MalwareInfosecurity Magazine·1 month ago

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

Researchers have discovered that HollowGraph malware leverages Microsoft 365 calendars and Microsoft Graph APIs to establish covert command-and-control communications, exploiting legitimate cloud services to evade detection. The malware has been linked to the Cavern framework, indicating a coordinated approach to using cloud-based calendar systems as an alternative C2 infrastructure.

Automate Volatility 3 Memory Analysis with This Tool

13Cubed·2.8K views · 1 month ago

In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 02:18 - Demo 🛠 Resources VolGolangWrapper:

Data BreachCheck Point Research·1 month ago

20th July – Threat Intelligence Report

Ernst & Young disclosed a data breach involving a compromised third-party IT support platform, with exposed support tickets potentially containing client documents and tax information. Check Point Research's weekly threat intelligence bulletin for July 20th covers this incident along with other significant cyber attacks and breaches discovered that week.

I got inside FIFA’s Secret World Cup Broadcast Network

NetworkChuck·513K views · 1 month ago

HackTheBox Logging

IppSec·8.4K views · 1 month ago

00:00 - Introduction 01:05 - Start of nmap 03:50 - Grabbing files off the open share, looking at logs and seeing an error message that contains an old credential 07:50 - Using BloodyAD to pull information from the account to see password last set, also running BloodHound 09:45 - Running Certipy, then using JQ to show me certificates with non-default groups/accounts in enrollment 12:25 - Going over Bloodhound, showing our SVC_RECOVERY can take over MSA_HEALTH$ 16:30 - Showing BloodyAD to allow ourselves read access to the MSA_HEALTH$ password, could also do Shadow Credentials 20:30 - Getting on the box with WinRM, discovering Monitor.ps1 file. Use COM to look at scheduled task 24:30 - Using MSFVenom to create a malicious DLL, zip it up and upload wait for the scheduled task to execute it 32:40 - Got access to Jaylee Clifton, using Rubeus tgtdeleg to get us a Kerberos ticket so we can run commands as them on our box 38:45 - Using Certipy to confirm the server is vulnerable to ESC17 41:45 - Looking at WSUS Config, discover things are pointed to wsus.logging.htb which does not exist 46:10 - Using Certipy to create a certificate that can impersonate wsus.logging.htb 49:00 - Setting up WSUKS to push a malicious windows update

VulnerabilityGraham Cluley·1 month ago

Google’s Gemini lets strangers send messages from your locked Android phone

Google's Gemini AI assistant on Android devices can be exploited to send messages from a locked phone without authorization, potentially allowing anyone with physical access to impersonate the device owner. This vulnerability undermines the security protections that locked phones are designed to provide, creating a risk for message-based attacks and social engineering. The issue highlights the need for stricter authentication controls when AI assistants have access to sensitive device functions.

Microsoft Spying in 2026 is crazy and VPN can't help!

PC Security Channel·150K views · 1 month ago
Data BreachInfosecurity Magazine·1 month ago

23andMe Faces New Security Mandates in $18m Data Breach Settlement

23andMe has agreed to an $18 million settlement with 42 US state attorneys general stemming from its 2023 data breach. The settlement includes mandatory enhancements to the company's data protection practices going forward. This action represents coordinated enforcement by state-level regulators against the genetic testing company for the security incident.

OtherBishop Fox·1 month ago

Using MCP Agents for Penetration Testing

AI-powered MCP agents are accelerating penetration testing workflows by automating reconnaissance and vulnerability discovery across external, application, and cloud environments. In a real-world deployment, Bishop Fox leveraged this approach to uncover two information leaks comprising over 12 million records in a fraction of the traditional timeframe, demonstrating significant efficiency gains over conventional testing methodologies.

VulnerabilityUnit 42·1 month ago

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Unit 42 has published a technical analysis documenting three chained zero-day vulnerabilities affecting Siemens ROX II OT switches that can be exploited to achieve privilege escalation and maintain persistent root access. The vulnerability chain demonstrates a complete attack path through these industrial network devices, highlighting a significant threat to operational technology infrastructure.

RansomwareGraham Cluley·1 month ago

Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

PhishingInfosecurity Magazine·1 month ago

Phishing Campaign Hides Lua Loader as TrueType Font File

A widespread phishing campaign is using TrueType font files as a disguise to deliver a Lua-based loader, which subsequently deploys remote access trojans and information-stealing malware to compromised systems. This obfuscation technique leverages file type spoofing to evade detection while establishing a foothold for follow-on malicious payloads across multiple targets globally.

MalwareInfosecurity Magazine·1 month ago

Modular macOS Stealer Uses Kill Loops to Force Password Entry

A new modular macOS stealer called ClickLock employs kill loops to lock victims out of their systems and coerce password entry. The malware forces users to surrender credentials by repeatedly terminating processes until they comply with the attacker's demands.

Policy & LegalInfosecurity Magazine·1 month ago

"Selfish Bravado" Behind TfL Cyber-Attack, Judge Says as Pair Jailed

Two individuals responsible for the 2024 cyber-attack against Transport for London have been sentenced to five and a half years in prison after pleading guilty to Computer Misuse Act violations. According to the judge, the attackers were motivated by what was characterized as selfish bravado rather than ideological or financial objectives.

Load more