04/07

URLhaus | almeida.clientepj.com

https://urlhaus.abuse.ch/host/almeida.clientepj.com/
URLhaus | almeida.clientepj.com

EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher

https://www.bleepingcomputer.com/news/security/encrypthubs-dual-life-cybercriminal-vs-windows-bug-bounty-researcher/
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher

Malicious VSCode extensions infect Windows with cryptominers

https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/
Malicious VSCode extensions infect Windows with cryptominers

Code reuse in the age of kCET and HVCI - Slowerzs' blog

https://blog.slowerzs.net/posts/keyjumper/
Code reuse in the age of kCET and HVCI - Slowerzs' blog

Microsoft delays WSUS driver sync deprecation indefinitely

https://www.bleepingcomputer.com/news/microsoft/microsoft-delays-wsus-driver-sync-deprecation-indefinitely/
Microsoft delays WSUS driver sync deprecation indefinitely

Food giant WK Kellogg discloses data breach linked to Clop ransomware

https://www.bleepingcomputer.com/news/security/food-giant-wk-kellogg-discloses-data-breach-linked-to-clop-ransomware/
Food giant WK Kellogg discloses data breach linked to Clop ransomware

MalwareBazaar | SHA256 a9b6aaaea37305c58e2076e65663542c0506ff4440a0fdec32e7ac618d6d4ef1 (LummaStealer)

https://bazaar.abuse.ch/sample/a9b6aaaea37305c58e2076e65663542c0506ff4440a0fdec32e7ac618d6d4ef1/
MalwareBazaar | SHA256 a9b6aaaea37305c58e2076e65663542c0506ff4440a0fdec32e7ac618d6d4ef1 (LummaStealer)

CERT-UA

https://cert.gov.ua/article/6282946
CERT-UA

Xintra APT Emulation Lab - Husky Corp

https://bri5ee.sh/blue%20team/2025/04/07/xintra-apt-emulation-lab-husky-corp.html
Xintra APT Emulation Lab - Husky Corp

⚡ Weekly Recap: VPN Exploits, Oracle's Silent Breach, ClickFix Surge and More

https://thehackernews.com/2025/04/weekly-recap-vpn-exploits-oracles.html
⚡ Weekly Recap: VPN Exploits, Oracle's Silent Breach, ClickFix Surge and More

PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks

https://thehackernews.com/2025/04/poisonseed-exploits-crm-accounts-to.html
PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks

NIST Puts Pre-2018 CVEs on Back Burner as It Works to Clear Backlog - SecurityWeek

https://www.securityweek.com/nist-puts-pre-2018-cves-on-back-burner-as-it-works-to-clear-backlog/
NIST Puts Pre-2018 CVEs on Back Burner as It Works to Clear Backlog - SecurityWeek

E-ZPass toll payment texts return in massive phishing wave

https://www.bleepingcomputer.com/news/security/toll-payment-text-scam-returns-in-massive-phishing-wave/
E-ZPass toll payment texts return in massive phishing wave

Potential RCE via missing `msgspec-python313-pre` dependency · Advisory · nhairs/python-json-logger · GitHub

https://github.com/nhairs/python-json-logger/security/advisories/GHSA-wmxh-pxcx-9w24
Potential RCE via missing `msgspec-python313-pre` dependency · Advisory · nhairs/python-json-logger · GitHub

Windows 11 24H2 blocked on PCs with code-obfuscation driver BSODs

https://www.bleepingcomputer.com/news/security/windows-11-24h2-blocked-on-pcs-with-code-obfuscation-driver-bsods/
Windows 11 24H2 blocked on PCs with code-obfuscation driver BSODs