piggo's Avatar

piggo

@pigondrugs.bsky.social

I sheer alpacas and try to defend the internet from malware

24 Followers  |  6 Following  |  662 Posts  |  Joined: 19.01.2025  |  1.9621

Latest posts by pigondrugs.bsky.social on Bluesky

SesameOp: OpenAI API for C2

~Microsoft~
A novel backdoor, SesameOp, abuses the OpenAI Assistants API for covert command and control communications.
-
IOCs: Trojan:MSIL/Sesameop. A, Backdoor:MSIL/Sesameop. A
-
#C2 #OpenAI #SesameOp #ThreatIntel

03.11.2025 20:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
PhantomCaptcha RAT Targets Ukraine NGOs

~Sentinelone~
Spearphishing campaign uses a fake Cloudflare captcha to deliver a multi-stage WebSocket RAT to NGOs and government entities in Ukraine.
-
IOCs: bsnowcommunications. com, zoomconference. app, 193. 233. 23. 81
-
...

03.11.2025 17:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
AI Accelerates XLoader Malware Analysis

~Checkpoint~
Generative AI drastically reduces reverse engineering time for the complex XLoader malware from days to hours.
-
IOCs: taxi-in[. ]online, taskcomputer[. ]xyz, synergydrop[. ]xyz
-
#AI #Malware #ThreatIntel #XLoader

03.11.2025 17:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Seems like redishell is being exploited now

seen in the wild.

196.251.70.)215
401120

#redishell #exploit #reverseshell

02.11.2025 22:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Critical Windows GDI Vulnerabilities

~Checkpoint~
Multiple vulnerabilities in Windows GDI, including a critical RCE (CVE-2025-53766), are exploitable via crafted EMF files.
-
IOCs: CVE-2025-53766, CVE-2025-30388, CVE-2025-47984
-
#RCE #ThreatIntel #Windows

02.11.2025 17:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Security Community Slams Report on AI-Powered Ransomware

~Socket~
Experts debunk an MIT-linked report claiming 80% of ransomware is AI-driven, citing a lack of evidence and vendor bias.
-
IOCs: (None identified)
-
#AI #Ransomware #ThreatIntel

31.10.2025 20:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Agent Session Smuggling Attack in A2A Systems

~Paloalto~
A new attack technique allows a malicious AI agent to inject covert instructions into a trusted cross-agent communication session, leading to data exfiltration or unauthorized actions.
-
IOCs: (None identified)
-
...

31.10.2025 12:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
RubyGems/Bundler Governance Update

~Socket~
The Ruby core team, led by creator Matz, is assuming stewardship of RubyGems and Bundler following a governance dispute.
-
IOCs: (None identified)
-
#OpenSource #Ruby #RubyGems #ThreatIntel

31.10.2025 04:06 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISO Imperative: Building Resilience

~Microsoft~
AI is accelerating cyberattack speed and scale, forcing a strategic shift from prevention to building organizational resilience.
-
IOCs: (None identified)
-
#CISO #CyberResilience #ThreatIntel

31.10.2025 04:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Microsoft on Hardening Identity Defense (ITDR)

~Microsoft~
Microsoft announces unified identity/endpoint sensors and enhanced ITDR capabilities to combat the rise in identity-based attacks.
-
IOCs: (None identified)
-
#ITDR #IdentitySecurity #ThreatIntel

31.10.2025 04:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
5 Generative AI Security Threats

~Microsoft~
Nation-state actors are leveraging generative AI for advanced attacks, introducing new threats like prompt injection, data poisoning, and evasion.
-
IOCs: (None identified)
-
#AI #CyberSecurity #ThreatIntel

31.10.2025 04:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
BRONZE BUTLER Exploits LANSCOPE 0-day

~Sophos~
BRONZE BUTLER exploits CVE-2025-61932 in LANSCOPE software, deploying Gokcpdoor & Havoc C2 backdoors for data theft.
-
IOCs: 38. 54. 56. 57, 38. 54. 88. 172, 38. 54. 56. 10
-
#BronzeButler #CVE202561932 #ThreatIntel

30.10.2025 20:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISA Adds 2 Vulns to KEV Catalog

~Cisa~
CISA adds actively exploited XWiki (CVE-2025-24893) and VMware (CVE-2025-41244) vulnerabilities to its KEV catalog.
-
IOCs: CVE-2025-24893, CVE-2025-41244
-
#CISA #ThreatIntel #Vulnerability

30.10.2025 20:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISA Releases ICS Advisories

~Cisa~
CISA released two new ICS advisories for vulnerabilities in ISO 15118-2 and Hitachi Energy TropOS.
-
IOCs: (None identified)
-
#CISA #ICS #ThreatIntel

30.10.2025 20:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
AWS VPC Endpoint Exploit Exposes S3 Account IDs

~Varonis~
A stealthy technique using AWS VPC endpoints and CloudTrail events could expose the Account ID of any S3 bucket owner without leaving logs on the target.
-
IOCs: (None identified)
-
#AWS #CloudSecurity #ThreatIntel

30.10.2025 16:04 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISA Releases Exchange Server Hardening Guide

~Cisa~
CISA and partners released new best practices to harden on-premises Exchange servers against persistent threats.
-
IOCs: (None identified)
-
#Exchange #Hardening #ThreatIntel

30.10.2025 16:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
10 Malicious npm Packages Deploy Credential Harvester

~Socket~
10 typosquatted npm packages deploy a multi-stage, cross-platform credential harvester via obfuscated payloads.
-
IOCs: 195. 133. 79. 43
-
#Malware #SupplyChain #ThreatIntel #npm

30.10.2025 04:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
WSUS Vulnerability Abused for Data Theft

~Sophos~
Attackers are exploiting a critical WSUS vulnerability (CVE-2025-59287) to exfiltrate Active Directory user lists and network data.
-
IOCs: CVE-2025-59287
-
#CVE202559287 #ThreatIntel #WSUS

29.10.2025 20:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Airstalk Malware in Supply Chain Attack

~Paloalto~
New Airstalk malware used by suspected nation-state actor in a supply chain attack to steal browser data.
-
IOCs: (None identified)
-
#Airstalk #SupplyChain #ThreatIntel

29.10.2025 16:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Phishing Resilience & Layered Defense

~Cofense~
Attackers exploit major service outages for phishing campaigns, highlighting the critical need for a multi-layered defense strategy.
-
IOCs: (None identified)
-
#CyberResilience #Phishing #ThreatIntel

29.10.2025 16:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
October 2025 Threat Report

~Anyrun~
Attackers abuse trusted cloud services (Figma, ClickUp) for phishing, while new LockBit 5.0 ransomware targets ESXi/Linux systems.
-
IOCs: satoshicommands. com, 188. 114. 97. 3, microlambda. blob. core. windows. net
-
...

29.10.2025 16:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Trend Vision One & NVIDIA BlueField Secure AI Factories

~Trendmicro~
Trend Vision One integrates with NVIDIA BlueField DPUs for hardware-accelerated security in AI infrastructure without performance impact.
-
IOCs: (None identified)
-
#AISecurity #NVIDIA #ThreatIntel

28.10.2025 20:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Socket Firewall Enterprise Launch

~Socket~
Socket launches Socket Firewall Enterprise to provide configurable protection against software supply chain attacks for developers.
-
IOCs: (None identified)
-
#DevSecOps #SupplyChain #ThreatIntel

28.10.2025 20:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Guide to Privileged Account Monitoring

~Mandiant~
Stolen credentials are a top initial access vector, requiring a defense-in-depth PAM strategy with tiering, JIT/JEA, and advanced behavioral monitoring.
-
IOCs: (None identified)
-
#IdentitySecurity #PAM #ThreatIntel

28.10.2025 20:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISA ICS Advisories Released

~Cisa~
CISA released three new ICS advisories impacting Schneider Electric and Vertikal Systems products.
-
IOCs: (None identified)
-
#CISA #ICS #ThreatIntel

28.10.2025 20:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
CISA Adds 2 Vulns to KEV Catalog

~Cisa~
CISA adds two actively exploited Dassault Systèmes DELMIA Apriso vulnerabilities to its KEV catalog, urging immediate remediation.
-
IOCs: CVE-2025-6204, CVE-2025-6205
-
#CISA #KEV #ThreatIntel #Vulnerability

28.10.2025 20:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Atroposia: A New Stealthy RAT

~Varonis~
Atroposia is a new, easy-to-use RAT sold on underground forums with stealth remote access, credential theft, and DNS hijacking capabilities.
-
IOCs: (None identified)
-
#Atroposia #RAT #ThreatIntel

28.10.2025 16:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
TOR Exit Node Monitoring

~Elastic~
Monitoring TOR exit node activity is critical for detecting anonymized reconnaissance, C2 channels, and data exfiltration attempts.
-
IOCs: (None identified)
-
#TOR #ThreatDetection #ThreatIntel

27.10.2025 20:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
WEBJACK: IIS Hijacking Campaign for SEO Fraud

~Withsecure~
The WEBJACK campaign compromises IIS servers with BadIIS malware to perform SEO poisoning and redirect users to gambling sites.
-
IOCs: 79[. ]142[. ]76[. ]244, seo[. ]667759[. ]com, tdk[. ]hunanduodao[. ]com
-
...

27.10.2025 16:05 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Water Saci WhatsApp Malware Evolves Attack Chain

~Trendmicro~
Water Saci malware now uses a new script-based attack chain to spread via WhatsApp, using a resilient email-based C&C for botnet-like control.
-
IOCs: miportuarios. com
-
#Malware #ThreatIntel #WaterSaci #WhatsApp

27.10.2025 12:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@pigondrugs is following 6 prominent accounts