced capabilities make it a significant threat to macOS users and developers. A Persistent Threat Since 2020 First identified by Trend Micro in 2020, XCSSET initially gained infamy as it was able to compromise Xcode projects, which allowed it to execute malicious code whenever a developer built an infected project. The malware leveraged zero-day vulnerabilities to slip past macOS security protections, steal…
As entities of every sector move more apps and workloads to the cloud, security is becoming a top priority. Microsoft Azure, one of the world’s most popular cloud platforms, provides a range of security tools and best practices to help businesses protect their assets stored in their environments. However, securing an Azure environment is about more than just enabling default protections—it’s about helping users maintain compliance, too. This takes a forward-thinking approach to identity management, network security, logging, and monitoring. To strengthen security, Microsoft has made several key changes, including mandatory Multi-Factor Authentication, new AI-driven security integrations, and enhancements to…
Jeremiah Fowler, an experienced cybersecurity researcher at vpnMentor and co-founder of Security Discovery, has uncovered a massive data exposure involving nearly 2.7 billion records linked to Mars Hydro, a China-based manufacturer of IoT-enabled grow lights. The breach, which included sensitive Wi-Fi credentials, IP addresses, and device details, underscores ongoing concerns about IoT security and data privacy. Fowler discovered the unprotected database and reported it to vpnMentor. The publicly accessible trove contained 2,734,819,501 records totaling 1.17 terabytes of data, exposing logging, monitoring, and error records for IoT devices sold globally. The records included: The database appeared to belong to LG-LED SOLUTIONS…
eSentire’s Threat Response Unit (TRU) has uncovered a new cyber espionage campaign leveraging a legitimate Adobe executable to sideload the EarthKapre/RedCurl loader. The attack specifically targeted a firm in the Legal Services industry, highlighting the group’s persistent focus on corporate espionage. A Sophisticated Attack Chain The TRU team said the initial foothold was gained through a phishing campaign, where targets received a PDF file masquerading as an Indeed job application. The PDF contained links to a ZIP archive with an ISO image. Once the victim opened the image file, they encountered what appeared to be a CV file (“CV Applicant…
