⤷ Title: Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 00:05:13 +0000
════════════════════════
⌗ Tags: #Malware #Bing Ads #Code Signing Abuse #initial access #Malvertising #OysterLoader #ransomware #Rhysida #Trusted Signing
Daily CyberSecurity
Rhysida Ransomware Abuses Microsoft Trusted Signing to Deploy OysterLoader Via Teams Malvertising
Rhysida ransomware is abusing Microsoft Trusted Signing to deploy OysterLoader (IAT) via Bing/Teams malvertising. The gang leveraged 40+ certificates to sign malware, bypassing security filters.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
Penetration Testing Tools
Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
The financially motivated group Storm-0249, long known as a broker of initial access for ransomware operators, has markedly
⤷ Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.
⤷ Title: SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
Daily CyberSecurity
SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
SpaceX is interviewing investment banks for a potential 2026 IPO after its valuation nearly doubled to $800 billion in a secondary sale, fueled by Starlink's growth.
⤷ Title: Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 00:35:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2017_9841 #CVE_2023_26360 #cyber_espionage #GreyNoise #IAB #initial access broker #Japan_based Threat #java #Mass Exploitation
Daily CyberSecurity
Holiday ColdFusion Attacks Reveal Massive 2.5 Million Request Onslaught
GreyNoise reveals a massive Japan-based holiday campaign: 2.5 million attacks targeting 767 CVEs to harvest access for ransomware gangs.
⤷ Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Daily CyberSecurity
Hidden in Plain Sight: TA584 Deploys "Tsundere Bot" & Invisible Registry Keys
TA584 triples activity with new "Tsundere Bot" malware. Attackers use invisible Registry keys to hide persistence. Read the Proofpoint analysis.
⤷ Title: The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
Daily CyberSecurity
The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
Group-IB reveals ShadowSyndicate is evolving. The cybercrime cluster now rotates SSH keys to hide its infrastructure. Is it a BPH or IAB?
⤷ Title: The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:39:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.scr files #BYOVD #Initial Access #JWrapper #persistence #ReliaQuest #Remote Monitoring and Management #RMM tools #screensaver phishing #SpearPhishing #Tech News 2026
Penetration Testing Tools
The Fatal Screensaver: ReliaQuest Unmasks Phishing That Uses .scr Files to Decapitate EDR
Security analysts at ReliaQuest have unmasked a sophisticated phishing campaign wherein adversaries secrete remote access mechanisms within an
⤷ Title: Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
Daily CyberSecurity
Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
New campaign targets Ivanti EPMM with dormant in-memory backdoors. Attackers use CVE-2026-1281 to plant "sleeper" agents. Restart servers immediately.
⤷ Title: Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
Penetration Testing Tools
Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
The compromise of a perimeter network appliance can swiftly shepherd a malefactor toward domain controllers and the enterprise’s
⤷ Title: Signed, Trusted, and Abused: Proxy Execution via WebView2
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #C2 #How_To #Matthew Eidelberg #Red Team #DLL sideloading #initial access
Black Hills Information Security, Inc.
Signed, Trusted, and Abused: Proxy Execution via WebView2 - Black Hills Information Security, Inc.
An offensive security perspective on Microsoft Edge WebView2 Runtime, including architectural weaknesses, existing vulnerabilities, and exploitation methods.
⤷ Title: “Lorem Ipsum” Loader Weaponizing Microsoft Teams via SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
⌗ Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:12:47 +0000
════════════════════════
⌗ Tags: #Malware #BlueVoyant #Code Signing #Cyber Security #DLL Sideloading #infosec #initial access broker #JFIF C2 #Lorem Ipsum Malware #Microsoft Teams #SEO Poisoning #Threat Intel
Daily CyberSecurity
"Lorem Ipsum" Loader Weaponizing Microsoft Teams via SEO Poisoning
BlueVoyant unmasks "Lorem Ipsum": a well-funded campaign using SEO poisoning and signed MS Teams installers to deploy stealthy backdoors via image files.
⤷ Title: KongTuke Abandoning “ClickFix” to Launch Direct Microsoft Teams Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 12:06:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix Lure #Cyber Security #EDR evasion #Help_Desk Impersonation #infosec #initial access broker #KongTuke #Microsoft Teams phishing #ModeloRAT #Script Execution Delay #WinPython Portable
Daily CyberSecurity
KongTuke Abandoning "ClickFix" to Launch Direct Microsoft Teams Attacks
ReliaQuest warns Initial Access Broker "KongTuke" is abusing external Microsoft Teams chats to deploy the highly resilient ModeloRAT. Audit tenants now!
⤷ Title: The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
Information Security News
The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
North Korea’s adversarial presence within the digital theater has transcended the legacy paradigm of isolated, decentralized hacking collectives. Per comprehensive threat intelligence compiled by …
⤷ Title: Romanian Hacker Sentenced to Prison Following Government Cyberattacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:54:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CCIPS #Cybercrime #Department of Justice #FBI Investigation #identity theft #initial access broker #Network Intrusion
Daily CyberSecurity
Romanian Hacker Sentenced to Prison Following Government Cyberattacks
A Romanian hacker sentenced to prison following an identity theft conviction and selling access to a US government network infrastructure.
⤷ Title: DriveSurge Threat Cluster Exploits Thousands of Websites Globally
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 10:54:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #DriveSurge #FakeUpdates #Infrastructure Fingerprinting #initial access broker #malware delivery #social engineering #zTDS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 10:54:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #DriveSurge #FakeUpdates #Infrastructure Fingerprinting #initial access broker #malware delivery #social engineering #zTDS
Daily CyberSecurity
DriveSurge Threat Cluster Exploits Thousands of Websites Globally
The active DriveSurge threat cluster is compromising thousands of websites. Discover how its customized Traffic Distribution System redirects victims.
⤷ Title: FortiBleed Turns Hacked FortiGate Firewalls Into Credential Collectors
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 04:06:14 +0000
════════════════════════
⌗ Tags: #Data Leak #Credential Theft #FortiBleed #FortiGate #FortigateSniffer #Fortinet #Initial Access Broker
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 04:06:14 +0000
════════════════════════
⌗ Tags: #Data Leak #Credential Theft #FortiBleed #FortiGate #FortigateSniffer #Fortinet #Initial Access Broker
Information Security News
FortiBleed Turns Hacked FortiGate Firewalls Into Credential Collectors
FortiBleed began as mass password guessing. Then it grew into an attack chain, where hijacked firewalls gathered fresh credentials for the next breach. A new timeline shows that the published Fort…
⤷ Title: Edgecution Malware Turns a Microsoft Edge Extension Into a Backdoor
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 06:11:32 +0000
════════════════════════
⌗ Tags: #Malware #Edgecution #initial access broker #malicious Edge extension #microsoft edge #Native Messaging #Payouts King ransomware #Python backdoor #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 06:11:32 +0000
════════════════════════
⌗ Tags: #Malware #Edgecution #initial access broker #malicious Edge extension #microsoft edge #Native Messaging #Payouts King ransomware #Python backdoor #Zscaler ThreatLabz
Daily CyberSecurity
Edgecution Malware Turns a Microsoft Edge Extension Into a Backdoor
At a Glance Malware family Edgecution (malicious Microsoft Edge extension plus a Python backdoor) Threat actor Initial access broker assessed as tied to Payouts King ransomware Targets / victims E…
⤷ Title: GoGRPC Backdoor Spreads Through Microsoft Teams Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 08:09:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlindDoor #GoGRPC #initial access broker #Microsoft Teams vishing #Quick Assist #ransomware #RSOX #Vishing #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 08:09:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlindDoor #GoGRPC #initial access broker #Microsoft Teams vishing #Quick Assist #ransomware #RSOX #Vishing #Zscaler ThreatLabz
Daily CyberSecurity
GoGRPC Backdoor Spreads Through Microsoft Teams Vishing
At a glance Actor Unnamed threat actor, likely a ransomware initial access broker Activity Vishing-led intrusion and custom backdoor deployment Targets Corporate and enterprise Windows environment…