Researchers at Palo Alto Networks have identified a new Linux malware strain dubbed Auto-Color, which uses cunning, advanced stealth techniques to slip through the security nets and maintain persistence on compromised systems. The malware, first detected in early November last year, mainly targets universities and government offices across North America and Asia. Auto-Color hides its presence by using benign-sounding file names, such as door or egg, and uses an advanced method for hiding command and control (C2) connections—similar to the tactics used by the Symbiote malware family. It also uses proprietary encryption algorithms to obfuscate communication and configuration details. Once…
Kirsten Doyle
At a time when artificial intelligence (AI) is reshaping cybersecurity, conventional approaches to passwords and endpoint management are increasingly vulnerable. AI-powered threats are rapidly evolving, leveraging automation and deep learning to crack passwords, slip past authentication measures, and exploit weaknesses in endpoints at an unrivaled scale. Entities that once relied on static credentials and perimeter-based security now face a landscape where adaptive, AI-driven attacks demand equally intelligent defenses. As endpoint ecosystems expand—with remote work, cloud services, and IoT devices—attack surfaces grow, making it critical for businesses to rethink how they manage access and secure endpoints in real-time. To understand how…
Cybersecurity researchers at SentinelLABS have uncovered a new campaign linked to the long-running Ghostwriter operation, targeting Belarusian opposition activists and Ukrainian military and government entities. The campaign, which entered its active phase in late 2024, is ongoing, with recent malware samples and command-and-control (C2) activity indicating continued threats. A Persistent Espionage Operation Ghostwriter, an advanced persistent threat (APT) campaign with ties to Belarusian intelligence, has been active since at least 2016. Previously tracked by cybersecurity firms under the names UNC1151 (Mandiant) and UAC-0057 (CERT-UA), the campaign blends information manipulation with cyber intrusions. Over the years, it has targeted European countries…
The Trump administration is set to significantly weaken the CHIPS Act by terminating hundreds of employees at the National Institute of Standards and Technology (NIST), the agency responsible for administering the semiconductor incentive program. President Biden signed the bipartisan CHIPS and Science Act two years ago, investing $53 billion to boost US semiconductor supply chains, create jobs, and enhance national security. According to multiple sources, including Axios and Bloomberg, nearly 500 NIST employees, many of whom were recently hired to support the CHIPS Act, are expected to be dismissed under the pretext of “probationary” firings. Mass Firings Threaten CHIPS Act…
A botnet made up of more than 130,000 compromised devices is conducting large-scale password-spraying attacks against M365 accounts, exploiting non-interactive sign-ins with Basic Authentication. This method lets malicious actors bypass modern login protections, evade multi-factor authentication (MFA) enforcement, and remain undetected by security teams. Leveraging Purloined Credentials Malefactors are leveraging stolen credentials from infostealer logs to systematically target M365 accounts on a global scale. These attacks are recorded in Non-Interactive Sign-In logs, an area frequently overlooked by security teams. They exploit this gap to launch high-volume password spraying attempts without triggering security alerts. Non-interactive sign-ins are often used for service-to-service…
The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI) and the Multi-State Information Sharing and Analysis Center (MS-ISAC), has issued a joint Cybersecurity Advisory on Ghost (Cring) ransomware. The advisory, titled #StopRansomware: Ghost (Cring) Ransomware, provides network defenders with key indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods identified through FBI investigations. Ghost ransomware actors target firms with outdated software and firmware in their internet-facing services. The advisory warns that these bad actors exploit known vulnerabilities where patches have not been applied to gain unauthorized access. The identified Common…
Cisco Talos has been actively tracking reports of extensive intrusion attempts targeting multiple major U.S. telecommunications companies. First identified in late 2024 and subsequently confirmed by the US government, this activity is attributed to a highly advanced threat actor known as Salt Typhoon. According to public reports, Salt Typhoon successfully infiltrated core networking infrastructure in multiple instances, leveraging these systems to collect sensitive information. While one case suggested exploitation of a known Cisco vulnerability (CVE-2018-0171), Cisco Talos’ investigations indicate that most incidents stemmed from the use of legitimate victim login credentials rather than newly discovered vulnerabilities. The findings reveal that…
In a newly seen phishing campaign, malicious actors have exploited URL manipulation techniques to obfuscate their malicious links, compromising businesses and individuals worldwide. Check Point researchers identified a whopping 200,000 phishing emails abusing URL information to hide phishing links, with the first instance recorded on 21 January. The campaign is still active but has shown a gradual decline in the volume of daily threats. Who’s in the Crosshairs? The US has been the favored target of these attacks, making up three-quarters (75%) of the email distribution. EMEA region follows with 17%, and Canada has 5% of the total attack volume. …
A recent analysis by cybersecurity firm Hudson Rock on its Infostealers site has uncovered alarming vulnerabilities within the US military and its defense contractors due to widespread info stealer malware infections. According to the company, these infections have compromised sensitive data across several high-profile entities, including Lockheed Martin, Boeing, Honeywell, the US Army, Navy, FBI, and the Government Accountability Office (GAO). The compromised data encompasses VPN credentials, email systems, and access to classified procurement portals, raising significant concerns about national security. Oops, I Did It Again “Each one of these infected employees is a real person — it could be an engineer working…
Cybercrime-as-a-Service (CaaS) is more than just a trend—it’s here to stay. As sophisticated attack tools become widely (and easily) available, even less experienced cybercriminals can now carry out highly disruptive campaigns. In fact, Malware-as-a-Service (MaaS) now makes up 57% of detected threats—a 17% increase from the first half of last nyear. This surge makes it clear that CaaS models, particularly Ransomware-as-a-Service (RaaS) and MaaS, continue to fuel cybercrime at scale, arming adversaries with the tools they need to launch more frequent and complex attacks with minimal effort. This was one of the findings of Darktrace’s 2024 Annual Threat Report, which…
