⤷ Title: Venom Spider Evolves: Arctic Wolf Exposes More_eggs Campaign Targeting HR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:46:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Arctic Wolf #backdoor #HR Phishing #JavaScript Obfuscation #LOLBAS #Polymorphic Malware #Resume Malware #TA4557
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:46:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Arctic Wolf #backdoor #HR Phishing #JavaScript Obfuscation #LOLBAS #Polymorphic Malware #Resume Malware #TA4557
Daily CyberSecurity
Venom Spider Evolves: Arctic Wolf Exposes More_eggs Campaign Targeting HR
Arctic Wolf exposes Venom Spider’s More_eggs campaign, where fake resumes and polymorphic JavaScript target HR to deploy a stealthy backdoor.
⤷ Title: CVE-2024-7399: Samsung MagicINFO Vulnerability Now Actively Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 22:28:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #CMS vulnerability #CVE_2024_7399 #JSP upload #Remote Code Execution #Samsung MagicINFO #unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 22:28:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #CMS vulnerability #CVE_2024_7399 #JSP upload #Remote Code Execution #Samsung MagicINFO #unauthenticated RCE
Daily CyberSecurity
CVE-2024-7399: Samsung MagicINFO Vulnerability Now Actively Exploited in the Wild
CVE-2024-7399 vulnerability actively exploited in Samsung MagicINFO 9 Server allows remote code execution. Arctic Wolf reports in-the-wild attacks. Upgrade now!
⤷ Title: Arctic Wolf Exposes “GIFTEDCROOK”: China-Linked APT Launches Evolving Cyber-Espionage on Ukraine Military
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 03:55:34 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf Labs #China #Cyber Espionage #Data Exfiltration #GIFTEDCROOK #Government #malware #Military #phishing #threat intelligence #UAC_0226 #Ukraine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 03:55:34 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf Labs #China #Cyber Espionage #Data Exfiltration #GIFTEDCROOK #Government #malware #Military #phishing #threat intelligence #UAC_0226 #Ukraine
Penetration Testing Tools
Arctic Wolf Exposes "GIFTEDCROOK": China-Linked APT Launches Evolving Cyber-Espionage on Ukraine Military
Arctic Wolf Labs reveals UAC-0226 (China-linked) is using evolving GIFTEDCROOK malware in cyber-espionage against Ukrainian military and government, exfiltrating sensitive documents.
⤷ Title: SEO Poisoning Campaign Targets IT Pros: Fake PuTTY & WinSCP Sites Deliver “Oyster” Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:46:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arctic Wolf #Backdoor #Broomstick #CleanUpLoader #cybersecurity #Fake Installers #IT Professionals #malware #Oyster #PuTTY #SEO Poisoning #WinSCP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:46:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arctic Wolf #Backdoor #Broomstick #CleanUpLoader #cybersecurity #Fake Installers #IT Professionals #malware #Oyster #PuTTY #SEO Poisoning #WinSCP
Penetration Testing Tools
SEO Poisoning Campaign Targets IT Pros: Fake PuTTY & WinSCP Sites Deliver "Oyster" Backdoor
Arctic Wolf uncovers an SEO poisoning campaign using fake PuTTY and WinSCP sites to deliver the "Oyster" backdoor via trojanized installers, targeting IT professionals.
⤷ Title: GRU Unit 29155 Uses SocGholish to Target US Firm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 02:14:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Arctic Wolf Labs #cyber_espionage #GRU Unit 29155 #Malware_as_a_Service #Mythic Agent #RomCom #russia #SocGholish #TA569 #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 02:14:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Arctic Wolf Labs #cyber_espionage #GRU Unit 29155 #Malware_as_a_Service #Mythic Agent #RomCom #russia #SocGholish #TA569 #Ukraine
Daily CyberSecurity
GRU Unit 29155 Uses SocGholish to Target US Firm
Arctic Wolf Labs reveals Russian GRU Unit 29155 using SocGholish to deploy RomCom malware against a US firm with ties to Ukraine.
⤷ Title: The SSO Trap: How a “Default” Feature is Granting Attackers Admin Access to FortiGate Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:55:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #CVE_2025_59718 #CVE_2025_59719 #Cyberattack 2025 #FortiCloud #Fortinet #FortiOS #network security #SAML #SSO
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:55:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #CVE_2025_59718 #CVE_2025_59719 #Cyberattack 2025 #FortiCloud #Fortinet #FortiOS #network security #SAML #SSO
Penetration Testing Tools
The SSO Trap: How a "Default" Feature is Granting Attackers Admin Access to FortiGate Devices
Arctic Wolf reports the first confirmed intrusions into customer networks in which attackers logged into FortiGate devices via
⤷ Title: Surgical Silence: The New Fortinet Zero-Day That Hijacks Firewalls in Seconds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:54:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #cloud_init@mail.io #CVE_2026_24858 #FortiCloud SSO #FortiGate #Fortinet #SAML exploit #secadmin #zero_day 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:54:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #cloud_init@mail.io #CVE_2026_24858 #FortiCloud SSO #FortiGate #Fortinet #SAML exploit #secadmin #zero_day 2026
Penetration Testing Tools
Surgical Silence: The New Fortinet Zero-Day That Hijacks Firewalls in Seconds
Cybersecurity specialists at Arctic Wolf have identified a nascent wave of incursions targeting Fortinet FortiGate firewalls. Adversaries are
⤷ Title: Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 03:58:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #BeyondTrust #CISA KEV #CVE_2026_1731 #lateral movement #Patch Alert #Privileged Remote Access #Remote Support #RMM #SimpleHelp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 03:58:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #BeyondTrust #CISA KEV #CVE_2026_1731 #lateral movement #Patch Alert #Privileged Remote Access #Remote Support #RMM #SimpleHelp
Daily CyberSecurity
Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
Arctic Wolf warns of CVE-2026-1731, a critical BeyondTrust flaw exploited in the wild. Attackers use it to deploy backdoors. Patch self-hosted instances now.
⤷ Title: The BurrowShell Threat: Inside ‘Sloppy Lemming’s’ Stealthy Cyber Espionage Campaign in South Asia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Arctic Wolf #BurrowShell #Critical Infrastructure #cyber_espionage #cybersecurity #infosec #Malware Analysis #Sloppy Lemming #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Arctic Wolf #BurrowShell #Critical Infrastructure #cyber_espionage #cybersecurity #infosec #Malware Analysis #Sloppy Lemming #threat intelligence
Daily CyberSecurity
The BurrowShell Threat: Inside 'Sloppy Lemming's' Stealthy Cyber Espionage Campaign in South Asia
Arctic Wolf details a year-long cyber espionage campaign by Sloppy Lemming, deploying the custom BurrowShell malware against Pakistan and Bangladesh.
⤷ Title: Under the Radar: How the SloppyLemming Syndicate Infiltrated South Asia’s Nuclear and Energy Sectors
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 07:40:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arctic Wolf #Bangladesh #BurrowShell #ClickOnce #Cyberespionage #DLL Sideloading #Pakistan #Rust RAT #SloppyLemming #South Asia #Tech News 2026 #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 07:40:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arctic Wolf #Bangladesh #BurrowShell #ClickOnce #Cyberespionage #DLL Sideloading #Pakistan #Rust RAT #SloppyLemming #South Asia #Tech News 2026 #threat intelligence
Penetration Testing Tools
Under the Radar: How the SloppyLemming Syndicate Infiltrated South Asia’s Nuclear and Energy Sectors
Over the past year, South Asia has witnessed a marked proliferation of cyberespionage offensives targeting state apparatuses and