⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More

Some risks don’t breach the perimeter—they arrive through signed software, clean resumes, or sanctioned vendors still hiding in plain sight. This week, the clearest threats weren’t the loudest—they were the most legitimate-looking. In an environment where identity, trust, and tooling are all interlinked, the strongest attack path is often the one that looks like it […]
Why a modern approach is needed?

Imagine this: you have hardened every laptop in your fleet with real-time telemetry, rapid separation and automatic rollback. However, corporate mailboxes (the front doors of most attackers) are still protected by virtually 1990s filters. This is not a balanced approach. Email remains the main vector of violations, but is treated as a static stream of […]
Scattered spider hijacking vmware esxi deploys ransomware on critical US infrastructure

July 28, 2025Ravi LakshmananCyber Attacks/Ransomware The infamous cybercriminal group known as scattered spiders is targeting VMware ESXi hypervisors in attacks targeting North American retail, airline and transportation sectors. “The group’s core tactics are consistent and do not rely on software exploits. Instead, we use proven playbooks centered around calling the IT help desk,” Google’s Mandiant […]
CISO Guide to SaaS AI Governance

Using AI is spreading faster than security teams can track. You could touch everything in your entire SaaS application. Within 24 hours of Deepseek’s launch, many companies discovered that their employees were already using it despite their strict policies on it. AI promises to increase productivity, but poses serious risks such as: • Non-compliance: Sensitive […]
Critical flaws in Niagara’s framework threaten smart buildings and industrial systems around the world

Cybersecurity researchers have discovered more than 12 security vulnerabilities affecting Tridium’s Niagara framework, which allows attackers on the same network to compromise their systems under certain circumstances. “If the Niagara system is misconfigured, these vulnerabilities are fully exploitable, thereby disabling encryption for certain network devices,” Nozomi Networks Labs said in a report published last week. […]
N. The US sanctions company behind the Korean IT scheme. Arizona woman was jailed to run a laptop farm

July 25th, 2025Ravi LakshmananCybercrime/Insider threat The US Treasury Department’s Office of Foreign Assets Control (OFAC) has approved the North Korean front company and three related individuals for their involvement in a fraudulent remote information technology (IT) worker scheme designed to generate illegal income in Pyongyang. The sanctions targeted South Korean Sobakshu Trade Company (aka Sobakshu […]
Patchwork targets Turkish defense companies with spear phishing using malicious LNK files

July 25th, 2025Ravi LakshmananMalware/Threat Intelligence The threat actor, known as Patchwork, is attributed to a new spear phishing campaign targeting Turkish defense contractors with the goal of gathering strategic information. “The campaign employs a five-stage execution chain delivered via malicious LNK files disguised as a meeting invitation sent to targets interested in learning more about […]
Cyberspy Campaign hits Russian aerospace sector using Eaglet Backdoor

July 25th, 2025Ravi LakshmananCyber Spy/Malware The Russian aerospace and defense industry has been targeted by a cyberspy campaign that offers a backdoor called the Eaglet to promote data delamination. An activity called Operation Cargotalon is assigned to a threat cluster tracked as UNG0901 (short for unknown group 901). “The campaign aims to target employees of […]
SOCO404 and Koske malware target cloud services with cross-platform encryption attacks

July 25th, 2025Ravi LakshmananMalware/Cloud Security Threat Hunter offers cryptocurrency miners by disclosing two different malware campaigns targeting vulnerabilities and misconceptions across cloud environments. The Threat Activity Cluster is called Codo404 and Koske by cloud security companies Wiz and Aqua, respectively. SOCO404 “It targets both Linux and Windows systems and deploys platform-specific malware,” said Wiz researchers […]
Overcoming the risks from using Chinese genai tools

July 25th, 2025Hacker NewsArtificial Intelligence/Data Privacy Recent analysis of enterprise data suggests that generation AI tools developed in China are often widely used by US and UK employees without security team monitoring or approval. The study, conducted by Harmonic Security, also identifies hundreds of instances where sensitive data has been uploaded to a platform hosted […]