Beware of hidden risks in the Entra environment

When inviting guest users to your Entra ID tenant, you can open yourself up to amazing risk. The access control gap in Microsoft Entra subscription handling allows guest users to create and transfer subscriptions to invited tenants, allowing them to maintain full ownership of them. All guest users’ needs are permission to create subscriptions in […]

SonicWall Netextender Trojan and ConnectWise exploits used in remote access attacks

June 25th, 2025Ravi LakshmananVPN Security/Malware An unknown threat actor distributed a troilerized version of the SSL VPN Netextender application on SonicWall and stole credentials from unsuspecting users who may have installed it. “NetExtender allows remote users to securely connect and run applications on their company network,” said Sravan Ganachari, a researcher at SonicWall. “Users can […]

North Korea-related supply chain attacks target developers with 35 malicious NPM packages

June 25th, 2025Ravi LakshmananMalware/Open Source Cybersecurity researchers have discovered fresh batches of malicious NPM packages linked to an ongoing infectious interview operation that emerged from North Korea. According to Socket, the ongoing supply chain attacks include 35 malicious packages uploaded from 24 npm accounts. These packages have been downloaded collectively over 4,000 times. The complete […]

Microsoft will expand security updates for Windows 10 for a year with new registration options

June 25th, 2025Ravi LakshmananEndpoint Security / IT Management On Tuesday, Microsoft announced it is extending the Windows 10 Extended Security Update (ESU) with additional extensions. The development will officially terminate security updates for devices running Windows 10 and will stop security updates ahead of the upcoming Tech Giant deadline of October 14, 2025. The desktop […]

Researchers find ways to shut down CryptoMiner campaigns using bad stocks and Xmrogue

June 24, 2025Ravi LakshmananMalware/Cryptocurrency Cybersecurity researchers have detailed two new methods that can be used to destroy cryptocurrency mining botnets. The method utilizes the design of various common mining topologies to close the mining process, Akamai said in a new report published today. “We have developed two methods by leveraging mining topology and pooling policies, […]

Hackers target over 70 Microsoft Exchange servers and steal credentials via keyloggers

June 24, 2025Ravi LakshmananVulnerability/Malware It has been observed that unidentified threat actors target publicly exposed Microsoft Exchange servers and inject malicious code into login pages that collect qualifications. In a new analysis released last week, Positive Technology said it identified two types of keylogger codes listed in JavaScript on its Outlook login page. Those who […]

CTEM conversations we all need

June 24, 2025Ravi LakshmananThreat Exposure Management There was honor of hosting the first episode of Xposure Podcast Live from Xposure Summit 2025. And we couldn’t ask for a better kickoff panel. Let me introduce them. Alex Delay, CISO at IDB Bank, knows what it means to advocate for a highly regulated environment. Ben Mead, director […]

Hackers misuse misunderstood Docker API to mine cryptocurrency via Tor Network

June 24, 2025Ravi LakshmananCloud Security/Crypto Jacking Misunderstood Docker instances are the target of campaigns that employ the TOR Anonymous Network to stealthily mine cryptocurrency in sensitive environments. “Attackers use the misunderstood Docker API to access containerized environments and mask activity while using Tor to deploy cryptominers,” trending microscientists Sunil Bharti and Shubham Singh said in […]

US Homes ban WhatsApp on Official Devices Over Security and Data Protection Issues

June 24, 2025Ravi LakshmananData Protection/Mobile Security The U.S. House of Representatives has formally banned members of Congressional staff from using WhatsApp on government-issued devices, citing security concerns. Development was first reported by Axios. The decision was motivated by concerns about the security of the app, according to the House Chief Management Officer (CAO). “The Cybersecurity […]