Medusa Ransomware: Threat Intelligence Brief TLP: WHITECYBER THREAT INTELLIGENCE BRIEF RANSOMWARE-AS-A-SERVICE THREAT SERIES Medusa
Zero-Days and Critical Flaws: CrowdStrike Falcon, Chrome, Elementor Pro, Super Forms, Plex, Cisco Nexus CrowdStrike Falcon Zero-Day Abuses Macro Remediation for SYSTEM Access A researcher
Trending Topics Critical Vulnerability Roundup: SonicWall, Dropbox, JFrog, and Redis SonicWall SMA1000 zero-days under active attack, a Dropbox breach via a Lenovo identity flaw, Microsoft Defender Safe Links false-flagging Google links, a Redis TLS use-after-free bug, and a critical JFrog Artifactory auth bypass already being exploited.
Trending Topics ServiceNow CVSS 10.0 Flaws, PaperCut Zero-Day, and New Tortoiseshell Malware ServiceNow, PaperCut, and cPanel all patched critical vulnerabilities, one under active exploitation. Plus: malicious Chrome and Edge extensions draining crypto wallets, and Iranian group Tortoiseshell's new SSH tunneling backdoor.
Trending Topics Water Utilities Under Attack, Plus Unauthenticated RCE Flaws in WatchGuard and SonicWall CISA warns of Iranian attacks on exposed water systems, plus critical patches for Ubiquiti UniFi, GitLab EE, WatchGuard Agent, and SonicWall NetExtender Linux Client covering unauthenticated RCE and root-level file-write flaws.
Trending Topics Rust Supply Chain Attack, Entra ID Zero-Day, and Cisco, TrueConf Patches This week: a crates.io compromise spread malware via arrayref, Microsoft fixed an exploited Entra ID zero-day, CISA flagged actively exploited TrueConf Server flaws, FTP-banner malware delivered E4del and PINHOLE, and Cisco patched nine Crosswork/Secure Workload bugs.
Trending Topics KEV Updates, 500+ Ransomware Victims, and a New China-Nexus Campaign Five active threats this week: a fixed Defender bug, an exploited Windows IKE flaw, new CISA KEV adds for macOS/SharePoint/vCenter, Medusa ransomware's 500+ victims, and SilkParasite, a China-linked espionage campaign targeting Central Asia. Patch fast and harden remote access.
Trending Topics Ransomware Evasion, a Nation-State Rootkit, and an Active 0-Day A look at five active threats making news this week, spanning EDR evasion, nation-state tooling, unpatched vulnerabilities, AI-assisted malware development, and IoT botnet activity.
Trending Topics Sessions, Privileges, and the Access Attackers Didn't Earn A quick roundup of what's making waves in security this
Threat Intelligence NoName057(16): Threat Intelligence Brief TLP: WHITECYBER THREAT INTELLIGENCE BRIEF HACKTIVIST THREAT SERIES NoName057(16) A pro-
Trending Topics Stolen Sessions, Borrowed Privilege: Where Attackers Are Focused Right Now This roundup covers vishing, AiTM phishing, a macOS kernel exploit, XSS-to-RCE risk, and a critical Chrome patch, all pointing to the same trend: stolen access over broken security.
Trending Topics This Week in Threat Intelligence: When Trust Becomes the Attack Surface This week's roundup covers five stories with a common thread: