Chinese state-backed hacking groups have exploited recently disclosed zero-day vulnerabilities in Microsoft SharePoint, compromising over 400 organizations globally—including sensitive U.S. government agencies such as the National Nuclear Security Administration. Despite Microsoft’s release of urgent patches, attackers continue targeting unpatched or end-of-life SharePoint versions using the ToolShell malware, enabling unauthenticated access, lateral movement, and data theft across networks. U.S. CISA has mandated immediate patching, as the victim count keeps rising and variants of the exploit proliferate.
Source: Bloomberg Cyber
Clorox Sues Cognizant After 2023 Breach Exposed Password Lapses in Ransomware Attack
The Clorox Company has filed a $380 million lawsuit against IT services provider Cognizant, alleging catastrophic security negligence that enabled a destructive 2023 breach. According to legal filings, help desk staff reset passwords and bypassed MFA checks after only basic social engineering, letting attackers (Linked to the Scattered Spider/UNC3944 group) seize privileged access, compromise Active Directory, and move laterally to Clorox’s core virtual infrastructure. The case underscores how the human element and weak identity controls remain key enterprise vulnerabilities even amid advanced technical defenses.
Source: ArsTechnica
FBI, CISA Warn of Interlock Ransomware Targeting Critical Infrastructure Sectors
A new advisory warns that the Interlock ransomware group is escalating attacks against critical infrastructure across the U.S. and Europe, hitting sectors such as healthcare and “smart cities.” Interlock uses double extortion, phishing, and even drive-by-downloads via fake system fixes, capitalizing on social engineering to gain entry. Agencies urge organizations to review defenses urgently as the group’s tactics evolve—moving beyond traditional ransomware to blend psychological manipulation with clever technical entry vectors.
Source: CSO Online
Supply Chain Threat: Popular npm Package “is” Compromised with Cross-Platform Malware
The widely-used npm package “is” (with over 2.8M weekly downloads) and several prettier-related lint utilities have been compromised in a sophisticated supply chain attack. Malicious actors stole maintainer tokens via phishing, injected backdoor malware into package updates, and published altered versions to the npm registry—giving attackers full access to developer devices across Windows, macOS, and Linux. This campaign underscores the ongoing risks of open-source dependencies and the growing trend of directly targeting software supply chains through developer ecosystems.
Source: Bleeping Computer
Cisco Identity Services Engine (ISE) Vulnerabilities Under Active Attack—Patch Now
Cisco has confirmed that multiple critical vulnerabilities affecting its Identity Services Engine (ISE) are being actively exploited in the wild. The flaws enable unauthenticated, remote code execution, allowing attackers to take full control of network policy and access control systems. Organizations using Cisco ISE are urged to upgrade immediately and search for signs of compromise, as evidence mounts that attacks are widespread and ongoing across enterprise environments.
Source: CyberScoop
Massive Arrest: Alleged Admin of Notorious Russian-Language Cybercrime Forum XSS Seized
Law enforcement authorities in France and Ukraine, coordinated with Europol, have arrested the suspected administrator of XSS.is—the long-running, Russian-speaking cybercrime forum central to the global trade in stolen data, malware, and illicit hacking services. The takedown, the result of years of investigation and wiretapping, is a major blow to the cybercriminal underground, as XSS.is had over 50,000 users and was a known recruitment platform for major ransomware and intrusion campaigns.
Source: The Hacker News
VMware vSphere/Active Directory Integration Exposes Hypervisors to Targeted Ransomware—Defense Strategies Revealed
New research from Mandiant and Google Threat Intelligence highlights critical risks in integrating VMware vSphere with Active Directory, a widespread practice in enterprise IT. Attackers increasingly exploit AD-linked admin accounts and help desk lapses to pivot directly into hypervisor management planes (vCenter/ESXi)—deploying ransomware, exfiltrating domain databases, and bypassing endpoint detection. Guidance published this week details the anatomy of real attacks (such as those by the Scattered Spider/UNC3944 group), advanced logging, and defense-in-depth strategies to secure virtual infrastructure against this sophisticated kill chain.
Source: Google Cloud Threat Intelligence
You May Also Be Interested In...
CISA warns of hackers exploiting SysAid vulnerabilities in attacks
UK’s Ransomware Payment Ban: Bold Strategy or Dangerous Gamble?
Autoswagger: Open-source tool to expose hidden API authorization flaws