⤷ Title: UNC6040 Threat Actor Exploits Salesforce via Vishing and Malicious Data Loader Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Jun 2025 00:17:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Theft #Cybercrime #data exfiltration #Data Loader #Google Threat Intelligence Group #GTIG #Microsoft 365 #Okta #Salesforce #social engineering #UNC6040 #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Jun 2025 00:17:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Theft #Cybercrime #data exfiltration #Data Loader #Google Threat Intelligence Group #GTIG #Microsoft 365 #Okta #Salesforce #social engineering #UNC6040 #Vishing
Daily CyberSecurity
UNC6040 Threat Actor Exploits Salesforce via Vishing and Malicious Data Loader Apps
UNC6040 is using sophisticated vishing to breach Salesforce, tricking employees into granting access, exfiltrating data, and then pivoting to other cloud platforms.
⤷ Title: Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via “smack” iOS Exploit Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
Daily CyberSecurity
Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via "smack" iOS Exploit Chain
Google exposed Intellexa (Predator spyware vendor) using 15 zero-days since 2021, including the iOS "smack" exploit chain (JSKit). Google is issuing mass warnings to targeted users globally.
⤷ Title: React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:49:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #crypto mining #CVE_2025_55182 #Espionage #GTIG #rce #React Server Components #React2Shell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:49:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #crypto mining #CVE_2025_55182 #Espionage #GTIG #rce #React Server Components #React2Shell #zero_day
Daily CyberSecurity
React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
A critical RCE (CVSS 10.0) in React Server Components (CVE-2025-55182) is under widespread exploitation by China-nexus groups deploying MINOCAT and HISONIC backdoors, plus XMRig miners.
⤷ Title: Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:49:23 +0000
════════════════════════
⌗ Tags: #Malware #Security #backdoor #Carpathian #Cybersecurity #Google #GTIG #Poison Ivy #RomCom #Russia #Stockstay #Vulnerability #WinRAR
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:49:23 +0000
════════════════════════
⌗ Tags: #Malware #Security #backdoor #Carpathian #Cybersecurity #Google #GTIG #Poison Ivy #RomCom #Russia #Stockstay #Vulnerability #WinRAR
Hackread
Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Under Siege: GTIG Report Exposes North Korean Spies & Russian Drone Hacks in Defense Sector
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:50:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT44 #cyber_espionage #Defense Industrial Base #Drone Security #Edge Device Security #Google Threat Intelligence #GTIG #Insider Threat #North Korean IT workers #SANDWORM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:50:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT44 #cyber_espionage #Defense Industrial Base #Drone Security #Edge Device Security #Google Threat Intelligence #GTIG #Insider Threat #North Korean IT workers #SANDWORM
Daily CyberSecurity
Under Siege: GTIG Report Exposes North Korean Spies & Russian Drone Hacks in Defense Sector
GTIG report: Defense Industrial Base faces "constant siege" from Russian drone hackers & North Korean IT insiders. Learn the new threats.
⤷ Title: China-Linked Hackers Use Dell RecoverPoint Flaw to Drop GrimBolt Malware
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 14:52:22 +0000
════════════════════════
⌗ Tags: #Security #China #Dell #GrimBolt #GTIG #Malware #RecoverPoint #UNC6201 #virtual machine
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 14:52:22 +0000
════════════════════════
⌗ Tags: #Security #China #Dell #GrimBolt #GTIG #Malware #RecoverPoint #UNC6201 #virtual machine
Hackread
China-Linked Hackers Use Dell RecoverPoint Flaw to Drop GrimBolt Malware
Hackers exploit Dell RecoverPoint flaw CVE-2026-22769 to deploy GrimBolt malware, prompting urgent security warnings for affected organizations.
⤷ Title: Coruna: The High-Powered iOS Exploit Kit Proliferating Across the Global Threat Landscape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 00:32:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Coruna #Crypto theft #cybersecurity #Google Threat Intelligence Group #GTIG #infosec #iOS Exploit Kit #UNC6353 #UNC6691 #vulnerability management #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 00:32:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Coruna #Crypto theft #cybersecurity #Google Threat Intelligence Group #GTIG #infosec #iOS Exploit Kit #UNC6353 #UNC6691 #vulnerability management #zero_day
Daily CyberSecurity
Coruna: The High-Powered iOS Exploit Kit Proliferating Across the Global Threat Landscape
Google Threat Intelligence uncovers "Coruna", a repurposed iOS exploit kit now used by state-sponsored and financially motivated hackers to steal crypto.