07/24

SonicWall urges admins to patch critical RCE flaw in SMA 100 devices

https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-critical-rce-flaw-in-sma-100-VPN-appliances/
SonicWall urges admins to patch critical RCE flaw in SMA 100 devices

Hangro: Investigating North Korean VPN Infrastructure Part 2 | North Korean Internet

https://nkinternet.wordpress.com/2025/07/16/hangro-investigating-north-korean-vpn-infrastructure-part-2/
Hangro: Investigating North Korean VPN Infrastructure Part 2 | North Korean Internet

Hangro: Investigating North Korean VPN Infrastructure Part 1 | North Korean Internet

https://nkinternet.wordpress.com/2025/01/06/hangro-north-korean-vpn-infrastructure/
Hangro: Investigating North Korean VPN Infrastructure Part 1 | North Korean Internet

BlackSuit ransomware extortion sites seized in Operation Checkmate

https://www.bleepingcomputer.com/news/security/law-enforcement-seizes-blacksuit-ransomware-leak-sites/
BlackSuit ransomware extortion sites seized in Operation Checkmate

[HackerNotes Ep.131] SL Cyber Writeups, Metastrategy & Orphaned Github Commits

https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-131-sl-cyber-writeups-metastrategy-orphaned-github-commits
[HackerNotes Ep.131] SL Cyber Writeups, Metastrategy & Orphaned Github Commits

China-nexus APT Targets the Tibetan Community | ThreatLabz

https://www.zscaler.com/blogs/security-research/illusory-wishes-china-nexus-apt-targets-tibetan-community
China-nexus APT Targets the Tibetan Community | ThreatLabz

Hacker sneaks infostealer malware into early access Steam game

https://www.bleepingcomputer.com/news/security/hacker-sneaks-infostealer-malware-into-early-access-steam-game/
Hacker sneaks infostealer malware into early access Steam game

Hackers breach Toptal GitHub account, publish malicious npm packages

https://www.bleepingcomputer.com/news/security/hackers-breach-toptal-github-account-publish-malicious-npm-packages/
Hackers breach Toptal GitHub account, publish malicious npm packages

NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

https://www.bleepingcomputer.com/news/security/npm-package-is-with-28m-weekly-downloads-infected-devs-with-malware/
NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

DHS impacted in hack of Microsoft SharePoint products, people familiar say - Nextgov/FCW

https://www.nextgov.com/cybersecurity/2025/07/dhs-impacted-hack-microsoft-sharepoint-products-people-familiar-say/406941/
DHS impacted in hack of Microsoft SharePoint products, people familiar say - Nextgov/FCW

Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/
Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog

Microsoft: SharePoint servers also targeted in ransomware attacks

https://www.bleepingcomputer.com/news/security/microsoft-sharepoint-servers-also-targeted-in-ransomware-attacks/
Microsoft: SharePoint servers also targeted in ransomware attacks

oss-fuzz-gen/agent at main · google/oss-fuzz-gen · GitHub

https://github.com/google/oss-fuzz-gen/tree/main/agent
oss-fuzz-gen/agent at main · google/oss-fuzz-gen · GitHub

Understand the SharePoint RCE: Exploitations, Detections, and Mitigations | Akamai

https://www.akamai.com/blog/security-research/sharepoint-vulnerability-rce-active-exploitation-detections-mitigations
Understand the SharePoint RCE: Exploitations, Detections, and Mitigations | Akamai

IDA 9.2 beta 1: A first look - YouTube

https://youtu.be/BeeXHWvCG9M
IDA 9.2 beta 1: A first look - YouTube

Persistence – COM Hijacking – Penetration Testing Lab

https://pentestlab.blog/2020/05/20/persistence-com-hijacking/
Persistence – COM Hijacking – Penetration Testing Lab

Offensive COM Hijacking - YouTube

https://www.youtube.com/watch?v=M_U2neTsSXo
Offensive COM Hijacking - YouTube

CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing

https://thehackernews.com/2025/07/castleloader-malware-infects-469.html
CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing

Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

https://thehackernews.com/2025/07/fire-ant-exploits-vmware-flaw-to.html
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

Mitel warns of critical MiVoice MX-ONE authentication bypass flaw

https://www.bleepingcomputer.com/news/security/mitel-warns-of-critical-mivoice-mx-one-authentication-bypass-flaw/
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw