Topic: credential dumping

  • Why Your Security Tools Miss Unknown Threats

    Why Your Security Tools Miss Unknown Threats

    Prevention effectiveness rose from 62% to 69% in 2026, but this stack-wide average masks a fragile core where subtle variations of known techniques often bypass defenses. IOC-based testing (checking for known-bad indicators) showed malware download prevention fell to 50%, down from 71% in 2024, w...

    Read More »
  • Former Medusa Affiliate Deploys New StormEncryptor Ransomware

    Former Medusa Affiliate Deploys New StormEncryptor Ransomware

    Microsoft's threat intelligence unit tracks Storm-1175, a China-based actor previously linked to Medusa ransomware, which has now deployed a new custom C++ locker called StormEncryptor that appends ".encrypted" to files and demands payment within 72 hours. The group's recent intrusions likely exp...

    Read More »
  • Sharepoint ToolShell Attacks Strike Global Orgs on 4 Continents

    Sharepoint ToolShell Attacks Strike Global Orgs on 4 Continents

    The ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint is a critical zero-day flaw that allows unauthenticated remote attackers to execute arbitrary code and access file systems, bypassing previous vulnerabilities. Microsoft attributes the exploitation to Chinese threat actors like ...

    Read More »
  • Remote Access Abuse: The #1 Sign of a Ransomware Attack

    Remote Access Abuse: The #1 Sign of a Ransomware Attack

    Abuse of remote access software and services is the most common warning sign of an impending ransomware attack, as cybercriminals exploit tools like RDP, AnyDesk, and PowerShell to gain domain administrator privileges. Key defenses include configuring security tools to allow only trusted applicat...

    Read More »