Topic: attack persistence
-
What Attackers Do After a Break-In
A Huntress investigation revealed a post-breach attack where the intruder gained entry via SQL injection, then methodically established persistence by enabling RDP, creating an admin account, and disabling Windows Defender. The attacker weaponized the compromised server by installing BadIIS web m...
Read More » -
Supply-Chain Attack Targeted Checkmarx and Bitwarden
Checkmarx suffered a supply-chain attack on March 19 via compromised Trivy GitHub accounts, and then its own GitHub account was breached on March 23, pushing malware to its customers. The malware attacks persisted, with a second wave on April 22 indicating the initial breach was never fully resol...
Read More » -
New ClickFix Attack Uses nslookup to Steal Data via DNS
Attackers have evolved ClickFix campaigns to weaponize DNS queries as a primary, stealthy delivery channel, tricking users into running a command that fetches and executes a malicious script from a rogue server. The attack chain involves a malicious nslookup command that retrieves a PowerShell sc...
Read More » -
Beware Fake PayPal Alerts: Hackers Steal Logins, Deploy Malware
A sophisticated cyberattack uses fake PayPal security alerts, starting with phishing emails and escalating through phone-based social engineering to install malware. Attackers abuse legitimate remote monitoring tools like LogMeIn Rescue and AnyDesk to gain persistent access, evading detection by ...
Read More » -
New ChatGPT Data Breach Exposes AI's Vicious Cycle
AI safety often relies on reactive patches for specific exploits, rather than addressing underlying systemic vulnerabilities, creating a cycle of temporary fixes. The "ZombieAgent" exploit against ChatGPT demonstrated a severe flaw, covertly extracting private data from servers and persisting acr...
Read More » -
Microsoft: Hackers Steal University Payroll in Pirate Attacks
Storm-2657, a cybercrime group, has been targeting U.S. university payroll systems since March 2025, primarily compromising Workday accounts through sophisticated social engineering and exploiting weak multifactor authentication. The attackers use highly customized phishing emails, such as fake c...
Read More » -
Stealth Malware Campaign Infects Thousands via DNS TXT Abuse
The Detour Dog malware campaign has infected over 30,000 websites, using DNS TXT records for server-side attacks that remain hidden from most users, selectively targeting specific visitors for redirection or malware downloads. This attack operates by having compromised servers send DNS queries wi...
Read More »