Fake Microsoft Teams Support Calls Plant Persistent Node.js Backdoors
Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Read article →Chrome 152.0.7977.82/.83 fixes an exploited V8 type-confusion flaw. Google has not disclosed the attackers, targets, exploit chain, or scale.
Read article →A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Read article →Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
Read article →SonicWall confirmed active attacks against two SMA1000 flaws and told customers to hotfix, seek an IoC review, and rebuild systems when compromise is found.
Read article →Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.
Read article →Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
Read article →CISA confirms exploitation of a critical Artifactory flaw and requires federal forensic triage. Self-hosted operators have six fixed-version floors to verify.
Read article →Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts show how to test each evidence plane.
Read article →CISA confirmed exploitation of a 2019 SQL Server flaw and now requires affected systems to be patched after evidence preservation and forensic triage.
Read article →PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
Read article →StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Shadowserver's retrospective Dysphoria report gives network owners 296,000 reasons to identify, rebuild, and verify compromised IoT devices.
Read article →