Intelligence Bulletin – How Murky Panda has revolutionized cloud attacks through Microsoft Entra ID

Chinese group Murky Panda exploits cloud trust relationships and abuses Microsoft Entra ID, compromising suppliers and SaaS to steal data.

VN Extraordinary – Windows Server Message Block (SMB)

Microsoft patched CVE-2025-55234 (CVSS 8.8) in Windows SMB, a flaw enabling relay attacks and privilege escalation. Classified as a zero-day, it was disclosed before the official patch.

Largest npm supply chain attack in history hits packages with 2.6 billion weekly downloads

🔴 Largest npm supply chain attack compromised 18 critical packages (chalk, debug, ansi-styles), impacting billions of installs and targeting cryptocurrency theft.

HVL – 21/08 a 03/09

The top 10 critical vulnerabilities from the past 15 days impact Citrix, WinRAR, Apple, WhatsApp, Fortinet, FreePBX, Git, SharePoint and CrushFTP. Many are under active exploitation and demand immediate patching.

OT-ICS Monthly NDV – August/2025

Critical vulnerabilities in OT and ICS environments were identified, posing risks to industrial operations and demanding quick response.

HVL – High-Risk Vulnerabilities List – Aug 7 to Aug 21

Top 10 critical flaws in Cisco, Fortinet, Trend Micro, WinRAR, PostgreSQL & VirtualBox. Several actively exploited — patch now.

VN Extraordinary – WinRAR

A critical WinRAR for Windows flaw is being exploited by the Russian RomCom group in spear-phishing campaigns, enabling system compromise simply by extracting files.

Intelligence Bulletin – Tycoon 2FA: AiTM Attacks via Quishing Compromise MFA in Brazilian Companies

Sophisticated QR-based phishing is bypassing MFA and hijacking corporate sessions. A growing threat to organizations.

VN Extraordinary – Trend Micro Apex One

Two critical flaws in Trend Micro Apex One are under active exploitation, allowing unauthenticated remote code execution. No official patch yet, but a mitigation tool is available.

Privacy Overview
SEK

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Additional Cookies

This website uses the following additional cookies:

(List the cookies that you are using on the website here.)