Payroll Pirates Phishing Campaign Targets Microsoft 365 Financial Workflows (Campaign)

The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled...

2026/8/7
阅读更多

keyv and cacheable npm Package Hijacked in Supply Chain Attack (Campaign)

Multiple npm packages in the keyv/cacheable ecosystem were compromised following the compromise of a GitHub maintainer account, resulting in the publication of malicious package versions. All versions shared a consistent payload. Starting at 9:00 UTC, the attacker first used a...

2026/8/4
阅读更多

CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Campaign)

Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary...

2026/7/31
阅读更多

Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability (Campaign)

The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-name...

2026/7/22
阅读更多

SleeperGem: RubyGems Supply Chain Attack Targets Dormant Maintainer Accounts (Campaign)

On July 18-19, 2026, an attacker compromised at least two dormant RubyGems maintainer accounts (inactive since 2019) to publish malicious gem versions. The attack was discovered when git_credential_manager appeared with suspicious behavior—downloading binaries from a public Fo...

2026/7/19
阅读更多

NadMesh: Autonomous AI-Focused Botnet Targeting Cloud and AI Infrastructure (Campaign)

NadMesh uses a centralized controller to coordinate scanning across large IP ranges and attempts exploitation using more than 20 supported attack vectors. The malware targets exposed services such as Docker APIs, Kubernetes APIs, Redis, Elasticsearch, Jenkins, WebLogic, and MC...

2026/7/17
阅读更多

CVE-2025-54068 Exploited in Large-Scale Laravel Livewire Credential Theft Campaign (Campaign)

A large-scale credential theft campaign exploiting CVE-2025-54068, a critical unauthenticated remote code execution vulnerability in Laravel Livewire v3. Attackers used PHP deserialization to execute a Bash-based credential stealer that harvested sensitive application secrets ...

2026/7/16
阅读更多

AsyncAPI Supply Chain Compromise via GitHub Actions (Campaign)

On July 14, 2026, an attacker opened 37 pull requests to the AsyncAPI generator repository. Almost all attempted to add a fake charity donation page. Camouflage in the noise, a single PR exploited a misconfigured GitHub Actions workflow to steal a highly privileged Personal Ac...

2026/7/14
阅读更多

Cryptomining campaign targeting Linux SSH servers (Campaign)

AhnLab ASEC identified an ongoing Linux-targeted cryptomining campaign that compromises internet-exposed SSH servers using brute-force attacks against weak credentials. Once access is obtained, attackers deploy a multi-stage malware toolkit consisting of Go-based downloaders a...

2026/7/12
阅读更多

Jscrambler npm Package Compromised in Supply Chain Attack (Campaign)

A malicious version of the Jscrambler npm package, jscrambler@8.14.0, was published at 15:12 UTC on 11 July 2026. The compromised release executed a dropper via an npm preinstall hook that detected the host operating system and extracted a platform-specific native binary for W...

2026/7/11
阅读更多

Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Keys (Campaign)

A malicious version of the @injectivelabs/sdk-ts npm package (version 1.20.21) was briefly published to the official Injective Labs npm namespace after a contributor account was compromised. The package contained credential-stealing functionality that silently exfiltrated cryp...

2026/7/9
阅读更多

Coordinated GitHub API Enumeration and Access Token Abuse (Campaign)

Datadog Security Labs identified multiple coordinated campaigns abusing the GitHub API to systematically enumerate organizations, repositories, users, and software development activity at scale. The activity primarily relied on legitimate GitHub functionality, including dorman...

2026/7/8
阅读更多

Cryptojacking Campaign Targeting K8s Clusters (Campaign)

Researchers identified a campaign leveraging the Realm C2 framework that has compromised thousands of Linux hosts between June 13-23, 2026, with a primary focus on a large managed Kubernetes clusters. The attackers exploited vulnerabilities in Argo Workflows and Gogs to gain i...

2026/6/25
阅读更多

Klue Supply Chain Breach Leads to Salesforce Data Exfiltration (Incident)

According to investigations, the compromise began when attackers gained access to Klue backend systems and deployed code capable of harvesting OAuth tokens used by customers to integrate Klue with third-party platforms such as Salesforce, Gong, SharePoint, HubSpot, Slack, and ...

2026/6/18
阅读更多

Mastra Packages Trojanized with Malicious Dependency (Campaign)

On 17 June 2026, attackers compromised a maintainer account associated with the Mastra npm organization and used it to republish 116 packages over a 27-minute period. Rather than modifying Mastra’s source code directly, the threat actor injected a malicious dependency, easy-da...

2026/6/17
阅读更多

FortiBleed: Credential Compromise Campaign Targeting Fortinet Devices (Campaign)

According to the research, the threat actor operates an automated infrastructure that scans the internet for Fortinet devices and attempts authentication using a curated set of previously leaked or compromised credentials. Successful logins are recorded and continuously revali...

2026/6/16
阅读更多

Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Package (Campaign)

Researchers have disclosed a software supply chain attack, dubbed "Atomic Arch," targeting orphaned packages in the Arch User Repository (AUR). Using newly created AUR accounts, an attacker adopted more than 400 abandoned packages through the legitimate maintainer-handoff mech...

2026/6/12
阅读更多

ServiceNow Unauthenticated Access Incident (Incident)

According to public reports, the activity appears to be associated with a Scripted REST Resource endpoint (/api/now/related_list_edit/create) that was allegedly configured with requires_authentication = false, potentially allowing unauthenticated access to backend functionalit...

2026/6/9
阅读更多

TeamPCP adds Malware to Multiple Microsoft-Linked GitHub Projects (Campaign)

TeamPCP has leveraged a compromised GitHub account to inject malicious code into at least 42 repositories and 236 branches across the Azure, Azure-Samples and Microsoft GitHub organizations. They were published between 02:36 and 03:22 UTC on 5 June 2026. As of 14:00 UTC on 5 J...

2026/6/5
阅读更多

Binding.gyp Supply Chain Attack Enables CI/CD Worm Propagation Across npm Packages (Campaign)

Researchers identified an active supply chain attack affecting multiple npm packages that leverages a novel abuse of the binding.gyp build mechanism to execute malicious code during package installation. Unlike traditional npm supply chain attacks that rely on preinstall or po...

2026/6/4
阅读更多

Miasma: Supply Chain Compromise in RedHat npm Packages (Campaign)

On 1 June 2026, Wiz Research identified a supply chain compromise affecting multiple packages published under the @redhat-cloud-services npm namespace. Investigation revealed that at least 29 package releases contained unauthorized modifications that did not match the correspo...

2026/6/1
阅读更多

JINX-0164 Targeting Cryptocurrency Development Infrastructure (Campaign)

Wiz Research identified an active threat campaign targeting cryptocurrency organizations and software development infrastructure through social engineering, malicious meeting lures, and supply chain compromise activity. The campaign leveraged fake business interactions and tro...

2026/5/27
阅读更多

Supply Chain Campaign Targeting Composer and GitHub Repositories (Campaign)

Researchers identified multiple coordinated software supply chain attacks targeting Composer/Packagist packages and upstream GitHub repositories. The activity involved malicious postinstall hooks, compromised Git tags, CI/CD payload execution, and credential-stealing malware d...

2026/5/24
阅读更多

Megalodon Campaign Backdoors GitHub Repositories via CI Workflow Compromise (Campaign)

Researchers disclosed a large-scale software supply chain campaign dubbed “Megalodon,” in which attackers reportedly compromised thousands of GitHub repositories by injecting malicious GitHub Actions workflows designed to exfiltrate secrets and cloud credentials. The campaign ...

2026/5/22
阅读更多

TeamPCP Claims Breach of Internal GitHub Repositories (Incident)

According to GitHub’s public statement, the company detected unauthorized access involving internal repositories and initiated an ongoing investigation into the scope and potential impact of the incident. GitHub stated that it is closely monitoring its infrastructure for follo...

2026/5/20
阅读更多

New Mini-Shai-Hulud Wave Targets NPM, PyPi Packages and VSCode Extension (Campaign)

Researchers identified a broad TeamPCP-linked supply chain campaign involving malicious NPM packages, compromised GitHub Actions, a trojanized VSCode extension, and malicious PyPI packages targeting cloud and CI/CD environments. The campaign includes large-scale credential the...

2026/5/18
阅读更多

node-ipc npm Distribution Compromised (Campaign)

Multiple trojanized versions of the @node-ipc package have were uploaded to npm on 14 May 2026. The malicious versions are: node-ipc@9.1.6, node-ipc@9.2.3, node-ipc@12.0.1 The malicious code collects data and exfiltrates it via dns tunneling.On 14 May 2026 three malicious vers...

2026/5/14
阅读更多

Tanstack and other Packages Compromised in Supply Chain Attack (Campaign)

On May 11, 2026, TeamPCP launched coordinated software supply chain attacks targeting the npm and PyPI ecosystems. Over roughly six hours, the attacker published dozens of trojanized packages across multiple namespaces, including several high-profile and trusted publishers.The...

2026/5/11
阅读更多

DDoS Botnet Leveraging Jenkins Misconfigurations for Initial Access (Campaign)

The attack begins with unauthorized access to exposed Jenkins instances, often enabled by weak credentials. Threat actors abuse the scriptText endpoint, which allows execution of Groovy scripts, to achieve remote code execution. The malicious script delivers platform-specific ...

2026/5/10
阅读更多

Compromise of Checkmarx Jenkins AST Plugin by TeamPCP (Campaign)

Previously, the attackers gained access to internal resources, and used it to extract sensitive credentials, including publishing credentials for Jenkins plugins. Using this access, they modified and redistributed the Checkmarx AST Scanner Jenkins Plugin via the official plugi...

2026/5/9
阅读更多

Lightning and Intercom Packages Compromised in Supply Chain Attack (Campaign)

In the PyPI package lightning, malicious code is triggered automatically upon import. The code downloads and installs the Bun runtime and executes a large (~11 MB) obfuscated JavaScript payload. This behavior enables credential harvesting from developer environments and CI/CD ...

2026/4/30
阅读更多

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware (Campaign)

Malicious versions of legitimate SAP ecosystem packages (e.g., @cap-js/sqlite, @cap-js/postgres) were created by modifying them to include a preinstall script that executes setup.mjs automatically during npm install. This script downloads the Bun runtime and executes an obfusc...

2026/4/29
阅读更多

Critical SQL Injection Vulnerability in LiteLLM Exploited in-the-Wild (Campaign)

The vulnerability exists in LiteLLM’s authentication flow, where the Authorization: Bearer header is directly concatenated into a SQL query without proper parameterization. This flaw allows attackers to inject arbitrary SQL statements prior to authentication, enabling direct a...

2026/4/27
阅读更多

Elementary Data Compromised in Supply Chain Attack (Campaign)

The compromise originated from a GitHub Actions script injection vulnerability in a workflow that improperly handled untrusted input from pull request comments. An attacker exploited this flaw to execute arbitrary commands within the CI pipeline, gaining access to the reposito...

2026/4/23
阅读更多

Checkmarx KICS and Bitwarden CLI Compromised in Fresh Supply Chain Attack (Campaign)

Multiple malicious versions of Checkmarx projects have been published, including Docker images and VS Code extensions (this included both publishing new malicious image versions and pointing existing tags to malicious instances). This is a new incident, separate from the March...

2026/4/22
阅读更多

Xinference Compromised in Supply Chain Attack (Campaign)

The attackers compromised legitimate xinference releases rather than publishing a typosquat package, embedding malicious code directly into xinference/init.py. This ensures execution whenever the package is imported, including during application startup or dependency resolutio...

2026/4/22
阅读更多

Context.ai OAuth Token Compromise (Incident)

On April 19th, 2026, Vercel disclosed a security incident involving unauthorized access to their internal systems. According to their incident report, the attacker compromised an employee’s Google Workspace account via a third-party AI tool named Context.ai, who have since con...

2026/4/20
阅读更多

PolinRider Campaign: DPRK-Linked Supply Chain Attack Infects GitHub Repositories (Campaign)

A supply chain campaign attributed to a DPRK-linked threat actor, PolinRider, has resulted in the compromise of over 1,900 GitHub repositories through malicious npm packages, VS Code artifacts, and injected JavaScript payloads. The campaign leverages stealthy code injection an...

2026/4/9
阅读更多

Stolen SaaS Integration Tokens Enable Data Theft Across Snowflake Environments (Campaign)

The attack originated reportedly from a security incident affecting Anodot, a SaaS analytics and anomaly detection platform that integrates with multiple cloud services (e.g., Snowflake, S3, and streaming pipelines). Threat actors reportedly obtained authentication tokens asso...

2026/4/7
阅读更多

O365 Device Code Phishing Campaign using EvilTokens and Abusing Railway Platform (Campaign)

A phishing campaign has been reported leveraging the EvilTokens Phishing-as-a-Service platform to target O365 users. The attackers use device code phishing to bypass Multi-Factor Authentication (MFA), and they also utilize Railway to host their malicious infrastructure. The ca...

2026/4/7
阅读更多

Exploitation Campaign of Vulnerable GitHub Workflows (Campaign)

An unknown threat actor has been conducting an opportunistic campaign of automated malicious pull requests to attempt to initiate supply chain compromise against various open source repositories. In at least two cases, the attacker has been able to inject malicious code that u...

2026/4/6
阅读更多

UAT-10608 Campaign Abuses React2Shell for Cloud Credential Harvesting (Campaign)

An automated campaign attributed to threat cluster UAT-10608 is exploiting vulnerable Next.js applications to achieve pre-authentication remote code execution and deploy a multi-phase credential harvesting framework. The operation has compromised hundreds of hosts across cloud...

2026/4/2
阅读更多

Axios supply chain attack (Incident)

The malicious versions of axios differed from legitimate releases by including a dependency on plain-crypto-js, a trojanized package. These versions were published directly via a compromised maintainer account and later removed from npm following disclosure. Due to the short e...

2026/3/31
阅读更多

Apifox supply chain attack (Incident)

The Apifox incident is a client-side supply chain attack in which attackers compromised an official CDN-hosted JavaScript resource (apifox-app-event-tracking.min.js) and injected heavily obfuscated malicious code into a trusted analytics script. Because the Apifox desktop clie...

2026/3/26
阅读更多

BuddyBoss supply chain attack (Incident)

The BuddyBoss campaign (Parts 1 & 2) represents a full-spectrum software supply chain attack against the WordPress ecosystem, where the threat actor compromised the BuddyBoss plugin/theme distribution pipeline and leveraged it to infect hundreds of downstream websites. The ini...

2026/3/25
阅读更多

LiteLLM supply chain attack (Incident)

Malicious versions of the LiteLLM python package (1.82.7 and 1.82.8) were published on the morning of 24 March 2026. The compromised packages employed two different methods to deliver their payload. The packages were published at approximately 8:30 UTC and quarantined by PyPI ...

2026/3/24
阅读更多

KICS supply chain attack (Incident)

The Checkmarx KICS GitHub Action was compromised by TeamPCP between 12:58 and 16:50 UTC on March 23, during which users pinning to affected tags were served credential-stealing malware before the repository was taken down. This marks the second major open source security scann...

2026/3/23
阅读更多

Exploitation of S1ngularity-exposed cloud keys for lateral movement (Incident)

The UNC6426 campaign demonstrates a multi-stage supply chain intrusion that transitioned from developer environment compromise to full cloud takeover within ~72 hours. The attack originated from a prior compromise of the nx npm package, where a malicious postinstall script dep...

2026/3/11
阅读更多

xygeni-action repository hijack (Incident)

The compromise of the xygeni-action represents a CI/CD supply chain attack in which a threat actor leveraged tag poisoning to distribute a backdoored GitHub Action at scale. The attacker first gained access to the repository via compromised maintainer credentials and a GitHub ...

2026/3/9
阅读更多

PolinRider supply chain attack (Incident)

The PolinRider campaign represents a highly automated software supply chain attack in which a threat actor—assessed to be DPRK-linked—leveraged a compromised developer environment to achieve large-scale propagation across GitHub repositories. The initial access vector was a tr...

2026/3/8
阅读更多

LexisNexis breach (Incident)

LexisNexis confirmed a cloud-based data breach after threat actor FulcrumSec leaked ~2GB of stolen data. The attacker exploited an unpatched React2Shell vulnerability in a frontend application to gain access to the company’s AWS environment, leading to large-scale data exfiltr...

2026/3/3
阅读更多

Trivy supply chain attack (Incident)

On March 19, 2026, Aqua Security’s Trivy was compromised in a follow-on incident attributed to unrotated credentials from a prior breach. Attackers pushed spoofed commits to both actions/checkout and aquasecurity/trivy, triggering the release of a malicious v0.69.4 version tha...

2026/3/1
阅读更多

SANDWORM_MODE: Typosquatted npm Packages Used to Hijack CI Workflows (Campaign)

According to Socket, the campaign operates as a typosquatting worm: the attacker publishes malicious packages that mimic trusted names (e.g., look-alikes of common utilities and AI coding tools). When one of these malicious packages is installed and imported, it executes a sta...

2026/2/20
阅读更多

SSHStalker Linux Botnet campaign (Campaign)

On 2026-02-09, a campaign was reported, involving SSHStalker, gaining initial access via Password attack, to achieve Resource hijacking, Data exfiltration.

2026/2/9
阅读更多

TeamPCP Cloud-Native Campaign Targeting Exposed Control Planes (Campaign)

TeamPCP’s operations center on abusing unauthenticated or weakly protected orchestration and management interfaces rather than exploiting traditional endpoints. Initial access is achieved via exposed Docker and Kubernetes APIs, vulnerable React/Next.js applications (CVE-2025-2...

2026/2/5
阅读更多

Supply-Chain Hijacking of Notepad++ Updates via Hosting Provider Compromise (Campaign)

Between June and late 2025, threat actors compromised the shared hosting infrastructure used by Notepad++ and selectively hijacked update traffic destined for notepad-plus-plus.org. Rather than exploiting a vulnerability in Notepad++ code, the attackers abused access at the ho...

2026/2/2
阅读更多

Supply-Chain Attack via Force Pushes on Plone GitHub Repositories (Campaign)

In January 2026, the Plone security team disclosed a security incident affecting the Plone GitHub organization, in which an attacker used force pushes to insert malicious JavaScript code into multiple repositories. The activity was traced back to a compromised contributor acco...

2026/1/31
阅读更多

Operation Bizarre Bazaar: Commercialized LLMjacking (Campaign)

Between December 2025 and January 2026, researchers uncovered a large-scale, systematic campaign targeting exposed large language model (LLM) and Model Context Protocol (MCP) infrastructure. Dubbed Operation Bizarre Bazaar, the activity represents the first publicly documented...

2026/1/28
阅读更多

Cloud-Native Phishing Infrastructure via Abused AWS WorkMail (Campaign)

Threat actors abused native AWS email services to build phishing and spam infrastructure inside a compromised cloud environment. After obtaining exposed long-term AWS credentials, the attackers conducted IAM and service reconnaissance to assess email-sending capabilities. Whil...

2026/1/27
阅读更多

Canonical Snap Store Hijacking Campaign (Campaign)

On 2026-01-17, a campaign was reported, involving an unknown actor, gaining initial access via Dangling resource,.

2026/1/17
阅读更多

VoidLink: A Cloud-Native Linux Malware Framework (Campaign)

Researchers have uncovered VoidLink, a highly modular and cloud-native Linux malware framework featuring custom loaders, implants, kernel-level rootkits, and more than 30 in-memory plugins. Built in Zig and engineered for modern cloud and containerized environments, VoidLink a...

2026/1/13
阅读更多

GeoServer RCE Exploited in CoinMiner Campaigns (Campaign)

The activity centers on CVE-2024-36401, a remote code execution vulnerability disclosed in 2024 that allows unauthenticated attackers to execute arbitrary commands on vulnerable GeoServer instances. Since disclosure, multiple threat actors have systematically scanned for expos...

2025/12/26
阅读更多

Amadey Loader Abuses Compromised Self-Hosted GitLab to Deliver StealC Infostealer (Campaign)

Amadey, an established malware loader active since at least 2018, was observed downloading second-stage payloads from a hijacked self-hosted GitLab instance hosted on gitlab[.]bzctoons[.]net. The infrastructure appears to belong to a legitimate organization, with evidence sugg...

2025/12/18
阅读更多

China-nexus Campaign Exploits CVE-2025-20393 in Cisco Email Security Devices (Campaign)

On December 17, 2025 Cisco announced that they had detected a campaign exploiting a zero day in their email security devices. The vulnerability affects the physical and virtual versions of Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and ...

2025/12/17
阅读更多

Shai-Hulud 2.0 Supply Chain Attack (Campaign)

A new wave of the Shai-Hulud–style supply-chain attack has trojanized hundreds of npm packages—including widely used components from Zapier, ENS Domains, PostHog, and Postman—resulting in more than 25,000 GitHub repositories populated with stolen secrets. Beginning on November...

2025/11/24
阅读更多

Cryptomining Campaign Exploiting Exposed Ray AI Infrastructure (Campaign)

ShadowRay 2.0 targets Ray clusters whose dashboard / Jobs API is exposed without authentication. Attackers first use interact.sh (oast.fun) for out-of-band discovery, posting test jobs to /api/jobs/ that trigger HTTP/DNS callbacks to identify exploitable Ray dashboards. Once a...

2025/11/19
阅读更多

Cisco ISE Vulnerability Exploited as 0day by APT (Campaign)

Researchers uncovered an advanced persistent threat (APT) exploiting zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems (CitrixBleed2). The vulnerabilities, tracked as CVE-2025-20337 and CVE-2025-5777, were leveraged by the attackers to deploy ...

2025/11/13
阅读更多

Unauthenticated Remote Access via Triofox Vulnerability Exploited by UNC6485 (Campaign)

Researchers uncovered active exploitation of an unauthenticated access vulnerability (CVE-2025-12480) in Gladinet’s Triofox remote access platform by the threat cluster UNC6485. The flaw, present in versions before 16.7.10368.56560, allowed attackers to bypass authentication u...

2025/11/12
阅读更多

Gambling Network Exploits Abandoned Subdomains (Campaign)

A routine asset scan for a major entertainment company uncovered a massive gambling operation hiding behind legitimate e-commerce infrastructure. The discovery began with a simple subdomain takeover on Shopify-an abandoned DNS mapping that had been left active after decommissi...

2025/11/11
阅读更多

China-Linked Actors Target U.S. Policy-Oriented Non-Profit Organisations (Campaign)

A China-linked espionage campaign targeted a U.S. non-profit organization engaged in influencing government policy, maintaining weeks of access in April 2025. The intrusion leveraged legitimate binaries for DLL sideloading and persistence, consistent with techniques observed i...

2025/11/5
阅读更多

TruffleNet Campaign Exploits AWS SES for Large-Scale Cloud Abuse and BEC Fraud (Campaign)

Researchers uncovered a coordinated campaign leveraging stolen AWS credentials to automate reconnaissance and abuse Amazon Simple Email Service (SES) for Business Email Compromise (BEC) operations. The attackers used a custom infrastructure dubbed TruffleNet, built around the ...

2025/10/31
阅读更多

Tata Motors Hardcoded AWS Keys and API Tokens Exposed (Research)

Security researcher Eaton Zveare disclosed that in 2023 multiple public-facing Tata Motors applications (notably the E-Dukaan marketplace and the FleetEdge fleet product) contained hardcoded or client-recoverable cloud credentials and API tokens that allowed access to hundreds...

2025/10/28
阅读更多

IIS Backdoor Exploiting Exposed ASP.NET Machine Keys (Campaign)

Initial access leverages IIS apps configured with reused/public machineKey (ValidationKey/DecryptionKey) values, enabling __VIEWSTATE deserialization to run arbitrary commands. Following foothold, REF3927 deploys Godzilla-family webshells (e.g., 1.aspx) and GotoHTTP for GUI ac...

2025/10/22
阅读更多

PassiveNeuron Campaign: Espionage Campaign Targeting Windows Server Environments (Campaign)

Attackers obtain remote code execution through abuse of SQL-server environments (exploitation, SQL injection, or credential compromise) and attempt to install web shells. When detection (e.g., endpoint AV) blocks the web-shell stage they escalate to a multi-stage DLL loader ch...

2025/10/21
阅读更多

F5 incident (Incident)

F5 disclosed a security incident in which a nation-state threat actor maintained persistent access to the company’s internal systems, including its BIG-IP product development and engineering knowledge management environments. The actor exfiltrated source code and information a...

2025/10/15
阅读更多

eBPF Rootkit Targeting AWS and Linux Environments (Campaign)

The infection began with the exploitation of a vulnerable Jenkins server (CVE-2024-238976), which enabled lateral movement into AWS EKS clusters. The threat actor deployed a malicious Docker image (kvlnt/vv) containing a Rust-based downloader (vGet) that retrieved an encrypted...

2025/10/14
阅读更多

Supply Chain Risk in Axis Autodesk Revit Plugin Due to Exposed Azure Storage Credentials and Revit RCE Vulnerabilities (Research)

researchers uncovered exposed Azure Storage Account credentials embedded in Axis Communications’ Autodesk Revit plugin, enabling unauthorized read/write access to cloud-hosted installers and RFA model files. When combined with multiple remote-code-execution (RCE) vulnerabiliti...

2025/10/8
阅读更多

“Crimson Collective” Claims Theft of Customer Data from Red Hat (Campaign)

An extortion group calling themselves "Crimson Collective" has claimed to have stolen nearly 570 GB of data from Red Hat's private GitLab repositories. Red Hat confirmed a security incident to BleepingComputer, saying "Red Hat is aware of reports regarding a security incident ...

2025/10/2
阅读更多

Cl0p Extortion Campaign Claims Theft via Oracle E-Business Suite (Campaign)

In an October 1st Bloomberg article, Halcyon, a cybersecurity company responding to a related incident, has stated that the attackers gained access to the data by compromising user emails and abusing the default password-reset function. On October 2nd, Oracle posted a statemen...

2025/10/2
阅读更多

Renewed "ArcaneDoor" Campaign Targeting 0-day Vulnerabilities in Cisco ASA (Campaign)

Cisco has reported exploitation in the wild of two 0-day vulnerabilities affecting Cisco Adaptive Security Appliance (ASA), CVE-2025-20333 and CVE-2025-20362, allowing RCE and local privilege escalation, respectively. NCSC and CISA have corroborated these reports, noting the u...

2025/9/26
阅读更多

BRICKSTORM Espionage Backdoor Targeting U.S. Tech and Legal Sectors (Campaign)

BRICKSTORM is a Go backdoor (with SOCKS proxying) deployed preferentially on Linux/BSD network and edge appliances that often lack EDR coverage. Attackers favor devices like VMware vCenter/ESXi as pivot points, using valid credentials harvested from appliances to move laterall...

2025/9/25
阅读更多

SonicWall MySonicWall Cloud Backup File Security Incident (Incident)

SonicWall has disclosed a security incident affecting its MySonicWall cloud backup service. Threat actors conducted brute force attacks on the MySonicWall.com portal and gained unauthorized access to a subset of firewall preference files. While fewer than 5% of firewall instal...

2025/9/25
阅读更多

Shai-Hulud: Ongoing Package Supply Chain Compromise Delivering Data-Stealing Malware (Campaign)

On September 15, 2025, malicious versions of multiple popular packages were published to npm with a post-install script that harvested sensitive developer assets and exfiltrated data to attacker-created public GitHub repos named Shai-Hulud. Wiz Research estimates that this act...

2025/9/15
阅读更多

Qix npm package supply chain compromise (Incident)

On September 8, 2025, malicious new versions of 18 popular npm packages maintained by a developer known as Qix (incl. debug@4.4.2, chalk@5.6.1) were published to npm. If those versions were pulled into a frontend build and served to users, the injected code runs in the browser...

2025/9/8
阅读更多

GhostAction campaign (Campaign)

On September 5, 2025, GitGuardian reported a campaign titled "GhostAction": attackers with write access to GitHub repositories - gained by an unknown initial access vector - added a malicious GitHub Actions workflow that exfiltrates CI/CD secrets via HTTP POST to an attacker-c...

2025/9/5
阅读更多

Compromised Salesloft Drift Tokens Enable Data Theft Across Integrations (Campaign)

Google Threat Intelligence Group report a widespread data-theft campaign abusing OAuth tokens tied to Salesloft Drift. Initially observed against Salesforce orgs (Aug 8–18, 2025), the scope now includes other Drift integrations: on Aug 9, a small number of Google Workspace mai...

2025/9/2
阅读更多

Storm-0501 Deploys Cloud-Based Ransomware (Campaign)

After attaining domain admin on-prem, Storm-0501 evaded visibility gaps (checking Defender services), moved laterally with Evil-WinRM, and performed DCSync. They compromised Entra Connect Sync servers, used the Directory Synchronization Account (DSA) to enumerate identities/re...

2025/8/28
阅读更多

Nx Package Supply Chain Compromise Delivers Data-Stealing Malware (Campaign)

The compromise introduced a malicious telemetry.js file triggered via a post-install script in the npm package. The payload executed only on Linux and macOS systems, systematically searching for sensitive files (wallets, keystores, .env, SSH keys) and extracting credentials (g...

2025/8/27
阅读更多

GENESIS PANDA's Cloud Intrusions: Persistent Control Plane Exploitation and Access Brokerage (Campaign)

GENESIS PANDA begins attacks by exploiting exposed services (e.g., Jenkins) and querying Instance Metadata Services (IMDS) on compromised cloud-hosted VMs to harvest credentials. With this access, the actor pivots into the cloud control plane, enabling actions like SSH access ...

2025/8/24
阅读更多

Silk Typhoon Exploiting Trusted Relationships for Cloud Environments Compromise (Campaign)

Silk Typhoon (a.k.a Murky Panda) achieves initial access primarily through exploiting internet-facing appliances (e.g., Citrix NetScaler ADC, CVE-2023-3519) and has also been observed compromising SOHO devices to mask activity. Once inside, the adversary deploys web shells suc...

2025/8/24
阅读更多

Salesloft Drift supply chain compromise (Incident)

On 2025-08-21, an incident was reported, involving UNC6395, gaining initial access via Unknown, to achieve Supply chain attack.

2025/8/21
阅读更多

Warlock Ransomware Exploiting Sharepoint Vulnerabilities (Campaign)

Warlock ransomware is exploiting Microsoft SharePoint vulnerabilities to infiltrate enterprise environments. Attackers gain initial access by uploading web shells through targeted HTTP POST requests, then escalate privileges via Group Policy abuse and compromised accounts. The...

2025/8/20
阅读更多

DripDropper Malware Exploits Patched Apache ActiveMQ for Persistence on Cloud Linux Systems (Campaign)

The attack chain begins with exploitation of the Apache ActiveMQ RCE vulnerability (CVE-2023-46604) on cloud Linux hosts. Upon gaining access, the attacker installs the Sliver C2 implant and modifies sshd settings to permit root login over SSH, then downloads and executes the ...

2025/8/19
阅读更多

UAT-7237 Targets Taiwanese Web Infrastructure Using Customized Open-Source Tools (Campaign)

Researchers uncovered a sophisticated intrusion by UAT-7237, a Chinese-speaking APT group active since at least 2022 and likely a subgroup of UAT-5918. The group recently compromised a Taiwanese web hosting provider, targeting its VPN and cloud infrastructure. Unlike its paren...

2025/8/18
阅读更多

Akira Ransomware Targeting Critical Vulnerability in SonicWall SSLVPN (Campaign)

Researchers identified active exploitation of CVE-2024-40766 in SonicWall's seventh-generation firewalls, specifically impacting SSL VPN functionality. Threat actors are bypassing multi-factor authentication (MFA), gaining privileged access, and deploying Akira ransomware. The...

2025/8/6
阅读更多

Plague PAM-Based Backdoor for Linux (Campaign)

A newly discovered Linux backdoor, dubbed Plague, was embedded as a malicious PAM (Pluggable Authentication Module) component. Designed to silently bypass system authentication, Plague grants attackers persistent SSH access while evading all known antivirus detection and leavi...

2025/8/4
阅读更多

Auto-Color Malware Exploits SAP Vulnerability for Linux Backdoor (Campaign)

In April 2025, a threat actor exploited CVE-2025-31324, a critical vulnerability in SAP NetWeaver, to deploy the Auto-Color backdoor malware on a US-based chemical company's network. The intrusion began with suspicious ZIP file downloads and DNS tunneling to test exploitabilit...

2025/7/29
阅读更多

AWS CodeBuild Vulnerability Allows Build Process Secrets Extraction (Research)

The vulnerability in AWS CodeBuild arises when a source code repository is configured to trigger builds based on pull requests or other actions from untrusted contributors. In such cases, an attacker can submit a pull request containing arbitrary code, which is then executed i...

2025/7/23
阅读更多

Soco404 Cryptomining Campaign Exploits PostgreSQL and Cloud Misconfigurations (Campaign)

Wiz Research has uncovered an ongoing, sophisticated cryptomining campaign dubbed Soco404, which targets both Linux and Windows systems in cloud environments. The campaign exploits exposed PostgreSQL instances and vulnerable Apache Tomcat servers to achieve initial access, the...

2025/7/23
阅读更多

Mimo Targets Magento, Docker, and Cloud Environments (Campaign)

The threat actor known as Mimo (or Mimo’lette) has expanded its intrusion operations from Craft CMS to the Magento ecommerce platform, Docker environments, and cloud instances. Mimo exploits PHP-FPM vulnerabilities in Magento to gain initial access, establishes persistence usi...

2025/7/21
阅读更多

Supply Chain Attack on npm Packages via Maintainer Phishing (Campaign)

A phishing attack targeting a popular npm maintainer led to the compromise of several widely used packages, including eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, and others. The attacker stole the maintainer’s npm token via a spoofed email and used it ...

2025/7/20
阅读更多

0day Vulnerability in Microsoft Sharepoint Exploited in-the-Wild (Campaign)

Microsoft has disclosed two actively exploited zero-day vulnerabilities in on-premises SharePoint Server—CVE-2025-53770 (RCE via unsafe deserialization) and CVE-2025-53771 (authentication bypass via Referer header spoofing). These flaws form a chained exploit known as ToolShel...

2025/7/20
阅读更多

Linuxsys Cryptominer Campaign (Campaign)

The Linuxsys cryptominer is part of a long-running campaign active since at least 2021, consistently exploiting multiple web application vulnerabilities to deploy the Linuxsys coinminer on compromised systems. The attacker utilizes a stable methodology: exploiting n-day vulner...

2025/7/17
阅读更多

AWS Network Exploitation and Ransomware Detonation (Campaign)

AWS customer faced a compromise through a SonicWall SMA 500v EC2 instance that was improperly exposed to the internet. The attacker connected via multiple Vultr VPS endpoints, performed network scans, and moved laterally between EC2 instances using RDP. Over 700 GB of data was...

2025/7/8
阅读更多

AWS Data Exfiltration and Attempted Ransomware (Campaign)

In February 2025, a UK-based AWS environment was infiltrated using compromised VPN credentials. The threat actor conducted internal reconnaissance with Nmap and staged data exfiltration using the Rclone tool, transferring sensitive files from AWS file servers, particularly fin...

2025/7/8
阅读更多

Azure Account Hijack via Stolen Tokens (Campaign)

In early 2024, a Darktrace customer’s Azure environment was compromised after attackers stole access tokens linked to an external consultant’s account, obtained via cracked software. Using these tokens, the attacker authenticated into the Azure environment, modified security r...

2025/7/8
阅读更多

In-Memory IIS Attacks via View State Deserialization (Campaign)

Unit 42 researchers uncovered a campaign by a threat actor they call TGR-CRI-0045—assessed with medium confidence to be part of the Gold Melody (UNC961/Prophet Spider) group—targeting ASP.NET IIS servers using compromised Machine Keys. This group, acting as an Initial Access B...

2025/7/8
阅读更多

UNC5174 Exploits Ivanti CSA Zero-Days in “Houken” Campaign (Campaign)

The attacker chained Ivanti CSA zero-days to execute a base64-encoded Python script, which extracted the admin password from a local PostgreSQL database. Using this access, the attacker created or modified PHP scripts to serve as webshells and sometimes deployed a custom Linux...

2025/7/3
阅读更多

JDWP Exploited in the Wild (Campaign)

On 2025-07-02, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting JDWP, TeamCity to achieve Resource hijacking. The following tools were observed: XMRig.

2025/7/2
阅读更多

Linux SSH Servers Compromised to Deploy Proxies (Campaign)

In one attack chain, a Bash script retrieved from 0x0[.]st was used to install TinyProxy via common package managers like apt, yum, or dnf. The script then modified configuration files to allow unrestricted external access (Allow 0.0.0.0/0), exposing the proxy service on port ...

2025/6/30
阅读更多

Attacks on Korean IIS & Linux Servers (Campaign)

In June 2025 researchers documented a campaign that breaches vulnerable South-Korean IIS web servers—and sometimes adjacent Linux hosts—by uploading ASP/ASPX web shells through file-upload flaws. Once the shell is in place, the operators fan out: they run basic host discovery ...

2025/6/25
阅读更多

Langflow Vulnerability Exploited to Deliver Flodrix Botnet (Campaign)

CVE-2025-3248 is an unauthenticated remote code execution (RCE) vulnerability in Langflow, a popular Python-based framework for building AI applications. The flaw lies in the code validation endpoint, which fails to enforce authentication or sandboxing when parsing and executi...

2025/6/17
阅读更多

SFireTruck: Malicious JavaScript Campaign Using Obfuscation (Campaign)

Researchers uncovered a large-scale malvertising campaign, active primarily between March 26 and April 25, 2025, during which over 269,000 legitimate websites were compromised with highly obfuscated JavaScript code dubbed “JSFireTruck” (a euphemism for JSF*ck). Using only six ...

2025/6/12
阅读更多

TeamFiltration Account Takeover Campaign (Campaign)

On 2025-06-11, a campaign was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Password spraying, Resource enumeration, targeting Microsoft OneDrive, Microsoft Outlook, Microsoft Teams to achieve Data exfiltration. The following tools were observed: TeamFiltration.

2025/6/11
阅读更多

NPM Supply Chain Attack Compromises 16 Popular React Native and GlueStack Packages (Campaign)

A threat actor compromised 16 highly popular React Native and GlueStack packages, collectively downloaded over a million times weekly. The attackers inserted a stealthy backdoor into these packages using whitespace obfuscation to hide malicious code. The payload is a Remote Ac...

2025/6/7
阅读更多

Open WebUI Misconfiguration Exploited for Cryptojacking (Campaign)

Researchers discovered an active exploitation of a misconfigured Open WebUI instance—a self-hosted interface for large language models (LLMs)—that was exposed to the internet with administrator access enabled and no authentication. A threat actor leveraged this misconfiguratio...

2025/6/3
阅读更多

Cryptojacking Campaign Targets Misconfigured DevOps Tools (Campaign)

JINX-0132 targets exposed Nomad servers lacking ACL protections by submitting malicious jobs through the API, effectively gaining remote code execution. These jobs download and run the XMRig miner from public GitHub releases, bypassing traditional IOC-based detection. Gitea in...

2025/6/2
阅读更多

Earth Lamia Custom Toolkit Targets Multiple Sectors via Web Vulnerabilities (Campaign)

Earth Lamia, a suspected China-nexus APT group active since at least 2023, has expanded its cyber espionage campaigns across Brazil, India, and Southeast Asia. The group targets multiple industries — shifting from financial services to logistics, online retail, and currently I...

2025/5/29
阅读更多

DragonForce Exploits SimpleHelp Vulnerabilities in Ransomware Campaign (Campaign)

DragonForce gained access to an MSP’s SimpleHelp instance and weaponized its remote management capabilities to deliver a malicious installer to client environments. Once executed, the installer enabled credential harvesting, network reconnaissance, and ransomware deployment. T...

2025/5/28
阅读更多

Coordinated One-Day Cloud Scanning Operation Targets 75 Exposure Points (Campaign)

On May 8, 2025, GreyNoise observed a tightly coordinated and large-scale reconnaissance campaign launched from 251 malicious IP addresses, all hosted on Amazon AWS and geolocated in Japan. These IPs were active for only one day and collectively triggered 75 distinct scanning b...

2025/5/28
阅读更多

Mimo Exploits Craft CMS RCE to Deploy Cryptominer and Proxyware in Coordinated Campaign (Campaign)

Between February and May 2025, the intrusion set known as Mimo exploited CVE-2025-32432, a critical unauthenticated RCE in Craft CMS, to deploy a multi-stage infection chain observed via honeypots. The attack began by injecting a PHP webshell through a crafted GET request, fol...

2025/5/27
阅读更多

Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild (Campaign)

Wiz Threat Research has confirmed active in-the-wild exploitation of a vulnerability chain in Ivanti Endpoint Manager Mobile (EPMM), comprising CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (post-auth RCE). Exploited together, these flaws enable unauthenticated remot...

2025/5/20
阅读更多

UTG-Q-015 Exploits 0-Days for Espionage in Asia (Campaign)

UTG-Q-015, a Southeast Asia-based threat actor, escalated its operations in early 2025 by shifting to more aggressive tactics. Initially exposed in December 2024 for mounting attacks on Chinese developer forums, UTG-Q-015 evolved to exploit both 0-day and N-day vulnerabilities...

2025/5/19
阅读更多

From stolen cloud key to persistence-as-a-service (Incident)

A recent incident revealed attacker activity stemming from a leaked long-term AWS access key (AKIA*) belonging to a user in an organization’s AWS management account. Over a 150-minute period, five IP addresses abused the credentials to perform both well-known and novel cloud a...

2025/5/13
阅读更多

RedisRaider Linux Cryptojacking Campaign Targets Redis Servers (Campaign)

RedisRaider begins by indiscriminately scanning the IPv4 space for Redis servers open on port 6379. Upon identifying a target, the malware checks the server OS and uses Redis commands to inject a base64-encoded shell script as a cron job. It writes this payload to disk by reco...

2025/5/8
阅读更多

ComfyUI exploitation campaign (Campaign)

Baidu reports an exploitation campaign targeting publicly-exposed instances of ComfyUI. ComfyUI provides a GUI for AI image generation workflows. By default, it does not implement authentication. A popular extension, ComfyUI-Manager, allows an attacker to execute remote code v...

2025/5/6
阅读更多

Supply Chain Compromise of (Campaign)

Researchers detected a malicious update to the popular npm package rand-user-agent, used for generating randomized user-agent strings. The attacker published multiple unauthorized versions (1.0.110, 2.0.83, 2.0.84) containing heavily obfuscated code designed to covertly instal...

2025/5/5
阅读更多

xAI leaked API key (Research)

A security lapse at xAI, led to the exposure of a private API key on GitHub by a company employee. The leaked credential, discovered by Philippe Caturegli and validated by GitGuardian, provided access to at least 60 private and unreleased large language models (LLMs), includin...

2025/5/1
阅读更多

Larva-25003: IIS Native Module Malware Used in Targeted Web Server Attacks (Campaign)

In early 2025, AhnLab Security Intelligence Center (ASEC) discovered a targeted attack campaign dubbed Larva-25003, believed to be operated by Chinese-speaking threat actors. The attackers gained access to poorly secured Microsoft IIS web servers in South Korea and deployed a ...

2025/4/30
阅读更多

Node.js repository CI/CD vulnerable to RCE (Research)

A security researcher uncovered a critical vulnerability in the Node.js CI/CD pipeline that allowed for remote code execution on internal Jenkins agents and posed a significant supply chain risk. The attack stemmed from how Node.js orchestrated workflows using GitHub Actions, ...

2025/4/30
阅读更多

Grafana GitHub Action attempted supply chain attack (Incident)

Grafana Labs detected suspicious activity via a triggered canary token, leading to the discovery of unauthorized access enabled by a misconfigured GitHub Action. An attacker exploited the workflow by forking a Grafana repository, injecting a malicious curl command to extract e...

2025/4/27
阅读更多

Password spray attack leads to containers being used for cryptomining (Campaign)

In the past year Microsoft observed AzureChecker(Storm-1977) launching password spray attacks, against cloud tenants in the education sector. The actor used AzureChecker.exe (CLI tool that is being used by a wide range of actors)

2025/4/23
阅读更多

Hybrid attack discovered by Mandiant (Incident)

During an investigation, Mandiant identified evidence that a threat actor had discovered cloud access keys stored in plain text on a compromised on-premises network. The threat actor was able to use the keys to access and steal data from the client’s cloud storage buckets. Whe...

2025/4/23
阅读更多

Apache Druid cryptojacking (Campaign)

ARMO’s research team uncovered two cryptojacking campaigns targeting a deliberately exposed Kubernetes honeypot running Apache Druid, leveraging the known CVE-2021-25646 vulnerability for unauthenticated remote code execution. The first campaign, linked to the RUDEDEVIL/LUCIFE...

2025/4/23
阅读更多

Apache Druid cryptojacking (Campaign)

ARMO’s research team uncovered two cryptojacking campaigns targeting a deliberately exposed Kubernetes honeypot running Apache Druid, leveraging the known CVE-2021-25646 vulnerability for unauthenticated remote code execution. The first campaign, linked to the RUDEDEVIL/LUCIFE...

2025/4/23
阅读更多

SAP NetWeaver Visual Composer exploitation campaign (Campaign)

CVE-2025-31324 is a critical zero-day vulnerability in the SAP NetWeaver Visual Composer component (CVSS 10.0) that enables unauthenticated remote code execution (RCE). The flaw, caused by missing authorization checks in the Metadata Uploader interface, allows attackers to upl...

2025/4/22
阅读更多

Multi-Layered Cryptojacking via Docker (Campaign)

A recent malware campaign targeting Docker showcases a novel form of cryptojacking that abuses legitimate Web3 services for profit while employing heavy layers of obfuscation to evade detection. By leveraging publicly hosted Docker images, the attackers deploy Python scripts t...

2025/4/22
阅读更多

Rspack supply chain attack (Incident)

Researchers uncovered a supply chain attack carried out by a threat actor labeled MUT-1692. Initially detected via a suspicious npm package (argus3-test) mimicking a legitimate tool, the investigation revealed a postinstall script that attempted to connect to a remote C2 serve...

2025/4/17
阅读更多

UNC5174 Linux Espionage Campaign (Campaign)

UNC5174, a suspected Chinese state-sponsored threat actor, has resurfaced in a stealthy espionage campaign targeting Linux systems across research institutions, government agencies, NGOs, and critical infrastructure sectors in Western and APAC countries. The campaign, active s...

2025/4/16
阅读更多

CrazyHunter Ransomware Group Targets Critical Sectors in Taiwan (Campaign)

CrazyHunter is a newly emerged ransomware group that has rapidly gained attention for its focused attacks on Taiwan’s critical sectors, particularly healthcare, education, and manufacturing. The group’s operations demonstrate a high level of sophistication, leveraging both adv...

2025/4/16
阅读更多

AWS Breach at a SaaS Company (Incident)

an AWS security breach that severely impacted a growing SaaS company. An attacker gained access to administrator-level credentials and exploited architectural flaws to compromise both staging and production environments. The incident led to data exfiltration, deletion of criti...

2025/4/15
阅读更多

BPFDoor’s Hidden Controller Targets AMEA Sectors (Campaign)

Trend Micro uncovered a previously unseen controller used in BPFDoor campaigns, attributing it to Earth Bluecrow (also known as Red Menshen), a state-sponsored APT group. BPFDoor is a stealthy Linux backdoor leveraging Berkeley Packet Filtering (BPF) to silently activate via "...

2025/4/14
阅读更多

Atlas Lion Campaign Exploits Device Enrollment and MFA for Persistence (Campaign)

The initial intrusion vector was an SMS phishing campaign that spoofed internal IT notifications to harvest user credentials and MFA codes. Atlas Lion then enrolled a VM from their Azure tenant into the organization’s domain by mimicking the legitimate Windows device setup pro...

2025/4/10
阅读更多

Long-Term Email Breach at OCC Exposes Sensitive Bank Oversight Data (Incident)

Hackers infiltrated the Office of the Comptroller of the Currency (OCC) and monitored email accounts of approximately 103 bank regulators for over a year, accessing around 150,000 sensitive messages. The attackers gained entry via an administrative account, allowing them to ob...

2025/4/8
阅读更多

Europecar Gitlab Breach (Incident)

A hacker breached the GitLab repositories of Europcar Mobility Group and stole source code for Android and iOS apps, along with SQL backups and configuration files that included personal data. The attacker, using Europcar’s name as an alias, claimed to have extracted over 9,00...

2025/4/4
阅读更多

Critical Ivanti Connect Secure Vulnerability Exploited by China-linked Actor (Campaign)

On April 3, 2025, Ivanti disclosed a critical vulnerability, CVE-2025-22457, affecting Ivanti Connect Secure (ICS) VPN appliances version 22.7R2.5 and earlier. The flaw, initially underestimated as a denial-of-service risk, was later found to be a buffer overflow that allows r...

2025/4/3
阅读更多

Weaver Ant data exfiltration campaign (Campaign)

Sygnia uncovered a prolonged cyber-espionage campaign targeting a major Asian telecom provider, orchestrated by a China-nexus APT group dubbed Weaver Ant. The group maintained stealthy, long-term access to the network for over four years using advanced techniques centered arou...

2025/3/24
阅读更多

Albabat Ransomware Targets Windows, Linux, and macOS Using GitHub Infrastructure (Campaign)

Researchers have uncovered new and evolving versions of the Albabat ransomware, which now target Windows, Linux, and macOS systems. These updated variants (v2.0.0 and v2.5) show a notable expansion from the ransomware’s initial Windows-only focus and use GitHub for storing and...

2025/3/21
阅读更多

Oracle Cloud Potential Supply Chain Breach (Incident)

On March 21, 2025, CloudSEK reported that a threat actor using the alias "rose87168" is claiming to have exfiltrated over 6 million records from Oracle Cloud’s SSO and LDAP systems. According to CloudSEK’s assessment, the leaked data includes sensitive authentication materials...

2025/3/21
阅读更多

Exposed Jupyter Notebooks Targeted for Cryptomining (Campaign)

Cado Security Labs has uncovered a cryptomining campaign exploiting misconfigured Jupyter Notebooks, affecting both Windows and Linux environments. The attackers use Jupyter as an entry point to deploy a cryptominer through a series of evasive techniques. On Windows, the attac...

2025/3/16
阅读更多

tj-actions/changed-files supply chain attack (Incident)

The compromised version of tj-actions/changed-files injects malicious code into CI workflows, potentially capturing and exposing secrets from affected repositories. On public repositories, the secrets would then be visible to everyone as part of the workflow logs, though obfus...

2025/3/15
阅读更多

CDC dangling domain hijack (Incident)

Attackers exploited poor DNS hygiene at the U.S. Centers for Disease Control and Prevention (CDC) to deliver malicious content disguised under the CDC’s trusted domain. The attack was discovered when users searching for English Premier League match streams encountered links th...

2025/3/10
阅读更多

PHP-CGI Vulnerability Exploited in Attacks Targeting Japan (Campaign)

Researchers identified an ongoing attack campaign targeting organizations in Japan across sectors like technology, telecommunications, education, entertainment, and e-commerce. Active since at least January 2025, the attacker exploits CVE-2024-4577, a critical PHP-CGI remote c...

2025/3/6
阅读更多

Silk Typhoon Targeting IT and Cloud Applications (Campaign)

Microsoft Threat Intelligence has identified an evolution in the tactics of Silk Typhoon, a Chinese state-sponsored espionage group, now increasingly focusing on compromising IT solutions, remote management tools, and cloud applications to gain initial access. By exploiting un...

2025/3/5
阅读更多

Zapier data breach (Incident)

On February 27, 2025, Zapier detected that an unauthorized user had accessed some of its internal code repositories due to a two-factor authentication (2FA) misconfiguration on an employee’s account. While the breach did not affect production systems, databases, or payment inf...

2025/3/1
阅读更多

JavaGhost SES abuse (Campaign)

The threat group JavaGhost has evolved from website defacement to persistent phishing operations targeting cloud environments, particularly AWS. Between 2022 and 2024, JavaGhost leveraged exposed long-term AWS access keys due to customer misconfigurations. These keys allowed t...

2025/2/28
阅读更多

CPU_HU: Malicious Campaign Targeting Misconfigured PostgreSQL Servers for Cryptomining (Incident)

Wiz Threat Research identified a malicious campaign targeting weakly configured and publicly exposed PostgreSQL servers to deploy a XMRig-C3 cryptominer. In observed attacks, the threat actor exploited exposed PostgreSQL instances, abused the COPY FROM PROGRAM function to exec...

2025/2/27
阅读更多

ByBit hack (Incident)

On February 21, 2025, Safe{Wallet} suffered a state-sponsored attack, attributed to TraderTraitor (UNC4899), a DPRK-affiliated group. The attackers compromised a developer’s laptop, hijacked AWS session tokens, and bypassed MFA to gain unauthorized access to Safe{Wallet} serve...

2025/2/26
阅读更多

Krpano XSS exploitation campaign (Campaign)

The "360XSS" campaign is a widespread exploitation of a reflected cross-site scripting (XSS) vulnerability in the popular virtual tour framework Krpano, which allows external XML content to be injected via the xml query parameter. The vulnerability, known as CVE-2020-24901, st...

2025/2/26
阅读更多

Teammate App exposed MongoDB (Research)

A researcher discovered that Teammate App had an exposed database containing nearly 3 million records, including user credentials, employee details, and confidential documents, accessible without authentication. The researcher flagged this issue in December 2024 and formally n...

2025/2/24
阅读更多

RevivalStone Campaign by Winnti (Campaign)

The China-linked APT group Winnti (APT41) has been linked to a new cyber espionage campaign, RevivalStone, targeting Japanese manufacturing, materials, and energy companies in March 2024. The attack, detailed by LAC, exploited an SQL injection vulnerability in an unspecified E...

2025/2/18
阅读更多

Earth Preta’s Campaign Abusing MAVInject to Bypass Detection (Campaign)

Earth Preta (Mustang Panda), a known APT group targeting government entities in the Asia-Pacific region, has been observed using a new technique to evade detection and maintain persistence. Researchers from Trend Micro discovered that the group leverages Microsoft Application ...

2025/2/18
阅读更多

Seashell Blizzard Subgroup's Campaign Exploiting Vulnerabilities for Data Exfiltration (Campaign)

The BadPilot campaign operates as a horizontally scalable cyber operation, compromising a wide range of internet-facing systems using publicly available exploits. The subgroup conducts broad scanning for vulnerable systems and leverages commodity exploits to infiltrate network...

2025/2/13
阅读更多

Code Injection Attacks Exploiting Publicly Disclosed ASP.NET Keys (Campaign)

Microsoft Threat Intelligence identified a threat actor exploiting publicly disclosed ASP.NET machine keys to perform ViewState code injection attacks. This technique enables attackers to inject malicious code into web applications, leading to remote code execution on IIS serv...

2025/2/12
阅读更多

Black Basta Exploiting Vulnerabilities in Multiple Products (Campaign)

A major leak of Black Basta’s internal chat logs on February 11, 2025, has exposed significant internal conflicts, leadership instability, and financial fraud within the ransomware group. The leak, allegedly triggered by their attacks on Russian banks, has led to a decline in ...

2025/2/11
阅读更多

Malicious AI Models Bypass Picklescan Detection (Campaign)

The nullifAI attack exploits Pickle file serialization, an insecure method for storing ML models, to distribute malware-laced PyTorch models on Hugging Face. Instead of using PyTorch’s default ZIP compression, the attackers compressed the models using 7z, preventing automatic ...

2025/2/9
阅读更多

From social engineering to Lambda modification (Incident)

Researchers discovered a sophisticated attack initiated through social engineering on LinkedIn and WhatsApp, leading to credential theft via seemingly benign code downloads. With stolen session tokens and cloud access keys, the attackers authenticated into Microsoft 365 and AW...

2025/2/3
阅读更多

USAID cryptojacking incident (Incident)

The U.S. Agency for International Development (USAID) was hit by a cryptojacking attack. A global administrator account in a test environment within their Azure subscription was compromised as a result of a password spray attack. The attackers then leveraged the compromised ac...

2025/1/31
阅读更多

DogWifTool supply chain attack (Incident)

Hackers compromised the Windows version of DogWifTools, a platform for promoting meme coins on the Solana blockchain, through a supply-chain attack that led to the theft of users' cryptocurrency wallets.The attack occurred after a threat actor reverse-engineered the software a...

2025/1/29
阅读更多

Operation LongFang (Campaign)

Operation LongFang is a cyber-espionage campaign, attributed to a Chinese threat actor, targeting Latin American government entities. First detected in December 2024, it has been active for at least two years. The campaign's initial access was achieved by exploiting vulnerabil...

2025/1/24
阅读更多

MasterCard Fixes Five-Year-Old DNS Typo Misconfiguration (Incident)

MasterCard recently corrected a significant DNS misconfiguration that had persisted for nearly five years, potentially allowing cybercriminals to intercept or divert its Internet traffic. While all MasterCard's DNS server names were supposed to end with "akam.net," one contain...

2025/1/22
阅读更多

TRIPLESTRENGTH: Cloud Account Hijacking and Cryptocurrency Mining via Stolen Credentials (Campaign)

The threat actor TRIPLESTRENGTH uses stolen credentials and cookies, partially sourced from Racoon infostealer logs, to gain unauthorized access to victim cloud environments. Initially, they exploited legitimate compromised accounts to create compute resources for cryptocurren...

2025/1/21
阅读更多

UNC2165 Targets Hybrid Environments with Ransomware (Campaign)

In 2024, UNC2165 exploited a victim's environment by a UNC1543 FAKEUPDATES infection to gain initial access. They deployed their Python tunneler, VIPERTUNNEL, for persistent access and used utility scripts for reconnaissance and disabling anti-virus protection. UNC2165 then ac...

2025/1/21
阅读更多

Otelier data breach (Incident)

An Otelier employee's workstation was infected with an infostealer, leading to compromise of their Jira credentials. The threat actor abused these to gain access to the Jira server, which contained additional credentials granting access to S3 buckets, which contained various d...

2025/1/17
阅读更多

Bapak Exploiting Stolen Cloud Access Keys (Campaign)

Wiz Threat Research discovered a malicious campaign where attackers are using leaked or stolen cloud access keys to access cloud environments and deploy ECS clusters. The attacker was observed abusing accidentally exposed AWS access keys and trying to gain a permanent foothold...

2025/1/15
阅读更多

Codefinger Ransomware Campaign Targeting S3 Buckets (Campaign)

Researchers discovered a ransomware campaign leveraging AWS Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data in Amazon S3 buckets. The attack, orchestrated by the threat actor "Codefinger," uses compromised AWS credentials to encrypt files securely. V...

2025/1/13
阅读更多

Exploitation in the Wild of Aviatrix Controller RCE (Campaign)

The vulnerability CVE-2024-50603 was disclosed on 2025-01-07, with a detailed blog and proof-of-concept exploit released by researchers soon after. Evidence of exploitation in cloud environments were observed by Wiz Research, targeting publicly exposed, vulnerable machines. At...

2025/1/11
阅读更多

Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls (Campaign)

Threat actors recently targeted Fortinet FortiGate firewall devices with exposed management interfaces in a suspected zero-day campaign. Arctic Wolf observed unauthorized admin logins via the jsconsole interface, new account creation, SSL VPN configurations, and other system c...

2025/1/10
阅读更多

Gravy Analytics data breach (Incident)

On 2025-01-10, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, to achieve Data exfiltration.

2025/1/10
阅读更多

Kong image compromise (Incident)

Kong Ingress Controller is a popular ingress controller for Kubernetes. The Kong Ingress Controller version 3.4 instances have been experiencing a significant performance regression causing excessive CPU utilization of approximately 4 cores, even with minimal Gateway API reso...

2025/1/2
阅读更多

US Treasury Breach (Incident)

In December 2024, the U.S. Department of the Treasury experienced a cybersecurity breach due to a compromised API key from BeyondTrust’s Remote Support SaaS. A Chinese state-sponsored Advanced Persistent Threat (APT) actor exploited the stolen key to bypass security measures, ...

2024/12/31
阅读更多

Volkswagen massive data leak through Spring Boot Actuator misconfiguration (Incident)

Researchers found a data exposure issue within Volkswagen’s environment by leveraging tools such as Subfinder, GoBuster, and Spring. Using these tools, they found a Java Spring application exposing its Heap dump file. Heap dumps, which list various objects within a Java Virtua...

2024/12/30
阅读更多

EC2 Grouper Campaign (Campaign)

The "EC2 Grouper" threat actor is a prolific group frequently detected in cloud environments. They are known for using consistent user agents and a specific security group naming convention (e.g., ec2group, ec2group12345) during attacks, making them easier to identify. However...

2024/12/30
阅读更多

ZAGG customer data compromised via hijacked FreshClicks BigCommerce app (Incident)

On 2024-12-28, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.

2024/12/28
阅读更多

Phishing campaign leading to Azure account takeover (Campaign)

In June 2024, Unit 42 researchers identified a phishing campaign targeting approximately 20,000 users in European automotive, chemical, and industrial compound manufacturing sectors, particularly in Germany and the UK. The attackers employed fake forms created with HubSpot's F...

2024/12/18
阅读更多

Diicot Campaign Targeting Linux Environments (Campaign)

Wiz Research uncovered a sophisticated malware campaign by the Romanian-speaking Diicot threat group targeting Linux systems, especially in cloud environments. This campaign demonstrates notable advancements over previous iterations, such as corrupted UPX headers, cloud-specif...

2024/12/17
阅读更多

RCE Vulnerability in Apache Struts Targeted by Attackers (Campaign)

CVE-2024-53677 is a critical vulnerability in Apache Struts 2 with a CVSS score of 9.5. This flaw in the file upload logic allows path traversal and uploading of malicious files, enabling remote code execution (RCE). Exploitation has been observed in the wild using public proo...

2024/12/17
阅读更多

PHP Targeted with Glutton backdoor (Campaign)

The Glutton backdoor, a modular PHP-based malware framework, has been observed targeting systems in China, the U.S., Cambodia, Pakistan, and South Africa. The malware, linked with moderate confidence to the Chinese nation-state group Winnti, showcases unique behavior by target...

2024/12/16
阅读更多

LLM Hijacking Targeting AWS (Campaign)

On November 26, 2024, Wiz Threat Research identified JINX-2401, a threat actor attempting to hijack LLM models in multiple AWS environments using compromised IAM credentials. The attackers leveraged compromised IAM user keys to gain access, perform privilege escalation, and es...

2024/12/15
阅读更多

Cleo Vulnerabilities Targeted by Cl0p Ransomware (Campaign)

Two critical vulnerabilities in Cleo file transfer software—CVE-2024-50623 and CVE-2024-55956—have been actively exploited, leading to unauthorized data access and system compromise. The Clop ransomware gang has claimed responsibility for these attacks, leveraging zero-day exp...

2024/12/15
阅读更多

Byte Federal Data Breach via Gitlab Vulnerability (Incident)

Byte Federal, the largest US Bitcoin ATM operator, experienced a data breach in November 2024, exposing the sensitive data of 58,000 customers. Hackers exploited an unspecified GitLab vulnerability to gain unauthorized access to Byte Federal's servers. The compromised informat...

2024/12/12
阅读更多

Attacks abusing Amazon SES (Incident)

Datadog researchers identified an intrusion targeting Amazon Simple Email Service (SES) in an AWS environment, where attackers employed advanced persistence techniques. The attack was notable for leveraging an external AWS account to assume roles within the victim's environmen...

2024/12/11
阅读更多

State-Sponsored APT Abuse Visual Studio Code in Attacks (Campaign)

Operation Digital Eye, a suspected China-nexus cyberespionage campaign, targeted business-to-business IT service providers in Southern Europe from late June to mid-July 2024. The attacks aimed to establish strategic footholds for further compromise of downstream entities. Thre...

2024/12/5
阅读更多

Ultralytics compromise (Incident)

Ultralytics is a popular AI image prediction library with over 33k stars on GitHub and a dependency for many packages. On December 5, 2024 security researchers have identified a supply chain attack targeting deployment versions of the Ultralytics Python package. The compromise...

2024/12/5
阅读更多

Solana web3.js Supply Chain Attack (Campaign)

On December 3, 2024, a critical supply chain attack was uncovered targeting versions 1.95.6 and 1.95.7 of the widely-used @solana/web3.js JavaScript library. The attack involved a malicious backdoor injected via a compromised npm publish account. Once deployed, the backdoor ca...

2024/12/4
阅读更多

Gafgyt Malware Targeting Misconfigured Docker Servers (Campaign)

Researchers identified threat actors leveraging misconfigured Docker Remote API servers to deploy the Gafgyt malware, traditionally targeting IoT devices, to perform DDoS attacks. Attackers exploit these misconfigurations to create Docker containers, elevate privileges, and ex...

2024/12/3
阅读更多

Mauri Ransomware Exploiting Apache ActiveMQ (Campaign)

CVE-2023-46604 is a critical Remote Code Execution (RCE) vulnerability in Apache ActiveMQ. This vulnerability may allow a remote attacker with network access to a broker to run arbitrary commands due to an insecure deserialization in the OpenWire protocol.The vulnerability is ...

2024/12/2
阅读更多

Gelsemium’s Shift to Linux Malware with WolfsBane and FireWood (Campaign)

ESET researchers have identified two Linux backdoors, WolfsBane and FireWood, linked to the China-aligned Gelsemium APT group. WolfsBane is the Linux counterpart of Gelsevirine, a Windows backdoor, and is attributed to Gelsemium with high confidence due to shared features like...

2024/11/21
阅读更多

Sports Piracy Exploiting Misconfigured Jupyter Servers (Campaign)

Threat actors have developed an attack leveraging misconfigured JupyterLab and Jupyter Notebook servers to conduct illegal live streaming of sports events. By exploiting unauthenticated access to these environments, attackers deploy the open-source tool ffmpeg to capture and r...

2024/11/19
阅读更多

Earth Kasha’s Campaign Exploiting Fortinet Vulnerability (Campaign)

Researchers discovered a new campaign by Earth Kasha, a threat group targeting Japan, Taiwan, and India since 2019, with connections to the broader APT10 umbrella. This recent campaign, beginning in 2023, employs updated TTPs, including exploiting vulnerabilities like CVE-2023...

2024/11/19
阅读更多

BrazenBamboo Weaponizes FortiClient Vulnerability to Steal Credentials (Campaign)

A zero-day vulnerability in Fortinet's Windows VPN client, FortiClient, was discovered by Volexity, allowing user credentials to remain in process memory after authentication. This vulnerability was exploited by BrazenBamboo, a Chinese state-affiliated threat actor, using a pl...

2024/11/15
阅读更多

RCE Vulnerability in PAN-OS Exploited in-the-Wild (Campaign)

Palo Alto Networks has confirmed the active exploitation of a critical remote code execution vulnerability (CVE-2024-0012) in the PAN-OS management interface. This vulnerability allows an unauthenticated attacker with network access to the management interface to bypass authen...

2024/11/8
阅读更多

Silent Skimmer Attacks Exploiting Telerik UI to Steal Payment Data (Campaign)

In May 2024, researchers observed an attack by the Silent Skimmer threat actor, targeting a multinational organization’s payment infrastructure. This attack exploited known vulnerabilities in Telerik UI to gain unauthorized access and deploy various malicious tools, including ...

2024/11/7
阅读更多

Mozi Botnet Using AndroxGh0st Toolkit to Target Cloud Environments (Campaign)

Researchers at CloudSEK’s Threat Research team identified major developments in the Androxgh0st toolkit, expanding its arsenal of vulnerabilities, and noticed a potential operational integration with the Mozi botnet. First observed in early 2024, Androxgh0st integrates Mozi’s ...

2024/11/6
阅读更多

Supply Chain Attack on lottie-player (Campaign)

On October 30, 2024, a supply chain attack was initiated against the popular JavaScript library lottie-player, injecting malicious code that populates a Web3 wallet connection prompt on legitimate websites using the library, potentially targeting prominent cryptocurrency platf...

2024/10/31
阅读更多

Cyberoam breach (2018) (Incident)

On 2024-10-31, an incident was reported, involving Volt Typhoon, APT31, APT41, gaining initial access via Unknown, while using SSM misconfiguration abuse, to achieve Data exfiltration. The following tools were observed: CloudSnooper, Onderon, Gh0st RAT.

2024/10/31
阅读更多

SharePoint Vulnerability Exploited in-the-Wild (Incident)

Researchers observed an attacker exploiting CVE-2024-38094—a vulnerability in Microsoft SharePoint. The attacker gained unauthorized access, escalated privileges, and moved laterally across the network to gain control over the entire domain. Through various techniques, includi...

2024/10/30
阅读更多

EMERALDWHALE Attacks Targeting Exposed Git Config Files (Campaign)

Research uncovered an operation named EMERALDWHALE that compromised over 15,000 cloud service credentials by exploiting exposed Git configurations and other misconfigured web services. The attack aimed to steal credentials from private Git repositories and cloud environments, ...

2024/10/30
阅读更多

Amazon DB exposed with Prime Video viewing habits (Research)

Security researcher Anurag Sen discovered an unprotected Amazon Prime database containing pseudonymized viewing data, accessible from the internet without a password. Named "Sauron," the Elasticsearch database held approximately 215 million records, including information on st...

2024/10/27
阅读更多

TeamTNT’s Docker Gatling Gun Campaign (Campaign)

Researchers observed TeamTNT, a threat group known to target cloud environments, in a campaign targeting cloud-native environments by compromising exposed Docker daemons. Using Docker Hub to distribute malware, the group employs cryptominers and the Sliver malware, enhancing t...

2024/10/25
阅读更多

UNC5820 exploiting FortiManager flaw (Campaign)

Researchers identified a zero-day vulnerability, CVE-2024-47575, impacting FortiManager, exploited by the UNC5820 group. This flaw allows unauthorized access, enabling threat actors to exfiltrate critical configuration data. The vulnerability has been actively exploited, with ...

2024/10/24
阅读更多

Prometei campaign (Campaign)

The Prometei botnet attempted to infiltrate a company’s network using a brute-force attack. Researchers from Trend Micro identified and mitigated the threat by tracing Prometei’s stealthy, modular structure. Prometei, primarily aimed at cryptocurrency mining and credential the...

2024/10/23
阅读更多

Triad Nexus: Funnull malicious campaign (Campaign)

Silent Push’s investigation into FUNNULL, a Chinese CDN, reveals its role in hosting extensive malicious infrastructure dubbed "Triad Nexus." This includes over 200,000 algorithmically generated domains connected to gambling, investment scams, phishing, and a supply chain atta...

2024/10/22
阅读更多

perfctl campaign targeting Docker API (Campaign)

Attackers are exploiting exposed Docker Remote API servers to deploy a new malware strain named "perfctl." This malware is designed to mine cryptocurrency and can evade detection by disabling security features and establishing persistence on compromised systems. The attackers ...

2024/10/21
阅读更多

EA cross-user access via API (Research)

On 2024-10-18, a research was reported, involving , gaining initial access via API vulnerability, to achieve Resp. disclosure.

2024/10/18
阅读更多

Earth Simnavaz (APT34) Targeting UAE and Gulf Regions (Campaign)

Researchers at Trend Micro identified cyberattacks by Earth Simnavaz (also known as APT34 or OilRig), targeting UAE and Gulf region entities. The group exploits vulnerabilities, including CVE-2024-30088, to escalate privileges and deploy backdoors via Microsoft Exchange server...

2024/10/11
阅读更多

Game Freak data leak (Incident)

On 2024-10-10, an incident was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Exposed git config files abuse, targeting GitLab to achieve Data exfiltration.

2024/10/10
阅读更多

APT29 Targeting Zimbra and TeamCity Servers (Campaign)

The U.S. and U.K. cyber agencies have issued a joint advisory warning about Russian Foreign Intelligence Service (SVR)-linked attackers, tracked as APT29 (a.k.a Cozy Bear or Midnight Blizzard). These actors are exploiting vulnerabilities in Zimbra and JetBrains TeamCity server...

2024/10/10
阅读更多

Veeam Vulnerability Exploited by Akira and Fog Ransomware (Campaign)

CVE-2024-40711 arises from the deserialization of untrusted data in the Veeam Backup & Replication software. This vulnerability can be exploited with low-complexity attacks, making it a threat to organizations relying on Veeam’s platform for backup, disaster recovery, and data...

2024/10/10
阅读更多

LLMJacking for Roleplaying Campaign (Campaign)

In September 2024, threat actors conducted a campaign exploiting exposed AWS access keys to hijack AWS Bedrock services for operating illicit AI-powered roleplay chatbots. The attackers leverage compromised long-lived credentials (AKIA keys) discovered primarily through GitHub...

2024/10/3
阅读更多

perfctl Malware Targeting Linux (Campaign)

Researchers investigated the "perfctl malware," a Linux malware targeting misconfigurations and vulnerabilities on Linux servers. Perfctl employs rootkits, privilege escalation exploits, and cryptomining activities. It also uses tactics such as process masquerading and deletin...

2024/10/3
阅读更多

Rackspace incident (2024) (Incident)

On 2024-09-30, an incident was reported, involving an unknown actor, gaining initial access via 0-day vulnerability, targeting ScienceLogic SL1 to achieve Data exfiltration.

2024/9/30
阅读更多

REF6138 campaign (Campaign)

Elastic Security Labs uncovered a Linux malware campaign that began in March 2024, targeting vulnerable servers via an Apache2 web server exploit. The attackers gained access and deployed a variety of tools and malware families, including KAIJI, known for its DDoS capabilities...

2024/9/27
阅读更多

Storm-0501 Targeting Hybrid Environments with Ransomware (Campaign)

Storm-0501 has been observed conducting multi-staged attacks targeting hybrid cloud environments across various U.S. sectors, including government and manufacturing. These attacks involve lateral movement from on-premises environments to the cloud, leading to data exfiltration...

2024/9/26
阅读更多

Storm-0501 attacking hybrid environments with ransomware (Campaign)

Microsoft sheds light on the activities of Storm-0501, a threat actor known for deploying ransomware attacks in hybrid cloud environments. The group has expanded its operations to target both on-premises and cloud resources, posing significant risks to organizations utilizing ...

2024/9/26
阅读更多

Docker Swarm and K8s cryptojacking campaign (Campaign)

Datadog Security Research has uncovered a sophisticated cryptojacking campaign targeting microservice technologies, specifically Docker and Kubernetes. The threat actors exploit exposed Docker Engine APIs to gain initial access, deploying cryptocurrency miners on compromised c...

2024/9/23
阅读更多

UNC1860 Attacks Targeting the Middle East (Campaign)

UNC1860 is an Iranian state-sponsored threat actor, likely affiliated with Iran's Ministry of Intelligence and Security (MOIS). This group specializes in gaining persistent access to high-priority networks, especially in the government and telecommunications sectors in the Mid...

2024/9/20
阅读更多

Scattered Spider targeting GCP environment (Incident)

On 2024-09-17, an incident was reported, involving 0ktapus, gaining initial access via Unknown, while using Create or modify firewall or security group rules, OS password reset, Create SSH backdoor, Modify compute startup script, Launch new cloud resources, Delete compute snapshot, to achieve RansomOp.

2024/9/17
阅读更多

Scattered Spider targeting Azure environment (Incident)

On 2024-09-17, an incident was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Vishing, MFA enrollment, Cloud API e, to achieve RansomOp.

2024/9/17
阅读更多

GitHub PAT leakage leading to RDS Database exfiltration (Incident)

On 2024-09-17, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, targeting GitHub to achieve Data exfiltration.

2024/9/17
阅读更多

Fortinet Sharepoint data leak (Incident)

Fortinet confirmed a data breach where a threat actor, "Fortibitch," claimed to have stolen 440GB of data from the company's Microsoft Sharepoint server. The threat actor reportedly shared access credentials to an S3 bucket containing the stolen data and attempted to extort Fo...

2024/9/12
阅读更多

Campaign targeting Selenium Grid for cryptomining (Campaign)

Cado Security Labs discovered two campaigns exploiting misconfigured Selenium Grid instances to deploy malware, including an exploit kit, cryptominer, and proxyjacker. Selenium Grid is widely used for browser automation and testing, but its default configuration lacks authenti...

2024/9/12
阅读更多

Hadooken Malware Targeting Weblogic Servers (Campaign)

Researchers discovered a new Linux malware named "Hadooken" that specifically targets Oracle WebLogic servers. The malware exploits weak passwords to gain access and then deploys both Tsunami malware and a cryptominer. The attack flow involves using a combination of shell and ...

2024/9/12
阅读更多

DragonRank Targeting IIS Web Servers (Campaign)

Researchers identified a "DragonRank" campaign targeting countries in Asia and Europe. This group exploits web application services to deploy web shells and malware like PlugX and BadIIS, primarily for manipulating search engine rankings. The campaign has affected more than 35...

2024/9/10
阅读更多

Godzilla Backdoor Exploiting Confluence Vulnerability (Campaign)

Researchers discovered a new attack exploiting the CVE-2023-22527. The attack uses an in-memory fileless backdoor, known as the Godzilla webshell. The Godzilla backdoor uses AES encryption for communication and remains in memory, making it difficult to identify. It is recommen...

2024/8/30
阅读更多

Confluence exploited for cryptojacking (Campaign)

The critical vulnerability CVE-2023-22527 is being actively exploited for cryptojacking activities, turning affected Confluence Data Center and Server instances into cryptomining networks. Attackers exploit this vulnerability through methods like deploying shell scripts and XM...

2024/8/28
阅读更多

ShinyHunters Ransomware Targeting Cloud Environments (Campaign)

The threat actor group Bling Libra (behind ShinyHunters ransomware) has been observed infiltrating an organization's Amazon Web Services (AWS) environment, focusing on extortion rather than selling stolen data. Using legitimate credentials sourced from public repositories, the...

2024/8/23
阅读更多

PG_MEM Malware Exploiting Misconfigured PostreSQL Instances (Campaign)

Researchers have discovered a new PostgreSQL malware called PG_MEM, which uses brute force attacks to access databases, hide its operations, and mine cryptocurrency. The attack involves creating a superuser role, delivering two malware payloads, and evading detection while eli...

2024/8/19
阅读更多

Msupedge Backdoor Targeting Taiwanese University (Campaign)

A newly discovered backdoor, dubbed Backdoor.Msupedge, was used in an attack on a Taiwanese university, leveraging an unusual communication method through DNS traffic to reach its command-and-control (C&C) server. While DNS-based communication is known among threat actors, its...

2024/8/19
阅读更多

Extortion Campaign Exploiting Exposed Environment Variable (Campaign)

Researchers uncovered an extortion campaign that exploited exposed environment variable files (.env) in cloud environments. These files, which contained sensitive credentials, were accessed and leveraged by attackers to ransom data from victim organizations. The attackers used...

2024/8/15
阅读更多

Gafgyt Malware Targeting Cloud Environments (Campaign)

Researchers identified a new variant of the Gafgyt botnet targeting cloud-native environments by exploiting weak SSH passwords. This variant integrates cryptomining with traditional botnet activities, using GPU power to mine cryptocurrency. The attack flow includes brute-forci...

2024/8/14
阅读更多

Horde Panda targeting South Asian telecommunications provider (Campaign)

Between late June 2023 and early August 2023, CrowdStrike detected suspicious activity at a South Asian telecommunications provider linked to the China-based threat group Horde Panda. The adversary used multiple compromised identities to try to embed themselves deeper into the...

2024/8/9
阅读更多

Scattered Spider Abuses Cloud Management Agent (Campaign)

In May 2024, CrowdStrike observed the cyber threat group Scattered Spider establish a foothold on a cloud-hosted virtual machine (VM) using a cloud service VM management agent. The attackers compromised existing credentials through a phishing campaign to authenticate to the cl...

2024/8/9
阅读更多

Earth Baku campaign (Campaign)

Earth Baku, a threat actor linked to APT41, has extended its operations beyond the Indo-Pacific, targeting regions across Europe, the Middle East, and Africa, including countries such as Italy, Germany, the UAE, and Qatar, with suspected activities in Georgia and Romania. The ...

2024/8/9
阅读更多

Panamorfi campaign (Campaign)

On 2024-08-02, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Jupyter Notebook misconfig abuse, targeting Jupyter Notebook to achieve Denial of service. The following tools were observed: Mineping.

2024/8/2
阅读更多

Mirai Botnet Exploiting Apache OFBiz Vulnerability (Campaign)

The Apache Foundation's OFBiz, an open-source Java-based ERP framework, addressed in May 2024 a critical security vulnerability (CVE-2024-32113) involving path traversal that could lead to remote command execution. Despite its lesser prevalence compared to commercial ERP syste...

2024/7/31
阅读更多

Ransomware operators exploit ESXi vulnerability (Campaign)

Microsoft researchers have discovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085. This flaw is being exploited by ransomware operators to gain full administrative access to domain-joined ESXi hypervisors, enabling them to encrypt file systems, access hos...

2024/7/29
阅读更多

BORN Group supply chain attack (Incident)

On 2024-07-25, an incident was reported, involving IntelBroker, gaining initial access via 1-day vulnerability, while using Network lateral movement, SSH key compromise, Local privilege escalation via vulnerability exploitation, targeting Jenkins, GitHub to achieve Supply chain attack.

2024/7/25
阅读更多

SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining (Campaign)

Wiz Research has detected an ongoing threat campaign dubbed “SeleniumGreed” that exploits exposed Selenium Grid services to deploy cryptominers. Selenium is a popular open-source suite used for testing web applications, allowing users to write tests that simulate user interact...

2024/7/25
阅读更多

Disney Slack breach (Incident)

On 2024-07-15, an incident was reported, involving NullBulge, gaining initial access via End-user compromise, targeting Slack to achieve Data exfiltration.

2024/7/15
阅读更多

crystalray (Campaign)

The Sysdig Threat Research Team (TRT) identified a threat actor named CRYSTALRAY, who has significantly expanded its operations since its initial detection in February 2024. CRYSTALRAY exploits multiple vulnerabilities and uses various open source security tools, such as SSH-S...

2024/7/11
阅读更多

Python infrastructure leaked access token (Research)

On 2024-07-08, a research was reported, involving , gaining initial access via Exposed secret, while using Registry secret scanning, targeting GitHub to achieve Resp. disclosure.

2024/7/8
阅读更多

Misconfigured Jenkins Servers Used for Cryptomining (Campaign)

Researchers discovered attackers targeting misconfigurations in the Jenkins Script Console to execute malicious Groovy scripts, leading to activities such as deploying cryptocurrency miners. By leveraging vulnerabilities and misconfigurations, such as improperly set authentica...

2024/7/5
阅读更多

8220 Gang Exploiting WebLogic Vulnerabilities for Cryptojacking (Campaign)

Water Sigbin exploits CVE-2017-3506 to gain initial access, deploying a PowerShell script on the compromised machine. This script decodes and executes the first stage payload, named wireguard2-3.exe, in the temporary directory. The malware masquerades as a legitimate VPN appli...

2024/6/30
阅读更多

Funnull Polyfill supply chain attack (Campaign)

A Chinese company named Funnull acquired the Polyfill domain and GitHub repo, and inserted malware into polyfill.js that redirected users to gambling websites. Further pivoting revealed that Funnull had exposed a CloudFlare API key that linked the company to several CDN provid...

2024/6/25
阅读更多

Rabbit AI exposed keys in code (Research)

Rabbit AI's codebase included several hardcoded API keys for ElevenLabs, Azure, Yelp, Google Maps, and SendGrid. According to the researchers who discovered this, this access would have allowed an attacker to read Rabbit customers' data, make customer devices inoperable, and t...

2024/6/25
阅读更多

Chinese Threat Actor RedJuliett Exploiting VPN and Firewall Vulnerabilities (Campaign)

Between November 2023 and April 2024, researchers observed RedJuliett, a likely Chinese state-sponsored cyber-espionage group, targeting entities primarily in Taiwan but also across Asia, Africa, and the US. The focus was on sectors such as government, education, technology, a...

2024/6/24
阅读更多

Boolka campaign (Campaign)

On 2024-06-21, a campaign was reported, involving Boolka, gaining initial access via Web vulnerability, while using SQL injection, to achieve Resource hijacking.

2024/6/21
阅读更多

Scattered Spider SaaS targeting (2024) (Campaign)

UNC3944, a financially motivated threat group linked to "0ktapus," "Octo Tempest," "Scatter Swine," and "Scattered Spider," has evolved its tactics to include data theft from SaaS applications, persistence mechanisms in virtualization platforms, and lateral movement via SaaS p...

2024/6/14
阅读更多

NCS mass server deletion (Incident)

On 2024-06-13, an incident was reported, involving , gaining initial access via Insider threat, to achieve Data destruction.

2024/6/13
阅读更多

RCE Vulnerability in PHP CGI Exploited by TellYouThePass (Campaign)

The TellYouThePass ransomware gang has been exploiting the recently patched vulnerability (CVE-2024-4577) in PHP to deploy webshells and execute their encryptor payload on target systems. Attacks started on June 8, just after the release of security updates, using publicly ava...

2024/6/10
阅读更多

NYT source code theft (Incident)

On 2024-06-08, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.

2024/6/8
阅读更多

DERO cryptojacking campaign (2024) (Campaign)

Wiz Threat Research discovered a new variant of a cryptojacking campaign targeting misconfigured Kubernetes clusters in cloud environments. The threat actor abuses cluster anonymous access to deploy malicious container images from Docker Hub that contain a DERO miner. The thre...

2024/6/7
阅读更多

Scylla LLMJacking campaign (Campaign)

On 2024-06-06, a campaign was reported, involving an unknown actor, gaining initial access via End-user compromise, while using LLMjacking, Cloud key compromise, Cloud API e, targeting Amazon Bedrock to achieve Resource hijacking.

2024/6/6
阅读更多

Gitloker campaign (Campaign)

On 2024-06-05, a campaign was reported, involving Gitloker, gaining initial access via End-user compromise, while using Repo encryption for extortion, targeting GitHub to achieve RansomOp.

2024/6/5
阅读更多

Club Penguin data theft via Confluence (Incident)

Club Penguin fans hacked a Disney Confluence server to obtain information about their favorite game, but ended up with 2.5 GB of internal corporate data. Club Penguin, a popular MMO from 2005 to 2018, continues to exist on private servers run by fans, despite Disney shutting i...

2024/6/5
阅读更多

Dama webshell deployment via ThinkPHP exploitation (Campaign)

On 2024-06-05, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ThinkPHP to achieve Resource hijacking. The following tools were observed: Dama.

2024/6/5
阅读更多

Operation Veles (Campaign)

On 2024-06-04, a campaign was reported, involving UTG-Q-008, gaining initial access via Password attack, while using SSH bruteforcing, to achieve Resource hijacking.

2024/6/4
阅读更多

Muhstik (Campaign)

Researchers uncovered a new campaign using Muhstik malware to target Apache RocketMQ, a distributed messaging platform, exploiting a remote code execution vulnerability (CVE-2023-33246). Attackers use this vulnerability to download and execute Muhstik malware on compromised in...

2024/6/4
阅读更多

ByteDance Rspack GitHub misconfiguration (Research)

On 2024-05-31, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.

2024/5/31
阅读更多

RedTail Cryptomining campaign (Campaign)

The RedTail cryptomining malware has been updated to exploit CVE-2024-3400, a vulnerability in PAN-OS. The attackers are using private cryptomining pools for greater control, and the malware now includes advanced antiresearch techniques. It spreads through multiple web exploit...

2024/5/30
阅读更多

Snowflake compromised creds abuse campaign (Incident)

On May 30, 2024, researchers published a report concerning activity by a threat actor dubbed UNC5537, involving abuse of stolen credentials to gain illicit access to Snowflake accounts unprotected by MFA by using a toolkit known as rapeflake.On May 31, 2024, Snowflake publishe...

2024/5/29
阅读更多

Kinsing targeting cloud servers (Campaign)

Researchers observed recent activities surrounding the Kinsing malware, which primarily targets Linux-based cloud infrastructure. Kinsing exploits various vulnerabilities to gain unauthorized access and deploys backdoors and cryptominers. Recent findings show that Kinsing also...

2024/5/16
阅读更多

Mirai campaign targeting Ivanti products (Campaign)

On 2024-05-07, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN to achieve Resource hijacking. The following tools were observed: Mirai.

2024/5/7
阅读更多

Atlas Lion phishing campaign (Campaign)

Microsoft has identified a Morocco-based cybercrime group, Storm-0539, known for sophisticated phishing attacks to steal and sell gift cards. Active since 2021, the group targets large retailers by compromising gift card services and bypassing multi-factor authentication. Thei...

2024/5/6
阅读更多

LLMjacking via Laravel exploitation (Incident)

Threat actors are attempting to monetize their illicit access to LLMs while the cloud account owner bears the costs. The attackers target a variety of LLM services across AWS, Azure, and GCP. In some instances, they employ a script to automate checking the validity of the stol...

2024/5/6
阅读更多

Utah “Bathroom Bill” open database (Research)

On 2024-05-03, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Google Cloud Storage to achieve Data exfiltration.

2024/5/3
阅读更多

TargetCompany Abusing MSSQL Servers for Ransomware (Campaign)

Researchers investigated a series of ransomware attacks targeting poorly managed MS-SQL servers by the TargetCompany ransomware group. This group primarily installs Mallox ransomware, with recent analysis linking these incidents to earlier attacks involving Tor2Mine CoinMiner ...

2024/5/2
阅读更多

ArcaneDoor Campaign Targeting Cisco Adaptive Security Appliance 0day (Campaign)

Cisco reported two zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls that have been exploited by a state-backed hacking group known as UAT4356 or STORM-1849. These vulnerabilities have been under attack since Novembe...

2024/4/24
阅读更多

MITRE breach via Ivanti Connect Secure (Incident)

On 2024-04-19, an incident was reported, involving UNC5221, gaining initial access via 1-day vulnerability, while using Session hijacking, Webshell deployment, targeting Ivanti Connect Secure VPN to achieve Data exfiltration.

2024/4/19
阅读更多

Kubernetes Clusters Targeted in OpenMetadata Exploits (Campaign)

Researchers observed attackers exploiting critical vulnerabilities in the OpenMetadata platform to infiltrate Kubernetes environments for cryptomining. OpenMetadata, an open-source platform for managing data source metadata, was found to have several vulnerabilities (CVE-2024-...

2024/4/17
阅读更多

Delinea breach (Incident)

On 2024-04-14, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, with unknown impact.

2024/4/14
阅读更多

From password reset to data exfiltration (Incident)

On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, while using Launch new cloud resources, Create or modify firewall or security group rules, to achieve Data exfiltration.

2024/4/11
阅读更多

Smishing into Entra onto VMWare ransomware (Incident)

On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Password spraying, Launch new cloud resources, MFA enrollment, Credential theft, Cloud to on-prem lateral movement, Smishing (SMS phishing), EDR whitelisting, to achieve RansomOp.

2024/4/11
阅读更多

Third party to cloud compromise (Incident)

On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Cloud key compromise, Cloud to on-prem lateral movement, to achieve RansomOp.

2024/4/11
阅读更多

Personal local drive to AWS ransomware (Incident)

On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, Phishing, to achieve RansomOp.

2024/4/11
阅读更多

Abusing management tooling for cloud access (Incident)

On 2024-04-11, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.

2024/4/11
阅读更多

Sisense breach (Incident)

An unknown threat actor gained access to a self-hosted Gitlab instance used by Sisense, which stored credentials for an S3 bucket containing customer access tokens, passwords and SSL certificates.

2024/4/11
阅读更多

RUBYCARP: Botnet Exploiting Vulnerabilities for Crypto (Campaign)

Researchers has uncovered a decade-long botnet operation by a Romanian group dubbed RUBYCARP. This group focuses on financial gain through cryptomining, phishing, and DDoS attacks, utilizing public exploits and brute force for deployment.Pinpointing their exact origin is chall...

2024/4/9
阅读更多

Muddled Libra campaigns (2024) (Campaign)

On 2024-04-09, a campaign was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Exfiltration via AWS Transfer, Exfiltration via AWS DataSync, Cloud API e, to achieve Data exfiltration.

2024/4/9
阅读更多

Microsoft exposed storage with credentials (Research)

On 2024-04-09, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Azure Storage to achieve Resp. disclosure.

2024/4/9
阅读更多

Hugging Face cross-tenant access (Research)

Wiz found two critical security risks that were present in Hugging Face’s environment:Specifically, Wiz Research showed that an attacker targeting Hugging Face could have achieved the following:Wiz Research were able to achieve remote code execution through a specially-crafted...

2024/4/4
阅读更多

Affirmed Networks breach (Incident)

In April 2020, Microsoft acquired Affirmed Networks. Sometime prior to that, Storm-0558 likely gained access to a device used by one of the company’s engineer, and retained that access following the acquisition, which allowed the threat actor to move laterally into Microsoft’s...

2024/4/2
阅读更多

XZ Utils backdoor incident (Incident)

A backdoor has been identified in versions 5.6.0 and 5.6.1 of XZ Utils (assigned CVE-2024-3094), which under some conditions may allow SSH authentication bypass in specific versions of certain Linux distributions.According to Wiz data, while XZ Utils itself is highly prevalent...

2024/3/29
阅读更多

Agenda Ransomware Targets ESXi and vCenter Servers (Campaign)

Researchers observed the Agenda Ransomware group, identified as Qilin or Water Galura, has been spreading through VMware vCenter and ESXi servers. The group has been actively evolving and targeting entities globally, particularly in the US, Argentina, Australia, and Thailand, ...

2024/3/26
阅读更多

Compromise of Top.gg repo (Incident)

On 2024-03-25, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Supply chain attack.

2024/3/25
阅读更多

UNC5174 ScreenConnect and F5 BIG-IP exploitation (Campaign)

On 2024-03-22, a campaign was reported, involving UNC5174, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ConnectWise ScreenConnect, F5 BIG IP, Confluence Server to achieve Data exfiltration. The following tools were observed: SUPERSHELL, SNOWLIGHT, GOHEAVY.

2024/3/22
阅读更多

Fujitsu exposed bucket (Research)

On 2024-03-21, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.

2024/3/21
阅读更多

teamcity-exploitation (Campaign)

On 2024-03-19, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using LOLBin abuse, targeting TeamCity to achieve Resource hijacking, RansomOp. The following tools were observed: Jasmin, XMRig, Cobalt Strike, SparkRAT.

2024/3/19
阅读更多

vulnerability-in-aiohttp-targeted-by-shadowsyndicate (Campaign)

Aiohttp is a widely used open-source library for handling concurrent HTTP requests in Python applications. The ransomware group ShadowSyndicate, has been scanning for servers vulnerable to CVE-2024-23334. The flaw means that improperly configuring static resource resolution in...

2024/3/15
阅读更多

Meson Network cryptojacking campaign (Campaign)

Researchers uncovered a malicious campaign targeting the Meson Network, a decentralized content delivery network (CDN) that leverages blockchain for bandwidth marketplace operations. This campaign aimed to exploit the crypto token unlock event around March 15th, attempting to ...

2024/3/11
阅读更多

From writable bucket to credential theft (Research)

On 2024-03-08, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.

2024/3/8
阅读更多

Magnet Goblin campaign (2024) (Campaign)

On 2024-03-08, a campaign was reported, involving Magnet Goblin, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN, Apache ActiveMQ, Magento, Qlink Sense with unknown impact. The following tools were observed: NerbianRAT, AnyDesk, WARPWIRE, MiniNerbian, ScreenConnect, Ligolo.

2024/3/8
阅读更多

malware-campaign-targeting-misconfigured-servers (Campaign)

Researchers observed threat actors exploiting misconfiguration in servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang-based malware, which uses worm-like behavior to automate host discovery and compromise. After gaining access to misconfigured serv...

2024/3/6
阅读更多

z0Miner targeting WebLogic servers (Campaign)

Researchers observed threat actor z0Miner targeting Korean WebLogic servers as download servers for distributing malware, including miners and network tools. It is recommended to look for indicators of compromise in your environment, and if any are identified, remove the files...

2024/3/6
阅读更多

From social engineering to cryptocurrency theft  (Incident)

On 2024-03-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.

2024/3/6
阅读更多

Cutout.Pro Breach (Incident)

The Singapore-based company, which provides AI-powered tools for designing image and video content, has suffered a massive data breach that compromised the personal information of nearly 20 million users.Unauthorized access to Cutout.Pro’s user data-base was disclosed on the a...

2024/2/28
阅读更多

Pure Incubation (DemandScience) Breach (Incident)

Pure Incubation was founded in 2012, and the company later rebranded to DemandScience.Back in March 2024, an actor named KryptonZambie posted a thread on Breach Forums selling a database belonging to Pure Incubation.Furthermore, within their group of businesses, they reportedl...

2024/2/28
阅读更多

From refresh token theft to global admin (Research)

On 2024-02-23, a research was reported, involving , gaining initial access via Unknown, while using Refresh token compromise, Attach administrative role to account, Create or modify cloud key, to achieve Resp. disclosure.

2024/2/23
阅读更多

lucifer-botnet-targeting-apache-hadoop (Campaign)

Researchers identified a malicious campaign focusing on Apache big-data solutions, particularly Apache Hadoop and Apache Druid. This campaign leverages the Lucifer DDoS botnet, infecting Linux machines to mine the Monero cryptocurrency.The attackers target misconfigurations an...

2024/2/22
阅读更多

US DOI PII exfiltration pentest (Research)

On 2024-02-21, a research was reported, involving , gaining initial access via Insider threat, to achieve Resp. disclosure.

2024/2/21
阅读更多

S3 ransomware scam (Incident)

On 2024-02-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, while using Data exfiltration from cloud storage, targeting S3 Bucket to achieve Data exfiltration, Data destruction.

2024/2/21
阅读更多

Migo cryptominer targeting Redis (Campaign)

A new campaign named Migo targeting Redis servers running on Linux hosts to mine cryptocurrency. The campaign was identified following suspicious activities on a Redis honeypot, where a malicious node disabled several Redis configuration options to weaken security and facilita...

2024/2/20
阅读更多

SSH-Snake Confluence targeting campaign (Campaign)

On 2024-02-20, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using SSH propagation, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: SSH-Snake.

2024/2/20
阅读更多

WinStar exposed app database (Research)

On 2024-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.

2024/2/18
阅读更多

Sliver deployment via Confluence vulnerability (Campaign)

On 2024-02-15, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: XMRig, Sliver.

2024/2/15
阅读更多

BMW exposed cloud storage (Research)

On 2024-02-14, a research was reported, involving , gaining initial access via Cloud native misconfig, while using Cloud key compromise, targeting Azure Storage to achieve Resp. disclosure.

2024/2/14
阅读更多

U.S. Internet exposed email server (Research)

On 2024-02-14, a research was reported, involving , gaining initial access via Software misconfig, targeting Ansible, NGINX to achieve Resp. disclosure.

2024/2/14
阅读更多

Microsoft Smartscreen Vulnerability Exploited by Water Hydra (Campaign)

Water Hydra group (AKA DarkCasino), whose activity was first detected in 2021, is known for their cyberattacks targeting the financial industry globally, including banks, cryptocurrency platforms, and gambling sites. Initially confused with the Evilnum APT group, Water Hydra w...

2024/2/13
阅读更多

CGI Federal incident (Incident)

On 2024-02-13, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Data exfiltration.

2024/2/13
阅读更多

Zenlayer exposed database (Research)

On 2024-02-13, a research was reported, involving , gaining initial access via Software misconfig, while using Cloud key compromise, to achieve Resp. disclosure.

2024/2/13
阅读更多

wrk-exposed-database (Research)

On 2024-02-09, a research was reported, involving , gaining initial access via Software misconfig, targeting MongoDB to achieve Resp. disclosure.

2024/2/9
阅读更多

Juniper support portal exposure (Research)

On 2024-02-09, a research was reported, involving , gaining initial access via Software misconfig, targeting Salesforce to achieve Resp. disclosure.

2024/2/9
阅读更多

Almerys incident (Incident)

On 2024-02-08, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.

2024/2/8
阅读更多

Viamedis incident (Incident)

On 2024-02-08, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, to achieve Data exfiltration.

2024/2/8
阅读更多

C3Pool mining via Confluence vulnerability (Campaign)

On 2024-02-08, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Confluence Server to achieve Resource hijacking. The following tools were observed: C3Pool.

2024/2/8
阅读更多

Cryptojacking via Azure Batch (Incident)

On 2024-02-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Azure Batch abuse, targeting Azure Batch to achieve Resource hijacking. The following tools were observed: XMRig.

2024/2/6
阅读更多

Windows SmartScreen vulnerability exploited by Mispadu trojan (Campaign)

Mispadu Stealer, a banking Trojan first reported in November 2019, has been observed exploiting the Windows SmartScreen bypass vulnerability, CVE-2023-36025. This variant of Mispadu spreads through phishing emails and primarily affects victims in Latin America. The malware is ...

2024/2/2
阅读更多

Football Australia exposed cloud key (Research)

On 2024-02-01, a research was reported, involving , gaining initial access via Exposed secret, Cloud native misconfig, while using Cloud key compromise, to achieve Resp. disclosure.

2024/2/1
阅读更多

Cloudflare incident following Okta breach (Incident)

On November 23, 2023, Cloudflare detected activity in their network related to the Okta support system supply chain attack.

2024/2/1
阅读更多

Commando Cat campaign (Campaign)

This campaign, active since the beginning of 2024, deploys a benign container through the Commando project, escaping it to run multiple payloads on the Docker host. Docker is used as an initial access vector to deliver payloads that register persistence, create backdoors, exfi...

2024/2/1
阅读更多

New Relic incident (November 2023) (Incident)

On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Credential stuffing, VPN anonymization, Email C2, to achieve Data exfiltration.

2024/1/31
阅读更多

DangerDev SES abuse incident (Incident)

On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, Create or modify firewall or security group rules, Launch new cloud resources, Evasive username patterns, Domain registration abuse, SES abuse for spam or phishing, Attach administrative role to account, Share compromised resources to an external account, Policy simulation, Modify existing IAM user or role, Cloud compute cryptojacking, targeting Amazon SES to achieve Resource hijacking.

2024/1/31
阅读更多

trigona-ransomware-infecting-misconfigured-mssql-servers (Campaign)

Trigona ransomware has been active since at least June 2022, targeting MSSQL servers. Mimic ransomware was first identified in June 2022, with a January 2024 attack by a Turkish-speaking threat actor on poorly managed MSSQL servers. Researchers believe the same Trigona threat ...

2024/1/28
阅读更多

Mercedes-Benz source code exposure (Research)

In January 2024, researchers at RedHunt Labs discovered that Mercedes-Benz accidentally included an access token in a one of their public GitHub repositories that granted access to an internal GitHub Enterprise server. This server contained intellectual property as well as cre...

2024/1/26
阅读更多

ECS Fargate cryptojacking (Campaign)

Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they immediately began spinning up hundreds of ECS Fargate clusters, within which they created ECS task definitions to launch containers based...

2024/1/19
阅读更多

S3 data exfiltration (Incident)

Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they checked SES quotes and enumerated cloud identities. The threat actor proceeded to create a new admin user. The above was quick and theref...

2024/1/19
阅读更多

Microsoft email exfiltration by Nobelium (Incident)

On January 19, 2023, Microsoft disclosed that email accounts of multiple employees had been compromised by Nobelium (which overlaps with APT29).According to Microsoft, beginning in late November 2023, Nobelium used a Password spraying attack to compromise a "legacy non-product...

2024/1/19
阅读更多

From ActiveMQ to Godzilla webshell (Campaign)

On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Apache ActiveMQ to achieve Resource hijacking. The following tools were observed: Godzilla.

2024/1/18
阅读更多

Mimo cryptomining campaign (Campaign)

On 2024-01-18, a campaign was reported, involving Mimo operator, gaining initial access via 1-day vulnerability, targeting VMware Horizon, Confluence Server, WSO2, Apache ActiveMQ, PaperCut to achieve Resource hijacking, RansomOp. The following tools were observed: Mimo, NHAS reverse_ssh, XMRig, Mimus, Peer2Profit.

2024/1/18
阅读更多

9hits Docker campaign (Campaign)

On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Proxyjacking, targeting Docker to achieve Resource hijacking. The following tools were observed: 9hits, XMRig.

2024/1/18
阅读更多

AndroxGh0st usage (2024) (Campaign)

On 2024-01-16, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, Software misconfig, while using Exposed environment config abuse, targeting PHP, Apache HTTP Server, Laravel to achieve Resource hijacking. The following tools were observed: AndroxGh0st.

2024/1/16
阅读更多

TensorFlow GitHub misconfiguration (Research)

On 2024-01-15, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.

2024/1/15
阅读更多

PyTorch GitHub misconfiguration (Research)

On 2024-01-11, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.

2024/1/11
阅读更多

S3 RansomOp following long-term key exposure (Incident)

On 2024-01-11, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, targeting S3 Bucket to achieve RansomOp, Data exfiltration.

2024/1/11
阅读更多

Dreambus campaign (2023) (Campaign)

On 2024-01-11, a campaign was reported, involving Dreambus operator, gaining initial access via Software misconfig, 1-day vulnerability, targeting Apache RocketMQ, Metabase to achieve Resource hijacking. The following tools were observed: XMRig.

2024/1/11
阅读更多

FBot toolkit targets cloud environments (Campaign)

FBot is a Python-based hacking toolkit, targeting web servers, cloud services, and SaaS platforms like AWS, Office365, PayPal, Sendgrid, and Twilio. FBot's primary purpose is to enable actors to hijack cloud, SaaS, and web services, with a secondary focus on acquiring accounts...

2024/1/11
阅读更多

Ivanti Connect Secure targeting campaign (Campaign)

On 2024-01-10, a campaign was reported, involving UNC5221, gaining initial access via 0-day vulnerability, targeting Ivanti Connect Secure VPN with unknown impact. The following tools were observed: PySoxy, LIGHTWIRE, THINSPOOL, WARPWIRE, WIREFIRE, enum4Linux, ZIPLINE, BUSHWALK, CHAINLINE, FRAMESTING, Impacket, CrackMapExec, iodine, DSLog.

2024/1/10
阅读更多

returgence-campaign-targeting-mssql-servers-with-ransomware (Campaign)

Researchers identified attacks targeting Microsoft SQL (MSSQL) servers to encrypt the victims' files with Mimic (N3ww4v3) ransomware. The attacks are tracked as RE#TURGENCE and have been observed targeting Europe, the United States, and Latin America.Threat actors targeted pub...

2024/1/10
阅读更多

Apache app cryptojacking campaign (Campaign)

On 2024-01-10, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, Software misconfig, targeting Apache Flink, Apache Hadoop, Spring Framework, Redis to achieve Resource hijacking.

2024/1/10
阅读更多

Cyber Toufan Linux destruction (Campaign)

On 2023-12-28, a campaign was reported, involving Cyber Toufan, gaining initial access via Supply chain vector, while using TOR anonymization, Email server hijacking, to achieve Data exfiltration, Data destruction.

2023/12/28
阅读更多

Cloud lateral movement via Citrix cookie (Incident)

On 2023-12-15, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Erase logs, Disable logging, Reverse shell, to achieve Data exfiltration.

2023/12/15
阅读更多

GambleForce SQL injection campaign (Campaign)

On 2023-12-14, a campaign was reported, involving GambleForce, gaining initial access via Web vulnerability, 1-day vulnerability, while using SQL injection, to achieve Data exfiltration.

2023/12/14
阅读更多

APT29 TeamCity campaign (Campaign)

On 2023-12-13, a campaign was reported, involving APT29, gaining initial access via 1-day vulnerability, targeting TeamCity to achieve Data exfiltration.

2023/12/13
阅读更多

OAuth applications to deploy VMs for cryptomining (Campaign)

On 2023-12-12, a campaign was reported, involving Storm-1283, gaining initial access via End-user compromise, while using OAuth app creation, OAuth app hijack, to achieve Resource hijacking.

2023/12/12
阅读更多

First Republic Bank incident (Incident)

On 2023-12-12, an incident was reported, involving an unknown actor, gaining initial access via Insider threat, to achieve Data destruction.

2023/12/12
阅读更多

Krasue Thailand campaign (Campaign)

On 2023-12-07, a campaign was reported, involving Krasue operator, gaining initial access via Unknown, to achieve Data exfiltration. The following tools were observed: Krasue.

2023/12/7
阅读更多

Package hijacking redteam op (Research)

On 2023-12-06, a research was reported, involving , gaining initial access via End-user compromise, while using Package hijacking, to achieve Resp. disclosure.

2023/12/6
阅读更多

GoTitan ActiveMQ campaign (Campaign)

Fortiguard Labs detected numerous threat actors exploiting CVE-2023-46604 to disseminate diverse strains of malware. Their analysis unveiled the emergence of a newly discovered Golang-based botnet named GoTitan and a .NET program called "PrCtrl Rat," equipped with remote contr...

2023/11/28
阅读更多

LINE and NAVER Cloud incident (Incident)

On 2023-11-27, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, to achieve Data exfiltration.

2023/11/27
阅读更多

Andariel exploiting Apache ActiveMQ (Campaign)

On 2023-11-27, a campaign was reported, involving Andariel, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Apache ActiveMQ with unknown impact. The following tools were observed: NukeSped, Metasploit.

2023/11/27
阅读更多

cryptojacking-against-apache-servers-with-cobalt-strike (Campaign)

Researchers detected a cyber attack campaign that installs the XMRig CoinMiner on Windows web servers operating Apache. The threat actor employed Cobalt Strike to manage the compromised system. Cobalt Strike, a commercial penetration testing tool, has recently become a common ...

2023/11/20
阅读更多

Confluence targeting by C3RB3R (Campaign)

On 2023-11-14, a campaign was reported, involving C3RB3R operator, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve RansomOp. The following tools were observed: C3RB3R Ransomware.

2023/11/14
阅读更多

OracleIV campaign (Campaign)

On 2023-11-13, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Abusing exposed Docker socket, targeting Docker to achieve Resource hijacking. The following tools were observed: OracleIV.

2023/11/13
阅读更多

sumologic-breach (Incident)

On 2023-11-07, an incident was reported, involving an unknown actor, gaining initial access via Unknown, with unknown impact.

2023/11/7
阅读更多

EleKtra-Leak (Campaign)

Unit 42 researchers identified a campaign dubbed EleKtra-Leak, which performs automated targeting of exposed identity and access management (IAM) credentials within public GitHub repositories.

2023/10/30
阅读更多

Okta support system supply chain attack (Incident)

The threat actor gained access to Okta’s environment, and figured out that Okta was storing unsanitized HAR files (recordings of browser activity) that customers were sharing with the Okta support team to help with troubleshooting. These HAR files sometimes contained customer ...

2023/10/20
阅读更多

Qubitstrike Crypto Mining and Rootkit Campaign (Campaign)

Qubitstrike is a cryptojacking campaing targeting exposed Jupyter Notebooks, as they may allow to execute commands remotely. After obtaining a shell on the remote host, the shell script executes a cryptocurrency miner and establishes persistence using a cron job that inserts a...

2023/10/18
阅读更多

Cloud tools imitation campaign (Campaign)

On 2023-10-10, a campaign was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Package typosquatting, Package Starjacking, with unknown impact.

2023/10/10
阅读更多

SQL Server to cloud lateral movement (Campaign)

On 2023-10-03, a campaign was reported, involving an unknown actor, gaining initial access via Web vulnerability, while using SQL injection, Use DNS for exfiltration, IMDS abuse, SQL commands, targeting Microsoft SQL Server to achieve Data exfiltration.

2023/10/3
阅读更多

Darkbeam data exposure (Research)

Cyber risk management company DarkBeam has leaked more than 3.8 billion records after it left an Elasticsearch server unprotected on the internet. The database contained information from older breaches that DarkBeam was using to send alerts to customers. While the leaked data ...

2023/10/2
阅读更多

Scattered Spider SaaS targeting (Campaign)

On 2023-09-20, a campaign was reported, involving 0ktapus, gaining initial access via End-user compromise, while using Smishing (SMS phishing), Serial port abuse, MFA enrollment, Create new cloud user, SIM swap scam, Phishing, to achieve Data exfiltration, RansomOp.

2023/9/20
阅读更多

Prophet Spider campaign (Campaign)

On 2023-09-20, a campaign was reported, involving Prophet Spider, gaining initial access via , while using Vulnerability exploitation,.

2023/9/20
阅读更多

Microsoft AI data exposure (Research)

On 2023-09-18, a research was reported, involving , gaining initial access via Software misconfig, targeting Azure Storage to achieve Resp. disclosure.

2023/9/18
阅读更多

AmberSquid campaign (Campaign)

Researchers uncovered a cryptojacking operation targeting AWS services such as AWS Amplify, AWS Fargate, and Amazon SageMaker to mine cryptocurrency. The timeline of this operation spans from May 2022 to March 2023. Initially, the attackers used Docker Hub accounts to distribu...

2023/9/18
阅读更多

peach-sandstorm-cloud-activity (Campaign)

According to Microsoft Threat Research, during a campaign by Iranian state-sponsored actor Peach Sandstorm, they were observed utilizing password spray attacks to gain unauthorized access to target environments. Active since February 2023, the campaign successfully targeted sa...

2023/9/14
阅读更多

Rollbar hack (Incident)

The security breach was discovered by Rollbar on September 6 when reviewing data warehouse logs showing that a service account was used to log into the cloud-based bug monitoring platform.Once inside Rollbar's systems, the threat actors searched the company's data for cloud cr...

2023/9/13
阅读更多

BlackCat Azure Storage Account RansomOp (Incident)

The threat actors gained access to the customer's Azure portal, where they obtained the Azure key required to access the storage account programmatically. The adversary encoded the keys using base-64 and inserted them into the ransomware binary with execution command lines bel...

2023/9/13
阅读更多

From SSH bruteforce to cryptojacking (Campaign)

The researchers observed a malicious IP address, previously flagged for conducting SSH brute force attempts, communicating with a malicious shell script named hoze. This script downloads xrx.tar, an archive that contains more scripts that uninstall security software and enable...

2023/9/8
阅读更多

Evil_MinIO campaign (Campaign)

On 2023-09-04, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting MinIO with unknown impact.

2023/9/4
阅读更多

Kinsing campaigns (2023-2024) (Campaign)

On 2023-08-29, a campaign was reported, involving Kinsing operator, gaining initial access via 1-day vulnerability, Software misconfig, while using Misconfigured PostgreSQL abuse, targeting Openfire, PostgreSQL, WebLogic, WordPress, Liferay, PHPUnit, Apache RocketMQ to achieve Resource hijacking.

2023/8/29
阅读更多

UNC4841 Barracuda ESG Campaign (Campaign)

On 2023-08-29, a campaign was reported, involving UNC4841, gaining initial access via 0-day vulnerability, targeting Barracuda ESG to achieve Data exfiltration.

2023/8/29
阅读更多

Retool hack (Incident)

On 2023-08-29, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Spearphishing, to achieve Supply chain attack.

2023/8/29
阅读更多

Fatal Model exposed database (Research)

A security researcher discovered an exposed cloud database that contained sensitive log records with references to Fatal Model, an escort service in Brazil. Additionally, the database contained access keys for an AWS storage account associated with Fatal Model, which wasn't pa...

2023/8/25
阅读更多

Labrat GitLab campaign (Campaign)

On 2023-08-17, a campaign was reported, involving Labrat operator, gaining initial access via 1-day vulnerability, while using Proxyjacking, Cloud compute cryptojacking, targeting GitLab to achieve Resource hijacking. The following tools were observed: Gsocket, ProxyLite, IPRoyal.

2023/8/17
阅读更多

From PHP exploitation to AWS lateral movement (Incident)

On 2023-08-15, an incident was reported, involving an unknown actor, gaining initial access via 0-day vulnerability, while using SSM orchestration abuse, Cron persistence, IMDS abuse, targeting PHP with unknown impact. The following tools were observed: Sliver.

2023/8/15
阅读更多

use-of-azure-run-commands (Campaign)

On 2023-08-15, a campaign was reported, involving 0ktapus, gaining initial access via Unknown, while using Azure Run Commands abuse, with unknown impact.

2023/8/15
阅读更多

Use of linPEAS for cloud enumeration (Incident)

On 2023-08-15, an incident was reported, involving an unknown actor, gaining initial access via ,. The following tools were observed: linPEAS.

2023/8/15
阅读更多

SugarCRM as initial access to AWS envs (Campaign)

On 2023-08-10, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting SugarCRM. The following tools were observed: Pacu, ScoutSuite.

2023/8/10
阅读更多

P2PInfect campaign (Campaign)

A campaign targeting misconfigured Redis servers with a peer-to-peer self-replicating worm named P2Pinfect. The campaign exploits a critical vulnerability and makes use of the SLAVEOF feature to install malware that acts as a botnet agent. P2Pinfect is written in Rust and empl...

2023/7/31
阅读更多

Meow Jupyter Notebook campaign (Campaign)

On 2023-07-31, a campaign was reported, involving Meow, gaining initial access via Software misconfig, while using Jupyter Notebook misconfig abuse, targeting Jupyter Notebook to achieve Data destruction.

2023/7/31
阅读更多

SkidMap targeting Redis (Campaign)

On 2023-07-30, a campaign was reported, involving SkidMap operator, gaining initial access via Software misconfig, while using Misconfigured Redis abuse, targeting Redis with unknown impact. The following tools were observed: SkidMap.

2023/7/30
阅读更多

DepositFiles exposed config file (Research)

The Cybernews research team discovered DepositFiles’ publicly hosted environment configuration (config) file, which exposed:

2023/7/27
阅读更多

JumpCloud supply chain attack (Incident)

On 2023-07-14, an incident was reported, involving TraderTraitor, gaining initial access via End-user compromise, to achieve Supply chain attack.

2023/7/14
阅读更多

SilentBob cryptomining campaign (Campaign)

A cloud attack campaign possibly orchestrated by the threat actor known as TeamTNT. The campaign primarily involves an aggressive cloud worm that targets JupyterLab and Docker APIs to deploy Tsunami malware, hijack cloud credentials, and execute resource hijacking.On July 13, ...

2023/7/13
阅读更多

Storm-0558 phishing campaigns (Campaign)

On 2023-07-11, a campaign was reported, involving Storm-0558, gaining initial access via End-user compromise, while using Phishing, LSASS dumping, with unknown impact. The following tools were observed: Cigril, China Chopper.

2023/7/11
阅读更多

PyLoose campaign (Campaign)

In mid-2023, an unknown financially-motivated threat actor began targeting publicly exposed Jupyter Notebook instances to hijack them for running cryptomining operations. The threat actor deployed a fileless Python tool (dubbed “PyLoose”) that loaded an XMRig miner directly in...

2023/7/11
阅读更多

APT31 Rekoobe campaign (Campaign)

On 2023-07-11, a campaign was reported, involving APT31, gaining initial access via ,. The following tools were observed: Rekoobe.

2023/7/11
阅读更多

storm-0558-signing-key-compromise (Incident)

In July 2023, Microsoft disclosed that Storm-0558, a threat actor attributed to China, managed to acquire a signing key that allowed them to gain illicit access to Exchange and Outlook accounts. The threat actor utilized this key in order to exfiltrate emails from multiple org...

2023/7/11
阅读更多

scarleteel20 (Campaign)

In July 2023, details of recent activities related to ScarletEel were published, showing the advancement of the attacker over time. The threat actors expanded their arsenal to include new tools and a C2 infrastructure, making it more difficult to detect their activity. They ty...

2023/7/11
阅读更多

RomCom exploiting Word vulnerability in campaign targeting government entities (Campaign)

In June 2023, Storm-0978 launched a campaign exploiting the CVE-2023-36884 vulnerability, a remote code execution flaw in Microsoft Word documents. This campaign targeted defense and government entities in Europe and North America, using phishing emails with lures related to t...

2023/7/3
阅读更多

Diicot Campaign Targeting Exposed SSH (Campaign)

On 2023-06-15, a campaign was reported, involving Diicot, gaining initial access via Password attack, while using SSH bruteforcing, UPX packing, Cron persistence, to achieve Resource hijacking. The following tools were observed: XMRig, zmap.

2023/6/15
阅读更多

From WSO2 RCE to SSH lateral movement (Incident)

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a WSO2 RCE vulnerability (CVE-2022-29464) affecting Linux machines. The actor downloaded several tools including cryptominers and websh...

2023/6/5
阅读更多

from-wso2-rce-to-ssh-lateral-movement (Incident)

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a vulnerability affecting an Internet-facing web app and gaining command shell access. The actor used Chisel for C2 purposes (specifica...

2023/6/5
阅读更多

from-php-vuln-to-silver-execution-via-cron (Incident)

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment using an RCE vulnerability affecting PHP applications on multiple Linux machines. The actor enumerated the environment and attempted to query the IMD...

2023/6/5
阅读更多

Cosmic Wolf cloud activity (Incident)

According to CrowdStrike research, in a certain incident Cosmic Wolf compromised a target organization’s cloud environment using a stolen credential. They used this to authenticate using a CLI and modified security group settings to allow shell access to machines in the enviro...

2023/6/5
阅读更多

Poisoned image to K8s to cloud (Incident)

[…] a real example of an AWS Kubernetes cluster infection through a software development supply chain compromise. The attackers were able to get AWS credentials from a DevOps workstation and use them to introduce a poisoned docker image into a Kubernetes cluster. It allowed th...

2023/5/25
阅读更多

8820-gang-targeting-oracle-weblogic (Campaign)

8220 Gang, a financially-motivated Chinese threat actor known for their cryptojacking activity, has been observed by researchers to be exploiting CVE-2020-14883, a remote code execution (RCE) vulnerability in Oracle WebLogic Server. The attackers seem to be exploiting the vuln...

2023/5/16
阅读更多

SIM swapping to serial port abuse (Incident)

In 2022, Mandiant identified attacker activity centered in Microsoft Azure that Mandiant attributed to UNC3944. Mandiant’s investigation revealed that the attacker employed malicious use of the Serial Console on Azure Virtual Machines (VM) to install third-party remote managem...

2023/5/16
阅读更多

Optimeyes data leak (Research)

Optimeyes's Jenkins instance was publicly exposed, albeit with few viewable workspaces and locked down admin permissions. However, the build information for each past build contained a link to the corrosponding git repository, including the bitbucket credentials in the url. Th...

2023/5/9
阅读更多

Capita data leak (Research)

UK outsourcing company Capita exposed sensitive data in a public S3 bucket with no password protection for seven years (since 2016). The bucket contained approximately 3,000 files totaling 655GB - including documents, software, cleartext secrets, server images and more - and w...

2023/5/5
阅读更多

fsevents supply chain attack (Incident)

The fsevents npm package previously pulled certain remote binaries from a public S3 bucket (fsevents-binaries.s3-us-west-2.amazonaws.com). At some point the bucket expired and the domain became dangling, and in April 2023 it was hijacked by an unknown actor (reportedly a secur...

2023/4/27
阅读更多

8220 Gang exploiting Log4Shell8220 Gang targeting Confluence (Campaign)

On 2023-04-21, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.

2023/4/21
阅读更多

misconfigured-fw-to-cryptojacking-botnet (Incident)

According to Unit42, a medium-sized e-commerce company was attacked by a threat actor with cryptojacking attack which performed large-scale crypto-mining and botnet operations in the company’s cloud environment. The attacked discovered by the cloud provider which alerted the c...

2023/4/18
阅读更多

SIM-Swap to Data Leak on Dark Web (Incident)

According to Unit42, a financial firm was attacked by an adversary that manipulated, and compromised it’s cloud workloads. The threat actor was able to drop storage components such as buckets and tables, threatened the firm to leak data if ransom will not paid and eventually t...

2023/4/18
阅读更多

Trigona targeting MSSQL servers (Campaign)

Microsoft SQL servers were observed being attacked through brute-force or dictionary attacks that exploit weak account credentials. The servers were then used as entry points to deploy Trigona ransomware and encrypt all filesOnce the attackers gain access to a server, they dep...

2023/4/17
阅读更多

Mexals cryptojacking campaign (Campaign)

On 2023-04-12, a campaign was reported, involving Diicot, gaining initial access via Password attack, while using SSH bruteforcing, Cron persistence, UPX packing, to achieve Resource hijacking. The following tools were observed: XMRig.

2023/4/12
阅读更多

MuddyWater cloud destruction operation (Incident)

Microsoft identified a destructive operation executed by MuddyWater (also known as MERCURY or Mango Sandstorm), a threat actor attributed to the Iranian government, in partnership with “DarkBit” (who gained notoriety for attacking the Technion, an Israeli university, in Februa...

2023/4/7
阅读更多

AlienFox campaign (Campaign)

On 2023-03-30, a campaign was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration. The following tools were observed: AlienFox.

2023/3/30
阅读更多

3CX and Trading Technologies supply chain attack (Incident)

In March 2023, a North Korean threat actor (dubbed “SmoothOperator”) gained access to 3CX (VoIP vendor) and inserted a backdoor into their desktop product, which was used for targeting some of their customers - primarily crypto companies. Researchers later discovered 3CX thems...

2023/3/29
阅读更多

ChinaZ campaigns (Campaign)

On 2023-03-24, a campaign was reported, involving ChinaZ, gaining initial access via , while using Misconfigured SSH abuse,.

2023/3/24
阅读更多

JavaScript injection via vulnerable CMS (Campaign)

On 2023-03-23, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.

2023/3/23
阅读更多

UNC3886 campaigns (Campaign)

On 2023-03-16, a campaign was reported, involving UNC3886, gaining initial access via 1-day vulnerability, targeting ESXi Server, Fortinet Fortigate to achieve Data exfiltration. The following tools were observed: Reptile.

2023/3/16
阅读更多

Dero cryptojacking targeting K8s (Campaign)

On 2023-03-15, a campaign was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, while using Cloud compute cryptojacking, K8s anonymous auth abuse, targeting Kubernetes to achieve Resource hijacking. The following tools were observed: DERO miner.

2023/3/15
阅读更多

GoBruteforcer campaign (Campaign)

GoBruteforcer is a new kind of botnet malware that is written in Golang, and targets web servers, specifically those running phpMyAdmin, MySQL, FTP and Postgres services. The following information is based on samples discovered by researchers in March 2023.The GoBruteforcer ma...

2023/3/10
阅读更多

IceFire Aspera Faspex campaign (Campaign)

On 2023-03-09, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Aspera Faspex to achieve RansomOp. The following tools were observed: IceFire.

2023/3/9
阅读更多

Stealing the LIGHTSHOW (Campaign)

On 2023-03-09, a campaign was reported, involving UNC2970, gaining initial access via , while using Azure AD abuse, Intune abuse,.

2023/3/9
阅读更多

scarleteel (Campaign)

In early 2023, Sysdig researchers discovered a cyber operation targeting public-facing containerized web apps running in a self-hosted K8s cluster, in order to mine for cryptocurrency and infiltrate the larger cloud environment. The operation, dubbed "SCARLETEEL", involved ret...

2023/2/28
阅读更多

Fayvo exposed database (Research)

Security researchers discovered a database containing sensitive data operated by Fayvo, a Saudi Arabia-based social media app. The server hosting the database also leaked its staging environment file, which led to another unprotected environment file with MySQL credentials, AW...

2023/2/23
阅读更多

US military email server exposure (Research)

On 2023-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.

2023/2/18
阅读更多

esxiargs-attack (Campaign)

On 2023-02-03, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, to achieve RansomOp. The following tools were observed: Babuk.

2023/2/3
阅读更多

HeadCrab campaign (Campaign)

On 2023-02-01, a campaign was reported, involving HeadCrab operator, gaining initial access via Software misconfig, while using Misconfigured Redis abuse, targeting Redis to achieve Resource hijacking. The following tools were observed: HeadCrab.

2023/2/1
阅读更多

GitHub certificate theft incident (Incident)

On 2023-01-30, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Phishing, targeting GitHub to achieve Data exfiltration.

2023/1/30
阅读更多

CommuteAir exposed Jenkins (Research)

On 2023-01-19, a research was reported, involving , gaining initial access via Software misconfig, targeting Jenkins to achieve Resp. disclosure.

2023/1/19
阅读更多

circleci-breach (Incident)

On December 29, 2022, CircleCI's security team were alerted to suspicious activity on one of their customer's GitHub OAuth tokens. The team then rotated all GitHub OAuth tokens on December 31, 2022 as a precautionary measure. By January 4, 2023, CircleCI's internal investigati...

2023/1/4
阅读更多

PyTorch-nightly torchtriton dependency compromise (Incident)

PyTorch-nightly Linux packages installed via pip between December 25th and December 30th, 2022 ran a malicious binary. The malicious binary was introduced by a dependency, torchtriton, that was vulnerable to dependency confusion. The malicious payload gathered system informati...

2022/12/31
阅读更多

Jupyter Notebook cred harvesting campaign (Campaign)

Permiso identified a credential harvesting campaign targeting cloud infrastructure for the purpose of harvesting credentials. The majority of the victim system were running public facing Juptyer Notebooks. At the time of writing there were about 50 compromised systems. The ini...

2022/12/28
阅读更多

Okta source code theft (Incident)

On 2022-12-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, targeting GitHub to achieve Data exfiltration.

2022/12/21
阅读更多

Redigo campaign (Campaign)

On 2022-12-01, a campaign was reported, involving Redigo operator, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting Redis with unknown impact. The following tools were observed: Redigo.

2022/12/1
阅读更多

lastpass-goto-breach (Incident)

In November 2022, GoTo (formerly LogMeIn) disclosed a security breach of their development environment and a cloud storage service used by them and LastPass (their affiliate).The investigation determined that the threat actor gained access to the development environment using ...

2022/11/30
阅读更多

WatchDog East-Asian CSP campaign (Campaign)

On 2022-11-16, a campaign was reported, involving WatchDog, gaining initial access via ,.

2022/11/16
阅读更多

Dropbox Github breach (Incident)

Dropbox disclosed a security breach where attackers stole 130 code repositories from one of its GitHub accounts by using credentials obtained from phishing Dropbox employees. The breach was discovered on October 14, following a GitHub alert. Attackers impersonated CircleCI in ...

2022/11/1
阅读更多

Dropbox breach (Incident)

On 2022-11-01, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.

2022/11/1
阅读更多

Backdooring self-hosted GitHub Runner (Research)

On 2022-10-26, a research was reported, involving , gaining initial access via Software misconfig, while using Misconfigured GitHub Runner abuse, targeting GitHub to achieve None.

2022/10/26
阅读更多

reuters-leaky-elasticsearch-dbs (Research)

On 2022-10-26, a research was reported, involving , gaining initial access via Software misconfig, while using Public exposure abuse, targeting Elasticsearch to achieve Data exfiltration.

2022/10/26
阅读更多

Leaked long-lived AWS creds (Incident)

Impacted organization discovered that long-lived AWS creds had leaked. Initially alerted to the following suspicious activity:Follow-up investigation into CloudTrail logs showed compromise of multiple IAM accounts and evidence of leakage of long-lived access keys.

2022/10/7
阅读更多

Auth0 source code theft (Incident)

On 2022-09-26, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Data exfiltration.

2022/9/26
阅读更多

fast-company-breach (Incident)

Fast Company took its website offline after its content management system (CMS) was hacked to display stories and push out Apple News notifications containing obscene and racist comments.A “Breached” hacking forum member named 'Thrax' published a database dump with 6,737 emplo...

2022/9/25
阅读更多

optus-breach (Incident)

A hacker reportedly stole ~11mil records of customer PII (dated 2017) from Optus, an Australian telco company. The data was disclosed and put on sale in late September 22’. According to information obtained by a reporter who claimed to be in contact with the hacker, the root c...

2022/9/21
阅读更多

Redirection Roulette (Campaign)

Beginning in early September 2022, an unknown threat actor successfully compromised tens of thousands of websites mainly aimed at East Asian audiences, redirecting hundreds of thousands of their users to adult-themed content. In several cases, the threat actor connected to the...

2022/9/1
阅读更多

Kiss-A-Dog campaign (Campaign)

CrowdStrike uncovered a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure using an obscure domain from the payload, container escape attempt and anonymized “dog”-themed mining pool domains.Nicknamed “Kiss-a-dog,” the campaign used multiple comman...

2022/9/1
阅读更多

APT29 targeting Microsoft 365 (Campaign)

On 2022-08-22, a campaign was reported, involving APT29, gaining initial access via , while using Add attacker-controlled IdP via ADFS access, Disable logging, MFA enrollment, Auth token signing via Golden SAML, Auth token signing via ADFS access,.

2022/8/22
阅读更多

Microsoft credential exposure on GitHub (Research)

On 2022-08-16, a research was reported, involving , gaining initial access via Exposed secret, targeting GitHub to achieve Resp. disclosure.

2022/8/16
阅读更多

twilio-breach (Incident)

A threat actor dubbed “Oktapus” / “ScatterSwine” conducted a widespread SMishing campaign against 136 organizations, and in some cases (Such as MailChimp, DoorDash and Digital Ocean) was successful in gaining initial access to their systems and exfiltrating customer data. One ...

2022/8/8
阅读更多

PREMINT hack (Incident)

On 2022-07-18, an incident was reported, involving an unknown actor, gaining initial access via Cloud native misconfig, to achieve Supply chain attack, Denial of wallet.

2022/7/18
阅读更多

Bondnet campaign (2022) (Campaign)

On 2022-07-11, a campaign was reported, involving Bondnet, gaining initial access via Password attack, targeting Microsoft SQL Server to achieve Resource hijacking.

2022/7/11
阅读更多

8220 Gang targeting Confluence (Campaign)

On 2022-07-07, a campaign was reported, involving 8220 Gang, gaining initial access via 1-day vulnerability, to achieve Resource hijacking.

2022/7/7
阅读更多

darkradiation-container-ransomwarewiper (Campaign)

On 2022-06-21, a campaign was reported, involving DarkRadiation operator, gaining initial access via Unknown, while using Database ransomware, Disk Wipe, Remotely execute commands or scripts on a VM , Rootkit - LD_PRELOAD, targeting Docker to achieve RansomOp.

2022/6/21
阅读更多

incident-report-spotting-an-attacker-in-gcp (Incident)

https://expel.com/blog/incident-report-spotting-an-attacker-in-gcp/

2022/6/9
阅读更多

JavaScript injection via WordPress exploitation (Campaign)

On 2022-05-11, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting WordPress to achieve Resource hijacking.

2022/5/11
阅读更多

UNC2903 campaigns (Campaign)

On 2022-05-04, a campaign was reported, involving UNC2903, gaining initial access via , while using IMDS abuse, SSRF,.

2022/5/4
阅读更多

LemonDuck Docker campaign (Campaign)

On 2022-04-21, a campaign was reported, involving LemonDuck, gaining initial access via ,.

2022/4/21
阅读更多

github-npm-breach (Incident)

On April 12, 2022, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm.According to GitHu...

2022/4/15
阅读更多

Denonia campaign (Campaign)

Denonia is a newly discovered type of malware targeting AWS Lambda environments. It was recently exposed by Cado Security, who named it after the domain it communicates with. Once the malware is executed on the victim's host, it launches XMRig cryptominer.Denonia's delivery an...

2022/4/6
阅读更多

incident-report-from-cli-to-console-chasing-an-attacker-in-aws (Incident)

Expel’s SOC detected unauthorized access into one of their customer’s Amazon Web Services (AWS) environments. The attacker used a long-term access key to gain initial access. Once they got in, they were able to abuse the AWS Identity and Access Management (IAM) service to esca...

2022/4/5
阅读更多

Muhstick Redis campaign (Campaign)

On 2022-03-28, a campaign was reported, involving Muhstik operator, gaining initial access via ,.

2022/3/28
阅读更多

LAPSUS$ campaigns (Campaign)

According to Microsoft Threat Research, as part of LAPSUS$’s large-scale social engineering and extortion campaigns, they also gained access to several of their targets’ cloud environments.LAPSUS$ initially targeted organizations in the UK and South America, and then expanded ...

2022/3/22
阅读更多

CoinStomp campaign (Campaign)

On 2022-02-02, a campaign was reported, involving CoinStomp operator, gaining initial access via , while using Timestomping, Reverse shell, Cron persistence,. The following tools were observed: CoinStomp.

2022/2/2
阅读更多

From code commit to production takeover (Research)

NCC Group performed a pentest in which they had (notionally) compromised a developer's laptop who could commit code to a certain Java library. The researchers set a pre-requirement file to one that provided a Meterpreter shell from within the target build environment. They fou...

2022/1/13
阅读更多

From S3 bucket to Jenkins credential dump (Research)

NCC Group performed a pentest against a web application, in which they leveraged anonymous access to discover a sitemap folder that turned out to be an S3 bucket with directory listing enabled. NCC identified a bash script containing a hardcoded Git credential, which granted a...

2022/1/13
阅读更多

UNC3379 npm supply chain attacks (Campaign)

Mandiant has attributed supply chain attacks which compromised ua-parser-js , coa, and rc to UNC3379. The malicious packages would download and execute both a Monero cryptocurrency miner, and the DANABOT banking trojan, depending on the OS.

2021/12/15
阅读更多

ivanti-supply-chain (Incident)

On 2021-12-02, an incident was reported, involving an unknown actor, gaining initial access via Supply chain vector, while using Package dependency confusion, to achieve Supply chain attack.

2021/12/2
阅读更多

Tsunami targeting Jenkins and Weblogic (Campaign)

On 2021-10-26, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, 1-day vulnerability, targeting Jenkins, WebLogic to achieve Resource hijacking. The following tools were observed: Tsunami.

2021/10/26
阅读更多

Abcbot Huawei Cloud targeting campaign (Campaign)

On 2021-10-08, a campaign was reported, involving Abcbot operator, gaining initial access via Cloud native misconfig, to achieve Resource hijacking. The following tools were observed: Kunpeng.

2021/10/8
阅读更多

Siloscape campaign (Campaign)

On 2021-06-07, a campaign was reported, involving Siloscape operator, gaining initial access via 1-day vulnerability, Web vulnerability, while using TOR anonymization, Thread impersonation to escape to host, targeting Kubernetes with unknown impact. The following tools were observed: Siloscape.

2021/6/7
阅读更多

Codecov incident (Incident)

On April 2021, Codecov was compromised by an unknown threat actor who abused their access to the company's cloud environment to conduct a supply chain attack. The threat actor gained initial access to Codecov's GCP environment by extracting an HMAC key for a service account fr...

2021/4/15
阅读更多

Multiple organizations vulnerable to dependency confusion (Research)

On 2021-02-09, a research was reported, involving , gaining initial access via Supply chain vector, while using Package dependency confusion, to achieve None.

2021/2/9
阅读更多

Gin Docker cryptojacking campaign (Campaign)

On 2021-02-09, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, while using Escape to host via cgroups release_agent, targeting Docker to achieve Resource hijacking.

2021/2/9
阅读更多

TeamTNT campaigns (Campaign)

On 2021-02-03, a campaign was reported, involving TeamTNT, gaining initial access via ,. The following tools were observed: Peirates, Hildegard.

2021/2/3
阅读更多

dreambus-campaign (Campaign)

See Dreambus operator for more information.

2021/1/22
阅读更多

solarwinds-supply-chain-attack (Campaign)

What seemed to be at first a targeted attack against FireEye, turned out to be a much worse espionage campaign associated with APT29 that the United State has suffered from.The SolarWinds attackers, linked to a Mimecast attack on Jan 13th, executed a sophisticated supply chain...

2020/12/13
阅读更多

Loggerminer campaign (Campaign)

On 2020-11-16, a campaign was reported, involving Abcbot operator, gaining initial access via , to achieve Resource hijacking. The following tools were observed: Loggerminer.

2020/11/16
阅读更多

Apple cloud key exposure (Research)

Between July and October 2020, researchers discovered multiple web vulnerabilities affecting Apple’s network, some of which could have allowed exfiltration of AWS access keys.

2020/10/7
阅读更多

Cetus campaign (Campaign)

On 2020-08-27, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting Docker to achieve Resource hijacking. The following tools were observed: Cetus.

2020/8/27
阅读更多

Drizly data breach (Incident)

Drizly, an online alcohol delivery service, recently notified customers of a data breach in which a hacker accessed customer information. This breach reportedly affected up to 2.5 million accounts, exposing email addresses, dates of birth, and bcrypt-hashed passwords. In some ...

2020/7/28
阅读更多

Doki cryptojacking campaign (Campaign)

On 2020-07-28, a campaign was reported, involving Doki operator, gaining initial access via Software misconfig, while using Exploiting host mount to escape to host, targeting Docker to achieve Resource hijacking.

2020/7/28
阅读更多

Behind the scenes in the Expel SOC: Alert-to-fix in AWS (Incident)

Over the July 4th holiday weekend Expel’s SOC spotted a coin-mining attack in a customer’s Amazon Web Services (AWS) environment. The attacker compromised the root IAM user access key and used it to enumerate the environment and spin up ten (10) c5.4xlarge EC2s to mine Monero....

2020/7/28
阅读更多

Meow database server campaign (Campaign)

On 2020-07-25, a campaign was reported, involving Meow, gaining initial access via Software misconfig, while using FTP access, Misconfigured DB abuse, targeting MongoDB, Elasticsearch, Apache Cassandra, Apache CouchDB, Jenkins, Apache Hadoop to achieve Data destruction.

2020/7/25
阅读更多

BlueKai exposed database (Research)

On 2020-06-19, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.

2020/6/19
阅读更多

Exim exploitation by Sandworm (Campaign)

On May 28, 2020, the NSA released a cybersecurity advisory on Russian APT group Sandworm exploiting CVE-2019-10149, a vulnerability in Exim Mail Transfer Agent (MTA) software. An unauthenticated remote attacker can use this vulnerability to send a specially crafted email to ex...

2020/5/28
阅读更多

Large-scale cryptomining attack against K8s clusters detected by Azure (Campaign)

On 2020-04-08, a campaign was reported, involving an unknown actor, gaining initial access via , targeting Kubernetes to achieve Resource hijacking.

2020/4/8
阅读更多

kinsing-campaign-2020 (Campaign)

On 2020-01-16, a campaign was reported, involving Kinsing operator, gaining initial access via Software misconfig, 1-day vulnerability, while using Vulnerability exploitation, Misconfigured Docker abuse, targeting Redis, Confluence Server, Docker, Apache Hadoop, Solr, ThinkPHP to achieve Resource hijacking. The following tools were observed: Kinsing.

2020/1/16
阅读更多

ubiquiti-breach (Incident)

In 2020, Ubiquiti, a company that manufactures and sells wireless data communication and wired products, suffered a data breach and an extortion attempt of nearly $2 million at the hands of a senior developer working for the company. The attacker set a 1-day retention policy o...

2020/1/1
阅读更多

Graboid campaign (Campaign)

On 2019-10-16, a campaign was reported, involving an unknown actor, gaining initial access via Software misconfig, targeting Docker to achieve Resource hijacking. The following tools were observed: Graboid.

2019/10/16
阅读更多

imperva-data-leak (Incident)

Imperva identified an unknown threat actor using an administrative AWS API key in one of their production AWS accounts, which led to the exposure of an RDS database snapshot from September 2017 containing email addresses of Imperva Cloud WAF customers, hashed & salted password...

2019/10/10
阅读更多

Webmin supply chain attack (2018) (Incident)

An unknown threat actor compromised the Webmin build server, and inserted a backdoor RCE vulnerability into the Webmin source code that anyone could exploit if they were aware of its existence. This backdoor persisted for over 15 months, likely being exploited as a 0day by the...

2019/8/15
阅读更多

capital-one-breach (Incident)

In 2019, Capital One had over 100 million consumer credit applications exfiltrated from their AWS environment. The root cause was a combination of two main factors: first, a Server Side Request Forgery (SSRF) vulnerability in a Web Application Firewall (WAF) named “ModSecurity...

2019/7/19
阅读更多

ngrok cryptojacking campaign (Campaign)

On 2018-09-12, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Redis, Apache CouchDB, Docker, Jenkins, Drupal, MODX to achieve Resource hijacking. The following tools were observed: ngrok.

2018/9/12
阅读更多

US DoD NIPRNet access via Atlassian SSRF (Research)

On 2018-04-09, a research was reported, involving , gaining initial access via 1-day vulnerability, while using SSRF, IMDS abuse, targeting Confluence Server, Jira Server to achieve Resp. disclosure.

2018/4/9
阅读更多

The Los Angeles Times Cryptomining Attack (Incident)

The Los Angeles Times website was covertly mining cryptocurrency on visitors' devices after hackers injected CoinHive's Monero-mining code. This happened due to an unprotected Amazon S3 storage bucket, which allowed unrestricted public access, letting hackers modify site files...

2018/2/22
阅读更多

BrowserStack Data Breach (Incident)

On November 9, 2014, BrowserStack suffered a breach when a hacker accessed an old, unpatched prototype server via the shellshock vulnerability. The server contained AWS credentials, allowing the attacker to create an instance, access a backup, and partially copy user data (ema...

2014/11/9
阅读更多

Operation Windigo (Campaign)

On 2014-03-18, a campaign was reported, involving Windigo operator, gaining initial access via Supply chain vector, while using Create SSH backdoor, to achieve Resource hijacking. The following tools were observed: Ebury.

2014/3/18
阅读更多

Cdorked campaign (Campaign)

On 2013-05-07, a campaign was reported, involving an unknown actor, gaining initial access via Unknown, targeting Apache HTTP Server, NGINX, Lighttpd to achieve Resource hijacking. The following tools were observed: Cdorked.

2013/5/7
阅读更多

kernel.org supply chain attack (Incident)

On 2011-08-31, an incident was reported, involving an unknown actor, gaining initial access via Unknown, to achieve Supply chain attack.

2011/8/31
阅读更多

Operation Aurora (Incident)

On 2010-01-12, an incident was reported, involving Storm-0558, gaining initial access via Unknown, to achieve Data exfiltration.

2010/1/12
阅读更多