05/23

TikTok videos now push infostealer malware in ClickFix attacks

https://www.bleepingcomputer.com/news/security/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/
TikTok videos now push infostealer malware in ClickFix attacks

Sliver EDR Bypass: Customizing Open Source Tools - Cyber Security Services - London

https://fortbridge.co.uk/research/reforging-sliver-how-simple-code-edits-can-outmaneuver-edr/
Sliver EDR Bypass: Customizing Open Source Tools - Cyber Security Services - London

Project Zero: The Windows Registry Adventure #7: Attack surface analysis

https://googleprojectzero.blogspot.com/2025/05/the-windows-registry-adventure-7-attack-surface.html
Project Zero: The Windows Registry Adventure #7: Attack surface analysis

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

https://thehackernews.com/2025/05/300-servers-and-35m-seized-as-europol.html
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

Operation ENDGAME strikes again: the ransomware kill chain broken at its source | Europol

https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-strikes-again-ransomware-kill-chain-broken-its-source
Operation ENDGAME strikes again: the ransomware kill chain broken at its source | Europol

DanaBot Botnet Disrupted, 16 Suspects Charged - SecurityWeek

https://www.securityweek.com/danabot-botnet-disrupted-by-law-enforcement-16-suspects-charged/
DanaBot Botnet Disrupted, 16 Suspects Charged - SecurityWeek

Anthropic's new AI model turns to blackmail when engineers try to take it offline | TechCrunch

https://techcrunch.com/2025/05/22/anthropics-new-ai-model-turns-to-blackmail-when-engineers-try-to-take-it-offline/
Anthropic's new AI model turns to blackmail when engineers try to take it offline | TechCrunch

How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation – Sean Heelan's Blog

https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/
How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation – Sean Heelan's Blog

Windows 11 Notepad gets AI-powered text writing capabilities

https://www.bleepingcomputer.com/news/microsoft/windows-11-notepad-gets-ai-powered-text-writing-capabilities/
Windows 11 Notepad gets AI-powered text writing capabilities

OffensiveCon-2025-Breaking-the-Sound-Barrier.pdf

https://www.dillonfrankesecurity.com/OffensiveCon-2025-Breaking-the-Sound-Barrier.pdf
OffensiveCon-2025-Breaking-the-Sound-Barrier.pdf

China-Nexus Threat Actor Actively Exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) Vulnerability

https://blog.eclecticiq.com/china-nexus-threat-actor-actively-exploiting-ivanti-endpoint-manager-mobile-cve-2025-4428-vulnerability
China-Nexus Threat Actor Actively Exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) Vulnerability

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

https://thehackernews.com/2025/05/gitlab-duo-vulnerability-enabled.html
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

Russian Qakbot Gang Leader Indicted in US - SecurityWeek

https://www.securityweek.com/russian-qakbot-gang-leader-indicted-in-us/
Russian Qakbot Gang Leader Indicted in US - SecurityWeek

OffensiveCon25 - Dillon Franke - YouTube

https://youtu.be/USQtPedx9Xg?feature=shared
OffensiveCon25 - Dillon Franke - YouTube

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

https://thehackernews.com/2025/05/cisa-warns-of-suspected-broader-saas.html
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

Office of Public Affairs | Leader of Qakbot Malware Conspiracy Indicted for Involvement in Global Ransomware Scheme | United States Department of Justice

https://www.justice.gov/opa/pr/leader-qakbot-malware-conspiracy-indicted-involvement-global-ransomware-scheme
Office of Public Affairs | Leader of Qakbot Malware Conspiracy Indicted for Involvement in Global Ransomware Scheme | United States Department of Justice

FBI warns of Luna Moth extortion attacks targeting law firms

https://www.bleepingcomputer.com/news/security/fbi-warns-of-luna-moth-extortion-attacks-targeting-law-firms/
FBI warns of Luna Moth extortion attacks targeting law firms

Hacker steals $223 million in Cetus Protocol cryptocurrency heist

https://www.bleepingcomputer.com/news/security/hacker-steals-223-million-in-cetus-protocol-cryptocurrency-heist/
Hacker steals $223 million in Cetus Protocol cryptocurrency heist