⤷ Title: Citrix Bleed 2: ReliaQuest Warns of Active Exploitation in NetScaler Gateway Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 00:30:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ADC #Citrix #Citrix Bleed 2 #CVE_2025_5777 #cybersecurity #Gateway #MFA Bypass #NetScaler #out_of_bounds read #ReliaQuest #Session Hijacking #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 00:30:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ADC #Citrix #Citrix Bleed 2 #CVE_2025_5777 #cybersecurity #Gateway #MFA Bypass #NetScaler #out_of_bounds read #ReliaQuest #Session Hijacking #Vulnerability
Daily CyberSecurity
Citrix Bleed 2: ReliaQuest Warns of Active Exploitation in NetScaler Gateway Vulnerability
Citrix Bleed 2 (CVE-2025-5777, CVSS 9.2) is actively exploited to hijack sessions and bypass MFA on NetScaler ADC/Gateway. Patch immediately to prevent covert access and data theft.
⤷ Title: Urgent Citrix Bleed 2 (CVE-2025-5777, CVSS 9.3) Actively Exploited: MFA Bypass & Session Hijacking Threaten Enterprises
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:41:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #ADC #Citrix #Citrix Bleed 2 #CVE_2025_5777 #cybersecurity #Gateway #MFA Bypass #NetScaler #Out_of_Bounds Read #ReliaQuest #Session Hijacking #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:41:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #ADC #Citrix #Citrix Bleed 2 #CVE_2025_5777 #cybersecurity #Gateway #MFA Bypass #NetScaler #Out_of_Bounds Read #ReliaQuest #Session Hijacking #vulnerability
Penetration Testing Tools
Urgent Citrix Bleed 2 (CVE-2025-5777, CVSS 9.3) Actively Exploited: MFA Bypass & Session Hijacking Threaten Enterprises
Citrix Bleed 2 (CVE-2025-5777, CVSS 9.3) is actively exploited to hijack sessions and bypass MFA on NetScaler ADC/Gateway. Patch immediately to prevent covert access and data theft.
⤷ Title: Scattered Lapsus$ Hunters Attack Zendesk Users with 40+ Fake SSO Phishing Portals
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:17:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Customer Support #phishing #ReliaQuest #Scattered LapSus Hunters #SSO #supply chain attack #Typosquatting #Zendesk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:17:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Customer Support #phishing #ReliaQuest #Scattered LapSus Hunters #SSO #supply chain attack #Typosquatting #Zendesk
Penetration Testing Tools
Scattered Lapsus$ Hunters Attack Zendesk Users with 40+ Fake SSO Phishing Portals
ReliaQuest specialists have uncovered more than forty fraudulent domains masquerading as Zendesk portals, attributing them to the cyber-criminal
⤷ Title: Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
Penetration Testing Tools
Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
The financially motivated group Storm-0249, long known as a broker of initial access for ransomware operators, has markedly
⤷ Title: The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
Penetration Testing Tools
The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
Security analysts at ReliaQuest have unmasked a sophisticated phishing campaign wherein adversaries secrete remote access mechanisms within an
⤷ Title: Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:28:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23760 #CVE_2026_24423 #Email Security #living_off_the_land #Patch Alert #ReliaQuest #SmarterMail #Storm_2603 #Velociraptor #Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:28:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23760 #CVE_2026_24423 #Email Security #living_off_the_land #Patch Alert #ReliaQuest #SmarterMail #Storm_2603 #Velociraptor #Warlock Ransomware
Daily CyberSecurity
Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware
Storm-2603 exploits SmarterMail vulnerability CVE-2026-23760 to deploy Warlock ransomware. Upgrade to Build 9511 immediately to prevent system compromise.
⤷ Title: The Invisible Hijack: How AI-Powered “DeepLoad” Malware Vanishes into Your Lock Screen
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 07:43:00 +0000
════════════════════════
⌗ Tags: #Malware #AI cybersecurity #ClickFix #Credential Theft #DeepLoad #Fileless Attack #LockAppHost.exe #Malware 2026 #Powershell obfuscation #ReliaQuest #WMI Persistence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 07:43:00 +0000
════════════════════════
⌗ Tags: #Malware #AI cybersecurity #ClickFix #Credential Theft #DeepLoad #Fileless Attack #LockAppHost.exe #Malware 2026 #Powershell obfuscation #ReliaQuest #WMI Persistence
Penetration Testing Tools
The Invisible Hijack: How AI-Powered "DeepLoad" Malware Vanishes into Your Lock Screen
A solitary click upon a purported “error rectification” within a browser may precipitate the absolute compromise of a
⤷ Title: Persistent Exposure: How OP-512 Exploits Legacy IIS Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 03:39:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET compilation bug #Chinese espionage tools #custom web shells #legacy IIS server hack #OP_512 threat group #ReliaQuest cyber report
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 03:39:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET compilation bug #Chinese espionage tools #custom web shells #legacy IIS server hack #OP_512 threat group #ReliaQuest cyber report
Information Security News
OP-512 Threat Group: New Legacy IIS Attacks
Discover how the OP-512 threat group targets legacy IIS servers. Learn about their bespoke web shells, Potato tools, and ReliaQuest defense tips.
⤷ Title: OP-512: China-Linked Hackers Hit IIS Servers With New Tool
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #OP_512 #ReliaQuest #Web Shell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 07:03:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #OP_512 #ReliaQuest #Web Shell
Daily CyberSecurity
OP-512: China-Linked Hackers Hit IIS Servers With New Tool
An AI Agent Spots What Analysts Might Have Missed ReliaQuest Threat Research has identified a new espionage group it calls OP-512, and the discovery itself is part of the story. According to the r…
⤷ Title: Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
Daily CyberSecurity
Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
At a glance Actor / group Helix (suspected ties to BlackFile and ShinyHunters) Activity type Data extortion through identity-based intrusion Targets / victims Enterprises; high-visibility staff an…
⤷ Title: Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:43:57 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #APT28 #Cyber Attack #Cybersecurity #Fancy Bear #Forest Blizzard #Hotels #Microsoft #Microsoft 365 #Phishing #ReliaQuest #Scam #WIFI
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:43:57 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #APT28 #Cyber Attack #Cybersecurity #Fancy Bear #Forest Blizzard #Hotels #Microsoft #Microsoft 365 #Phishing #ReliaQuest #Scam #WIFI
Hackread
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
⤷ Title: Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
Daily CyberSecurity
Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
At a glance Actor Unnamed operator; ReliaQuest notes tradecraft similar to APT28 (Fancy Bear, Forest Blizzard) but does not attribute the campaign Activity type Gateway compromise, DNS poisoning, …