A newly discovered Linux backdoor dubbed "Plague" is raising alarms after researchers found it evaded detection for over a year. Hidden within a malicious Pluggable Authentication Module (PAM), this backdoor silently bypasses authentication and grants attackers persistent SSH access, making it a formidable threat to enterprise and server environments dependent on secure Linux infrastructures.
Source: TheHackerNews
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attacks
Attackers behind the Akira ransomware are exploiting SonicWall SSL VPN devices—even those fully patched—indicating a likely zero-day vulnerability. The recent surge in incidents highlights the risks organizations face from compromised VPN appliances, potentially granting threat actors initial access for ransomware deployment and data exfiltration.
Source: CISO2CISO
CISA Blasts Critical Infrastructure Organization Over Poor Security Hygiene
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning after uncovering widespread security lapses—including plaintext passwords, shared admin accounts, and poor logging—at an unidentified critical national infrastructure entity. The revelations underscore persistent systemic weaknesses threatening national and economic security, with CISA urging all operators to immediately review their own practices.
Source: The Register
Hackers Phish Microsoft Accounts—Even When Users Click “Cancel”
A cunning new phishing scheme is enabling hackers to take over Microsoft accounts with a 50% success rate, even when users try to abort the process. The attack cleverly bypasses multi-factor authentication (MFA), which is typically considered a strong defense, raising fresh concerns about the effectiveness of common account security measures.
Source: CyberNews
Russian Cyberspies Target Foreign Embassies in Moscow Using AitM Attacks
Microsoft reports that Russian state-sponsored hackers have been conducting adversary-in-the-middle (AitM) attacks against foreign diplomatic personnel in Moscow, deploying a custom malware family dubbed "ApolloShadow." These campaigns, ongoing since at least 2024, underline the increasing sophistication of espionage operations targeting the diplomatic sector.
Source: CISO2CISO
New Attack Uses Windows Shortcut Files to Deliver REMCOS Backdoor
Security researchers warn of a malware campaign leveraging malicious Windows LNK (shortcut) files to install the REMCOS backdoor. By disguising the payload within innocuous-looking files, attackers can gain full system control, posing significant risk for both individual and organizational targets who fall for these traps.
Source: HackRead
Telecoms in Southeast Asia Hit by Sophisticated 10-Month Espionage Campaign
A state-sponsored threat actor identified as CL-STA-0969 has covertly compromised telecommunications organizations in Southeast Asia for 10 months, establishing remote control over critical infrastructure. These intrusions highlight the persistent risk posed by advanced espionage operations against the telecom sector.
Source: TheHackerNews
You May Also Be Interested In... China Presses Nvidia Over Alleged Backdoors in H20 Chips
Google Issues 3 Gmail Security Warnings
Microsoft Recall AI Can Still Capture Sensitive Data