⤷ Title: Signed Malware Masquerading as Workplace Apps Deploys Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:13:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #EV Certificate Phishing #infosec #malware #MeshAgent #Microsoft Defender #RMM Backdoors #ScreenConnect #Tactical RMM #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:13:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #EV Certificate Phishing #infosec #malware #MeshAgent #Microsoft Defender #RMM Backdoors #ScreenConnect #Tactical RMM #threat intelligence
Daily CyberSecurity
Signed Malware Masquerading as Workplace Apps Deploys Persistent Backdoors
Microsoft Defender exposes a new phishing campaign using EV certificates and fake Teams invites to silently deploy RMM backdoors on corporate networks.
⤷ Title: Leaving the Doors Unlocked: Critical 9.0 CVSS ScreenConnect Flaw Exposes Machine Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 12:07:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise #Cryptographic Keys #CVE_2026_3564 #cybersecurity #infosec #Patch Alert #Remote Access #ScreenConnect #Server Security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 12:07:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise #Cryptographic Keys #CVE_2026_3564 #cybersecurity #infosec #Patch Alert #Remote Access #ScreenConnect #Server Security #Vulnerability
Daily CyberSecurity
Leaving the Doors Unlocked: Critical 9.0 CVSS ScreenConnect Flaw Exposes Machine Keys
A critical 9.0 CVSS vulnerability (CVE-2026-3564) in ConnectWise ScreenConnect exposes server cryptographic keys. On-premise users must update to 26.1 now.
⤷ Title: The “Special Invitation” Trap: STAC6405 Abuses Legitimate RMM Tools to Hijack Your PC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 07:30:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #infosec #LogMeIn Resolve #Microsoft Teams Lure #Norton Mimicry #phishing #Punchbowl Lure #Remote Access #RMM Abuse #ScreenConnect #Sophos MDR #STAC6405
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 07:30:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #infosec #LogMeIn Resolve #Microsoft Teams Lure #Norton Mimicry #phishing #Punchbowl Lure #Remote Access #RMM Abuse #ScreenConnect #Sophos MDR #STAC6405
Daily CyberSecurity
The "Special Invitation" Trap: STAC6405 Abuses Legitimate RMM Tools to Hijack Your PC
Sophos MDR uncovers STAC6405, a phishing campaign abusing RMM tools like LogMeIn for unattended access. Learn how to spot the "Special Invitation" lure.
⤷ Title: New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:21:28 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #Adobe Acrobat #cybersecurity #Fileless Malware #In_Memory Execution #infosec #ScreenConnect #UAC bypass #VBScript Loader #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:21:28 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection #Adobe Acrobat #cybersecurity #Fileless Malware #In_Memory Execution #infosec #ScreenConnect #UAC bypass #VBScript Loader #Zscaler ThreatLabz
Daily CyberSecurity
New Stealth Attack Chain Weaponizes Legitimate Remote Access Software
Zscaler reveals a 2026 attack chain using fake Adobe Reader lures to install ScreenConnect via in-memory execution and UAC bypass. Protect your network now!
⤷ Title: Cyber-Actors are “Laundering Trust” to Hijack the Global Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 08:04:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cargo Diversion #Cyber Reconnaissance #Fleet Payments #infosec #Load Board Phishing #powershell #Proofpoint #RMM Abuse #ScreenConnect #Signing_as_a_Service #Transportation Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 08:04:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cargo Diversion #Cyber Reconnaissance #Fleet Payments #infosec #Load Board Phishing #powershell #Proofpoint #RMM Abuse #ScreenConnect #Signing_as_a_Service #Transportation Security
Daily CyberSecurity
Cyber-Actors are "Laundering Trust" to Hijack the Global Supply Chain
Proofpoint monitors a 30-day supply chain attack using "signing-as-a-service" to bypass Windows security. Protect your load boards and fleet payments now.
⤷ Title: Attackers Hijack Trusted RMM Tools to Create Invisible, Permanent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 08:15:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #infosec #living_off_the_land #persistence #phishing #RMM Hijacking #Safe Mode #ScreenConnect #Securonix #SimpleHelp #social engineering #Threat Hunting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 08:15:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #infosec #living_off_the_land #persistence #phishing #RMM Hijacking #Safe Mode #ScreenConnect #Securonix #SimpleHelp #social engineering #Threat Hunting
Daily CyberSecurity
Attackers Hijack Trusted RMM Tools to Create Invisible, Permanent Backdoors
Securonix exposes an 80+ organization breach using "self-healing" RMM tools and Safe Mode persistence. Standard antivirus is blind—learn how to hunt it!
⤷ Title: Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AMSI Bypass #ConnectWise #Cyber Security #Cyfirma #infosec #JPEG Exploit #Operation SilentCanvas #PowerShell Malware #ScreenConnect #Trojan #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AMSI Bypass #ConnectWise #Cyber Security #Cyfirma #infosec #JPEG Exploit #Operation SilentCanvas #PowerShell Malware #ScreenConnect #Trojan #UAC bypass
Daily CyberSecurity
Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
CYFIRMA warns of Operation SilentCanvas: A weaponized JPEG delivers trojanized ScreenConnect, bypassing AMSI and UAC for full-system surveillance. Stay alert!
⤷ Title: Algorithmic Infiltration: Microsoft Unmasks Generative AI Poisoning in Cryptojacking Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 06:43:30 +0000
════════════════════════
⌗ Tags: #Malware #autorun.dll sideloading exploit #cryptocurrency harvesting evasion techniques #Dynu dynamic DNS infrastructure #Fake hardware monitoring cryptojacker #HWMonitor FurMark cloned malware #Microsoft Defender registry exclusions #poisoned AI chatbot search results #ScreenConnect remote access trojan #SimpleRunPE.exe process injection #smart GPU throttling miner
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 06:43:30 +0000
════════════════════════
⌗ Tags: #Malware #autorun.dll sideloading exploit #cryptocurrency harvesting evasion techniques #Dynu dynamic DNS infrastructure #Fake hardware monitoring cryptojacker #HWMonitor FurMark cloned malware #Microsoft Defender registry exclusions #poisoned AI chatbot search results #ScreenConnect remote access trojan #SimpleRunPE.exe process injection #smart GPU throttling miner
Information Security News
Fake Hardware Monitoring Cryptojacker Hijacks High-End GPUs
Microsoft exposes a stealthy fake hardware monitoring cryptojacker mimicking FurMark and HWMonitor. It masks its GPU usage to avoid detection.
⤷ Title: Sophisticated GPU Cryptojacking Campaign Surfaced by Microsoft Experts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 07:11:24 +0000
════════════════════════
⌗ Tags: #Malware #AI Search Poisoning #GPU Cryptojacking #malware #Microsoft Defender #Process Hollowing #ScreenConnect #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 07:11:24 +0000
════════════════════════
⌗ Tags: #Malware #AI Search Poisoning #GPU Cryptojacking #malware #Microsoft Defender #Process Hollowing #ScreenConnect #threat intelligence
Daily CyberSecurity
Sophisticated GPU Cryptojacking Campaign Surfaced by Microsoft Experts
A stealthy GPU cryptojacking campaign leverages AI search poisoning and process hollowing injection to hijack high-end rigs. Read the Microsoft report.
⤷ Title: ScreenConnect AsyncRAT Campaign Hides Inside Fake Freeware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 12:38:06 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #kaspersky #Malware Campaign #ScreenConnect
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 12:38:06 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #kaspersky #Malware Campaign #ScreenConnect
Daily CyberSecurity
ScreenConnect AsyncRAT Campaign Hides Inside Fake Freeware
At a Glance Malware Family: AsyncRAT Threat Actor: Unknown cybercriminals Target or Victims: Individual consumers and corporate networks Delivery Vector: SEO poisoning and fake freeware portals Ke…
⤷ Title: SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 08:02:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloudflare Tunnel #phishing #RMM Abuse #ScreenConnect #Securonix #SMOKE#SCREEN
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 08:02:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloudflare Tunnel #phishing #RMM Abuse #ScreenConnect #Securonix #SMOKE#SCREEN
Daily CyberSecurity
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
At a Glance Attribute Detail Actor / group Unattributed threat actor (tracked by Securonix as SMOKE#SCREEN) Activity type Multi-wave phishing and RMM abuse for remote access Targets / victims Wind…