Topic: persistent access
-
Laundry Bear exploits Exchange zero-day on email open (CVE-2026-42897)
Russia-linked group Laundry Bear is exploiting CVE-2026-42897, a Microsoft Exchange XSS flaw, to breach government and private networks via emails with no malicious links or attachments, making lures difficult to detect. The attack delivers the OWAReaper backdoor that runs in Outlook Web Access, ...
Read More » -
Attackers Use ClickFix and PySoxy Proxying for Persistent Access
Attackers are increasingly using legitimate open-source tools like ClickFix and PySoxy to establish persistent, undetected access after social engineering attacks. ClickFix tricks victims into executing malicious code via deceptive update prompts, while PySoxy provides proxying to mask command-an...
Read More » -
Hotel Wi-Fi malware targets Microsoft 365 logins
Microsoft attributed the CaptiveCrunch cyberattack on hotel and conference Wi-Fi networks to a sub-cluster of Russian state-sponsored group Midnight Blizzard (Storm-2945), which used DNS tampering and phishing to hijack Microsoft 365 credentials since at least May. The campaign deploys two malwar...
Read More » -
Hijacked OAuth Apps: Your Cloud's Secret Backdoor
Cybercriminals exploit internal OAuth applications to create persistent backdoors in corporate cloud systems, bypassing security measures like password resets and multi-factor authentication. Attackers deceive users into approving malicious OAuth apps or compromise admin accounts to create truste...
Read More » -
Kremlin hackers actively exploit critical Exchange server flaw
Russian state-sponsored group TA488 is exploiting a critical Microsoft Outlook Exchange Server vulnerability (CVE-2026-42897) to plant backdoors and steal credentials, with infection triggered simply by opening an email. The attacks use a "half-click" exploit chain ending in a sophisticated new J...
Read More » -
Chinese Tech Firms Tied to Global Salt Typhoon Hacking Campaigns
Three Chinese tech firms are identified as key enablers of the global Salt Typhoon hacking campaigns, supplying tools and services to Chinese state security and military bodies for cyber espionage against governments, telecoms, and critical infrastructure. The hacking campaigns exploit known and ...
Read More » -
Cisco Warns Hackers Exploited Critical Bug Since 2023
Cisco has disclosed a critical, actively exploited vulnerability in its Catalyst SD-WAN Manager software, which allows attackers to remotely compromise networks and gain full administrative control. The flaw poses a severe threat to critical infrastructure, and a coalition of governments has issu...
Read More » -
Google: Cloud Breaches Driven More by Flaws Than Weak Passwords
Exploiting software vulnerabilities has replaced weak passwords as the primary method for breaching cloud environments, accounting for nearly 45% of intrusions as attackers rapidly weaponize new flaws. The window for exploiting disclosed vulnerabilities has collapsed to mere days, with attackers ...
Read More » -
Ransomware Attackers Wipe Azure Data and Backups After Theft
A new wave of cloud-focused ransomware attacks by group Storm-0501 systematically wipes primary data and backups in Microsoft Azure, leaving organizations with no recovery options. The group exploits native cloud functionalities to exfiltrate large volumes of data without on-premises hardware, ma...
Read More »