Phishing Campaigns Abuse Trusted Cloud Platforms, Raising New Risks for Enterprises

Phishing campaigns abusing trusted cloud platforms are rising, exposing enterprises to credential theft, account takeover, and supply chain risks by leveraging legitimate infrastructure for malicious delivery. More information here https://hackread.com/phishing-campaigns-cloud-platforms-enterprises-risks/

Continue ReadingPhishing Campaigns Abuse Trusted Cloud Platforms, Raising New Risks for Enterprises

GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace

A new supply chain attack, GlassWorm malware, has been targeting developers on OpenVSX and Microsoft VS Code marketplaces, with over 35,800 installations. For more information, please check here https://www.koi.ai/blog/glassworm-first-self-propagating-worm-using-invisible-code-hits-openvsx-marketplace

Continue ReadingGlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace

Earth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors

APT group Earth Kurma has been targeting government and telecommunications sectors in Southeast Asia in a cyberespionage campaign using advanced malware, rootkits, and trusted cloud services for data exfiltration. Refer https://www.trendmicro.com/en_us/research/25/d/earth-kurma-apt-campaign.html

Continue ReadingEarth Kurma APT Campaign Targets Southeast Asian Government, Telecom Sectors