Eggs in a Cloudy Basket: Skeleton Spider’s Trusted Cloud Malware Delivery

FIN6, also known as Skeleton Spider, employs sophisticated social engineering tactics leveraging professional job platforms to distribute the Moreeggs backdoor via cloud-hosted malicious infrastructure. Their campaigns utilize fake resumes, CAPTCHA protections, and environmental filtering to evade detection and deliver ransomware and credential theft malware. #FIN6 #Moreeggs #Skeleton_Spider

Read More
The Hidden Threat in Your Stack: Why Non-Human Identity Management is the Next Cybersecurity Frontier

Modern enterprise networks depend heavily on non-human identities (NHIs) like API keys and service accounts, which are expanding rapidly and presenting significant security risks. Managing and securing NHIs is critical as they are prime targets for cyberattacks, and organizations are increasing their cybersecurity investments accordingly. #NHIs #identitymanagement…

Read More
DanaBleed: DanaBot C2 Server Memory Leak Bug

DanaBot is a Malware-as-a-Service platform active since 2018, known for operating under an affiliate model facilitating banking fraud and credential theft. A memory leak vulnerability named DanaBleed in DanaBot’s C2 server, discovered in 2022, exposed sensitive internal data until the infrastructure was dismantled in 2025 under Operation Endgame. #DanaBot #DanaBleed #OperationEndgame

Read More
Stay Ahead of Cyber Threats Sweeping Container Telemetry data

Trend Vision One™ – Threat Intelligence enhances proactive security by providing retrospective scanning and container-aware visibility to detect past and ongoing threats in diverse environments. It integrates real-time data, MITRE ATT&CK mapping, and automated investigations to enable faster, intelligence-driven incident response. #TrendVisionOne #ThreatInsights #ContainerSecurity…

Read More
Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets

SentinelLABS detected and thwarted reconnaissance and intrusion operations linked to the PurpleHaze and ShadowPad activity clusters, attributed with high confidence to China-nexus threat actors targeting SentinelOne and related organizations. Despite multiple sophisticated attacks between 2024 and 2025, SentinelOne’s infrastructure remained uncompromised, underscoring persistent threats to cybersecurity vendors and global industries. #PurpleHaze #ShadowPad #GOREshell #APT15 #UNC5174

Read More
Spyware maker cuts ties with Italy after government refused audit into hack of journalist’s phone

Paragon, a spyware manufacturer, terminated its contract with Italy after the government committee refused independent verification of alleged misuse against a journalist. The report confirmed Italian intelligence agencies used Paragon’s Graphite spyware, but found no evidence of targeting journalist Francesco Cancellato. #Paragon #Graphite #Italy #COPASIR #Cancellato…

Read More
New hacker group uses LockBit ransomware variant to target Russian companies

A cybercrime group called DarkGaboon has been conducting targeted ransomware attacks on Russian companies across multiple sectors, using LockBit 3.0 ransomware and phishing emails in Russian. Although their methods are similar to other LockBit operations, DarkGaboon operates independently and primarily targets financial departments with malicious documents. #DarkGaboon #LockBit3.0 #RussianCyberattacks…

Read More