Attacker violates Microsoft 365 account using fake OAuth app with Tycoon kit

Cybersecurity researchers detail a cluster of new activities in which threat actors are impersonating fake Microsoft OAuth applications as businesses to promote qualification harvests as part of an account acquisition attack. “Fake Microsoft 365 applications are spoofing a variety of companies, including RingCentral, SharePoint, Adobe, Docusign, and more,” ProofPoint said in a report Thursday. The […]

Malicious NPM packages generated by AI will emit Solana funds from over 1,500 before takedowns

August 1, 2025Ravi LakshmananMalware/Artificial Intelligence Cybersecurity researchers have flagged malicious NPM packages generated using artificial intelligence (AI) to hide cryptocurrency wallet drainers. The package @kodane/patch-manager claims to provide “advanced license verification and registry optimization utility for high-performance node.js applications.” It was uploaded to NPM on July 28, 2025 by a user named “Kodane.” This package […]

Why are your AI security tools only as strong as the data you supply them?

Just as triathletes know that peak performance requires more than expensive gear, cybersecurity teams discover that AI success doesn’t depend on the tools they deploy and more with the data that makes them work Cybersecurity junk food issues Imagine a triathlete who doesn’t spend money on equipment, such as a carbon fiber bicycle, a hydrodynamic […]

Protecting the Python Supply Chain in 2025

The Python ecosystem is under constant threat in 2025. Every month, a new well-known malicious upload set to Python package indexes was discovered. In December 2024, one of the most serious supply chain attacks in recent memory targeted the popular, ultra-high-end Yolo Python package. Supply chain threats such as report jacking, type cutting and slope […]

Storm-2603 deploys DNS-controlled backdoors to Warlock and Lockbit ransomware attacks

August 1, 2025Ravi LakshmananThreat Intelligence/Ransomware The recently disclosed threat actors related to the exploitation of security flaws used a bespoke command and control (C2) framework called AK47 C2 (also spelled AK47C2). This framework includes at least two different types of clients, HTTP-based and Domain Name System (DNS)-based, which are called AK47HTTP and AK47DNS, respectively, by […]

Secret Blizzard deploys malware to ISP-level AITM attacks against the Moscow embassy

July 31, 2025Ravi LakshmananCyberspy/Network Security The Russian nation-state threat actor, known as Secret Blizzard, has been observed to coordinate a new cyberspy campaign targeting foreign embassies in Moscow through enemy (AITM) attacks at the Internet Service Provider (ISP) level, providing custom malware called Apollozadow. “Apolloshadow has the ability to install trusted root certificates on trick […]

Experts detect multi-tier redirect tactics used to steal Microsoft 365 login credentials

July 31, 2025Ravi LakshmananPhishing/Threat Intelligence Cybersecurity researchers have revealed details of a new phishing campaign that hides malicious payloads by bypassing defenses by abuse of link wrapping services from Proofpoint and Intermedia. “Link Lapping is designed by vendors such as Proofpoint to protect users by routing all clicked URLs through the scanning service, allowing them […]

N. Korea’s hackers have stolen millions of people using cryptography using job lures, cloud account access and malware

July 31, 2025Ravi LakshmananCryptocurrency/Malware A North Korea-related threat actor known as UNC4899 has been attributed to attacks targeting two different organizations by approaching employees via LinkedIn and Telegram. “Under the shaming of a freelance opportunity for software development work, UNC4899 has leveraged social engineering techniques to convince targeted employees to run malicious Docker containers on […]

2025 What Gartner® MagicQuadrant™ reveals

Cyber threats and attacks like ransomware continue to increase in volume and complexity as endpoints are usually the most sought after and valuable targets. It is more important than ever to ensure that endpoints are properly protected by a platform that can not only maintain their pace with the rapid expansion and adoption of AI, […]

UNC2891 violates ATM network via 4G Raspberry Pi and attempts Caketap rootkit for fraud

July 31, 2025Ravi Lakshmanan It has been observed that a financially motivated threat actor known as UNC2891 is targeting automatic teller machine (ATM) infrastructure using 4G equipped Raspberry PIs as part of a secret attack. Cyberphysical attacks involved exploiting physical access to install Raspberry PI devices, connecting directly to the same network switch as the […]