cyberresearch.bsky.social
@cyberresearch.bsky.social
Originally from Red Canary: Bun and done: The second coming of the Shai-Hulud worm ( :-{ı▓ #threatintel #redcanary #cyberresearch
Bun and done: The second coming of the Shai-Hulud worm
Everything you need to know about npm compromises from Shai-Hulud’s latest campaign, including detection and prevention guidance
redcanary.com
December 11, 2025 at 11:36 AM
Originally from Unit 42: Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite ( :-{ı▓ #unit42 #threathunting #cyberresearch
Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite
Hamas-affiliated threat actor Ashen Lepus (aka WIRTE) is conducting espionage with its new AshTag malware suite against Middle Eastern government entities. The post Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite appeared first on Unit 42.
unit42.paloaltonetworks.com
December 11, 2025 at 11:36 AM
Originally from DataDog: Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users ( :-{ı▓ #cloudsecurity #datadog #cyberresearch
Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users
In this post, we investigate a recent phishing campaign that targets Microsoft 365 users.
securitylabs.datadoghq.com
December 11, 2025 at 11:35 AM
Originally from Red Canary: Beyond the bomb: When adversaries bring their own virtual machine for persistence ( :-{ı▓ #threatintel #redcanary #cyberresearch
Beyond the bomb: When adversaries bring their own virtual machine for persistence
We peel back the layers on a threat involving an adversary who brought their own VM into an environment following aggressive spam bombing.
redcanary.com
December 10, 2025 at 11:40 AM
Originally from Unit 42: 01flip: Multi-Platform Ransomware Written in Rust ( :-{ı▓ #unit42 #threathunting #cyberresearch
01flip: Multi-Platform Ransomware Written in Rust
01flip is a new ransomware family fully written in Rust. Activity linked to 01flip points to alleged dark web data leaks. The post 01flip: Multi-Platform Ransomware Written in Rust appeared first on Unit 42.
unit42.paloaltonetworks.com
December 10, 2025 at 11:40 AM
Originally from TrustedSec: Holy Shuck! Weaponizing NTLM Hashes as a Wordlist ( :-{ı▓ #trustedsec #pentesting #cyberresearch
Holy Shuck! Weaponizing NTLM Hashes as a Wordlist
Password reuse is common in Active Directory (AD). From an attacker’s perspective, it is a reliable path to lateral movement or privilege escalation. Most IT teams recognize the risk, but longer passwords and password…
trustedsec.com
December 9, 2025 at 2:05 PM
Originally from PortSwigger: The Fragile Lock: Novel Bypasses For SAML Authentication ( :-{ı▓ #PortSwigger #Burpsuite #cyberresearch
The Fragile Lock: Novel Bypasses For SAML Authentication
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
portswigger.net
December 9, 2025 at 11:42 AM
Originally from Red Canary: Lost in the cloud: What Home Alone 2 teaches us about cloud security ( :-{ı▓ #threatintel #redcanary #cyberresearch
Lost in the cloud: What Home Alone 2 teaches us about cloud security
Home Alone 2 offers some some sage wisdom about cloud security. Here's what defenders can learn from Kevin McCallister.
redcanary.com
December 5, 2025 at 11:54 AM
Originally from DataDog: CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js ( :-{ı▓ #cloudsecurity #datadog #cyberresearch
CVE-2025-55182 (React2Shell): Remote code execution in React Server Components and Next.js
Learn more about the CVE-2025-55182 vulnerability affecting React Server Components and affecting Next.js.
securitylabs.datadoghq.com
December 5, 2025 at 11:53 AM
Originally from TrustedSec: What is a TrustedSec Program Maturity Assessment (PMA)? ( :-{ı▓ #trustedsec #pentesting #cyberresearch
What is a TrustedSec Program Maturity Assessment (PMA)?
The TrustedSec PMA is a tactical approach to evaluating the components, efficiency, and overall maturity of an organization’s Information Security program.Unlike a traditional compliance audit, the PMA is designed as a…
trustedsec.com
December 4, 2025 at 2:08 PM