09/17

APT28 Operation Phantom Net Voxel - Sekoia.io Blog

https://blog.sekoia.io/apt28-operation-phantom-net-voxel/
APT28 Operation Phantom Net Voxel - Sekoia.io Blog

SonicWall warns customers to reset credentials after breach

https://www.bleepingcomputer.com/news/security/sonicwall-warns-customers-to-reset-credentials-after-MySonicWall-breach/
SonicWall warns customers to reset credentials after breach

Going Underground: China-aligned TA415 Conducts U.S.-China Economic Relations Targeting Using VS Code Remote Tunnels | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/going-underground-china-aligned-ta415-conducts-us-china-economic-relations
Going Underground: China-aligned TA415 Conducts U.S.-China Economic Relations Targeting Using VS Code Remote Tunnels | Proofpoint US

RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains

https://thehackernews.com/2025/09/raccoono365-phishing-network-shut-down.html
RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains

Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims

https://thehackernews.com/2025/09/scattered-spider-resurfaces-with.html
Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/
ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts

https://thehackernews.com/2025/09/chinese-ta415-uses-vs-code-remote.html
Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts

VC giant Insight Partners warns thousands after ransomware breach

https://www.bleepingcomputer.com/news/security/vc-giant-insight-partners-warns-thousands-after-ransomware-breach/
VC giant Insight Partners warns thousands after ransomware breach

Malware development: persistence - part 28. CertPropSvc registry hijack. Simple C/C++ example. - cocomelonc

https://cocomelonc.github.io/persistence/2025/09/14/malware-pers-28.html
Malware development: persistence - part 28. CertPropSvc registry hijack. Simple C/C++ example. - cocomelonc

CrowdStrike Falcon Prevents NPM Package Supply Chain Attacks

https://www.crowdstrike.com/en-us/blog/crowdstrike-falcon-prevents-npm-package-supply-chain-attacks
CrowdStrike Falcon Prevents NPM Package Supply Chain Attacks

CTRL-Z DLL Hooking - SANS Internet Storm Center

https://isc.sans.edu/diary/32294
CTRL-Z DLL Hooking - SANS Internet Storm Center

Details Emerge on Chinese Hacking Operation Impersonating US Lawmaker - SecurityWeek

https://www.securityweek.com/details-emerge-on-chinese-hacking-operation-impersonating-us-lawmaker/
Details Emerge on Chinese Hacking Operation Impersonating US Lawmaker - SecurityWeek

Microsoft: WMIC will be removed after Windows 11 25H2 upgrade

https://www.bleepingcomputer.com/news/microsoft/microsoft-wmic-will-be-removed-after-windows-11-25h2-upgrade/
Microsoft: WMIC will be removed after Windows 11 25H2 upgrade

One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - dirkjanm.io

https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens - dirkjanm.io

What Makes System Calls Expensive: A Linux Internals Deep Dive

https://blog.codingconfessions.com/p/what-makes-system-calls-expensive
What Makes System Calls Expensive: A Linux Internals Deep Dive

North Koreans Targets South With Military ID Deepfakes

https://www.darkreading.com/cyberattacks-data-breaches/north-korean-group-south-military-id-deepfakes
North Koreans Targets South With Military ID Deepfakes

Secure Kernel Research with LiveCloudKd – Winsider Seminars & Solutions Inc.

https://windows-internals.com/secure-kernel-research-with-livecloudkd
Secure Kernel Research with LiveCloudKd – Winsider Seminars & Solutions Inc.

Microsoft: Office 2016 and Office 2019 reach end of support next month

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-2016-and-office-2019-reach-end-of-support-next-month/
Microsoft: Office 2016 and Office 2019 reach end of support next month

Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service

https://www.bleepingcomputer.com/news/security/microsoft-and-cloudflare-disrupt-massive-raccoono365-phishing-service/
Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service