- Cyber Threat Intelligence, Intelligence Bulletin
Intelligence Bulletin – How Murky Panda has revolutionized cloud attacks through Microsoft Entra ID
Chinese group Murky Panda exploits cloud trust relationships and abuses Microsoft Entra ID, compromising suppliers and SaaS to steal data.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – Windows Server Message Block (SMB)
Microsoft patched CVE-2025-55234 (CVSS 8.8) in Windows SMB, a flaw enabling relay attacks and privilege escalation. Classified as a zero-day, it was disclosed before the official patch.
- Cyber Threat Intelligence, Emergency Announcement
Largest npm supply chain attack in history hits packages with 2.6 billion weekly downloads
🔴 Largest npm supply chain attack compromised 18 critical packages (chalk, debug, ansi-styles), impacting billions of installs and targeting cryptocurrency theft.
- Cyber Threat Intelligence, Trending Vulnerabilities List
HVL – 21/08 a 03/09
The top 10 critical vulnerabilities from the past 15 days impact Citrix, WinRAR, Apple, WhatsApp, Fortinet, FreePBX, Git, SharePoint and CrushFTP. Many are under active exploitation and demand immediate patching.
- Notificação de Vulnerabilidades OT/ICS
OT-ICS Monthly NDV – August/2025
Critical vulnerabilities in OT and ICS environments were identified, posing risks to industrial operations and demanding quick response.
- Cyber Threat Intelligence, Trending Vulnerabilities List
HVL – High-Risk Vulnerabilities List – Aug 7 to Aug 21
Top 10 critical flaws in Cisco, Fortinet, Trend Micro, WinRAR, PostgreSQL & VirtualBox. Several actively exploited — patch now.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – WinRAR
A critical WinRAR for Windows flaw is being exploited by the Russian RomCom group in spear-phishing campaigns, enabling system compromise simply by extracting files.
- Cyber Threat Intelligence, Intelligence Bulletin
Intelligence Bulletin – Tycoon 2FA: AiTM Attacks via Quishing Compromise MFA in Brazilian Companies
Sophisticated QR-based phishing is bypassing MFA and hijacking corporate sessions. A growing threat to organizations.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – Trend Micro Apex One
Two critical flaws in Trend Micro Apex One are under active exploitation, allowing unauthenticated remote code execution. No official patch yet, but a mitigation tool is available.