Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Medium
medium.com > @emirkilicer01 > portal-drop-tryhackme-write-up-462688158564

Portal Drop — TryHackMe Write Up

20+ min ago   (786+ words) A spoiler free SOC investigation using web access logs EDR telemetry and MITRE ATTACK By Emir Kılıçer A WAF alert reports a scan against a public CRM portal …...

Medium
medium.com > @jarmijos12 > dissecting-the-mammoth-phaas-framework-from-saas-hijacking-to-real-time-socket-c2-and-financial-b2df05af940c

Dissecting the “Mammoth” PhaaS Framework: From SaaS Hijacking to Real-Time Socket C2 and Financial…

3+ hour, 19+ min ago   (23+ words) Dissecting the “Mammoth” PhaaS Framework: From SaaS Hijacking to Real-Time Socket C2 and Financial Profiling Threat actors targeting European peer-to-peer e-commerce platforms (specifically …...

Medium
medium.com > @mdfayjulkabir65 > one-click-away-from-account-compromise-what-a-recent-microsoft-365-phishing-campaign-teaches-us-0c11fdfaf365

One Click Away from Account Compromise: What a Recent Microsoft 365 Phishing Campaign Teaches Us

8+ hour, 43+ min ago   (352+ words) Phishing is still one of the simplest ways to target an employee. A message does not always look …...

Medium
medium.com > @xpert4cyber > weworm-the-zero-click-wechat-worm-that-hijacks-accounts-with-just-a-phone-call-97543633eede

WeWorm: The Zero-Click WeChat Worm That Hijacks Accounts With Just a Phone Call

9+ hour, 1+ min ago   (34+ words) WeWorm: The Zero-Click WeChat Worm That Hijacks Accounts With Just a Phone Call Imagine your phone rings. You let it go …...

Crypto Briefing
cryptobriefing.com > solana-mobile-phishing-warning-brevo-breach

Solana Mobile warns users of phishing risks after Brevo breach

21+ hour, 6+ min ago   (387+ words) A SAML SSO vulnerability gave attackers access to 138 customer accounts, with phishing emails reaching hundreds of thousands of crypto users Email marketing platforms are the quiet infrastructure of the internet, the unglamorous pipes that move newsletters and alerts from companies…...

Medium
medium.com > @mandem868 > phishing-to-trick-ai-and-how-to-defend-against-it-367f897f09ec

Phishing To Trick AI And How To Defend Against It

10+ hour, 4+ min ago   (28+ words) CYBERSECURITY Phishing To Trick AI And How To Defend Against It Indirect prompt injection repurposes the content AI assistants ingest as an attack vector. Layered disciplines form the …...

SecurityWeek
securityweek.com > bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

1+ day, 18+ hour ago   (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...

Help Net Security
helpnetsecurity.com > 12/19/2024 > threat-feeds

Are threat feeds masking your biggest security blind spot?

4+ mon, 2+ week ago   (474+ words) Security teams that subscribe to threat feeds get lists of known malicious domains, IPs, and file signatures that they can leverage to blacklist and prevent attacks from those sources. Using network... Are threat feeds masking your biggest security blind spot?...

DEV Community
dev.to > anoymask > fakeagent-macsync-and-amos-distribution-via-legitimate-ai-sharing-pages-1e65

FakeAgent, MacSync, and AMOS Distribution via Legitimate AI Sharing Pages

1+ day, 4+ hour ago   (1540+ words) 1. Basic Information Original Title: How threat actors are turning trusted AI platforms into an attack surface Source: BleepingComputer, Huntress Publication Date: 2026-09-11 Severity: High Basis for Severity: Trusted AI sharing pages are being used to distribute malware via ads and SEO,…...

SOC Prime
socprime.com > active-threats > new-kimsuky-lnk-malware-using-multi-channel-c2-infrastructure

Kimsuky LNK Malware Uses Multi-Channel C2

2+ day, 14+ hour ago   (121+ words) SOC Prime Bias: Critical We are still updating this part. Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim…...