Topic: proofpoint research

  • Kremlin hackers actively exploit critical Exchange server flaw

    Kremlin hackers actively exploit critical Exchange server flaw

    Russian state-sponsored group TA488 is exploiting a critical Microsoft Outlook Exchange Server vulnerability (CVE-2026-42897) to plant backdoors and steal credentials, with infection triggered simply by opening an email. The attacks use a "half-click" exploit chain ending in a sophisticated new J...

    Read More »
  • New OAuth Spoofing Attack Exploits Client IDs in Cloud Environments

    New OAuth Spoofing Attack Exploits Client IDs in Cloud Environments

    Cyberattackers are using OAuth client ID spoofing to infiltrate cloud environments via Microsoft Entra ID, exploiting the Resource Owner Password Credentials (ROPC) flow to send POST requests and infer valid credentials and security controls like MFA. This technique evades detection in Entra sign...

    Read More »
  • Chinese hackers deploy new Atlas RAT malware in European attacks

    Chinese hackers deploy new Atlas RAT malware in European attacks

    Chinese-speaking cybercrime group TA4922 has expanded from targeting East Asia to hitting organizations in Germany, Italy, the UK, and South Africa, deploying a new remote access trojan called Atlas RAT and several custom loaders. The group uses localized phishing lures via email and messaging ap...

    Read More »
  • Hackers Now Use Tsundere Bot for Ransomware Attacks

    Hackers Now Use Tsundere Bot for Ransomware Attacks

    The TA584 threat actor has significantly escalated operations, tripling campaign volume in late 2025 and expanding its geographic targeting to include Germany and Australia, while deploying the Tsundere Bot and XWorm trojan to establish network access for ransomware. The group uses a sophisticate...

    Read More »
  • Microsoft 365 Users Hit by Sneaky Device Code Phishing

    Microsoft 365 Users Hit by Sneaky Device Code Phishing

    Attackers are exploiting Microsoft's device code authorization flow to bypass multi-factor authentication, tricking users into granting account access via fraudulent login portals. The campaigns are scaled using readily available red team tools like Squarephish and Graphish, which automate phishi...

    Read More »
  • Hijacked OAuth Apps: Your Cloud's Secret Backdoor

    Hijacked OAuth Apps: Your Cloud's Secret Backdoor

    Cybercriminals exploit internal OAuth applications to create persistent backdoors in corporate cloud systems, bypassing security measures like password resets and multi-factor authentication. Attackers deceive users into approving malicious OAuth apps or compromise admin accounts to create truste...

    Read More »
  • Sextortion Spyware: Webcam Pics Snapped During Porn Viewing

    Sextortion Spyware: Webcam Pics Snapped During Porn Viewing

    A new spyware called Stealerium automates the capture of compromising images by monitoring online activity for adult content keywords and activating the webcam for blackmail. Unlike typical infostealers, Stealerium specifically targets intimate moments to gather deeply personal material, increasi...

    Read More »