⤷ Title: GOLD SALEM: A New Ransomware Group Is Exploiting SharePoint Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:11:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #CVE_2024_51324 #Cybercrime #EDR evasion #GOLD SALEM #ransomware #Sharepoint #Sophos #Warlock Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:11:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #CVE_2024_51324 #Cybercrime #EDR evasion #GOLD SALEM #ransomware #Sharepoint #Sophos #Warlock Group
Daily CyberSecurity
GOLD SALEM: A New Ransomware Group Is Exploiting SharePoint Flaws
Sophos uncovers GOLD SALEM, a new ransomware group exploiting SharePoint flaws. The group uses EDR evasion and legitimate tools to attack global targets.
⤷ Title: Ensuring Compliance in ICT Projects: Adapting to Australia’s Regulatory Ecosystem
════════════════════════
𐀪 Author: TechBlokes
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 11:38:34 GMT
════════════════════════
⌗ Tags: #sharepoint_solution #ict_project #managed_it_services #cybersecurity #crm
════════════════════════
𐀪 Author: TechBlokes
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 11:38:34 GMT
════════════════════════
⌗ Tags: #sharepoint_solution #ict_project #managed_it_services #cybersecurity #crm
Medium
Ensuring Compliance in ICT Projects: Adapting to Australia’s Regulatory Ecosystem
Australia’s ICT regulatory environment in 2025 is evolving rapidly with stricter requirements under the SOCI Act, Privacy Act reforms, and…
⤷ Title: Warlock Ransomware: How SharePoint Flaws Were Weaponized to Breach Enterprises
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 03:32:50 GMT
════════════════════════
⌗ Tags: #warlock #patch_management #ransomware #sharepoint_vulnerability #cybersecurity
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 03:32:50 GMT
════════════════════════
⌗ Tags: #warlock #patch_management #ransomware #sharepoint_vulnerability #cybersecurity
Medium
Warlock Ransomware: How SharePoint Flaws Were Weaponized to Breach Enterprises
In cybersecurity, the battlefield is rarely where you expect it. Sometimes, it’s not the flashy zero-days or exotic malware strains that…
⤷ Title: Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Oct 2025 00:20:21 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CamoFei #China APT #CVE_2025_53770 #Ransomware_as_a_Service #SharePoint Zero_Day #Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Oct 2025 00:20:21 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CamoFei #China APT #CVE_2025_53770 #Ransomware_as_a_Service #SharePoint Zero_Day #Warlock Ransomware
Daily CyberSecurity
Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
Symantec exposed Warlock ransomware (a probable Anylock rebrand) used by China-linked Storm-2603. It exploits the SharePoint zero-day and BYOVD to disable security and encrypt files with the .x2anylock extension.
⤷ Title: ToolShell Exploit: China-Linked Hackers Target Global Critical Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 09:36:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China_linked #Critical Infrastructure #RCE #SharePoint #ToolShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 09:36:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China_linked #Critical Infrastructure #RCE #SharePoint #ToolShell
Penetration Testing Tools
ToolShell Exploit: China-Linked Hackers Target Global Critical Infrastructure
Hackers exploited the ToolShell SharePoint RCE flaw (CVE-2025-53770) to deploy Zingdoor and ShadowPad in attacks on global telecom and government targets.
⤷ Title: Nuclear Threat: Hackers Breach US Weapons Component Maker via SharePoint Zero-Days
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 08:30:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #APT #China_linked #KCNSC #Nuclear Security #SharePoint RCE #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 08:30:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #APT #China_linked #KCNSC #Nuclear Security #SharePoint RCE #zero_day
Penetration Testing Tools
Nuclear Threat: Hackers Breach US Weapons Component Maker via SharePoint Zero-Days
Government-backed hackers breached a US nuclear component manufacturer (KCNSC) using unpatched SharePoint RCE flaws, accessing sensitive IT and financial data.
⤷ Title: Scammers Sent 40,000 E-Signature Phishing Emails to 6,000 Firms in Just 2 Weeks
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 12:46:42 +0000
════════════════════════
⌗ Tags: #Phishing Scam #Security #Cyber Attack #Cybersecurity #DocuSign #Fraud #Mimecast #Phishing #Privacy #Scam #SharePoint
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 12:46:42 +0000
════════════════════════
⌗ Tags: #Phishing Scam #Security #Cyber Attack #Cybersecurity #DocuSign #Fraud #Mimecast #Phishing #Privacy #Scam #SharePoint
Hackread
Scammers Sent 40,000 E-Signature Phishing Emails to 6,000 Firms in Just 2 Weeks
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.
⤷ Title: The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
Penetration Testing Tools
The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
Researchers at Check Point Research have uncovered a large-scale espionage operation conducted by the Chinese APT group Ink
⤷ Title: MFA Under Siege: Microsoft Unveils Stealthy AiTM Attacks Striking the Energy Sector
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:58:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #BEC #Energy Sector #InfoSec 2026 #MFA Bypass #Microsoft #Microsoft Defender #phishing #Session Hijacking #SharePoint
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:58:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #BEC #Energy Sector #InfoSec 2026 #MFA Bypass #Microsoft #Microsoft Defender #phishing #Session Hijacking #SharePoint
Penetration Testing Tools
MFA Under Siege: Microsoft Unveils Stealthy AiTM Attacks Striking the Energy Sector
Microsoft has disclosed a sophisticated sequence of multi-stage incursions leveraging Adversary-in-the-Middle (AiTM) session hijacking in tandem with Business