Cybersecurity

Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery 

Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery 

A threat actor known as Hazy Hawk has been observed hijacking abandoned cloud resources of high-profile organizations, including Amazon S3 buckets and Microsoft Azure endpoints, by leveraging misconfigurations in the Domain Name System (DNS) records.
The hijacked domains are then used to host URLs that direct users to scams and malware via traffic distribution systems (TDSes), according to

100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads 

100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads 

An unknown threat actor has been attributed to creating several malicious Chrome Browser extensions since February 2024 that masquerade as seemingly benign utilities but incorporate covert functionality to exfiltrate data, receive commands, and execute arbitrary code.
“The actor creates websites that masquerade as legitimate services, productivity tools, ad and media creation or analysis

The AI Fix #51: Divorce by coffee grounds, and why AI robots need your brain 

The AI Fix #51: Divorce by coffee grounds, and why AI robots need your brain 

In episode 51 of The AI Fix, a Greek man’s marriage is destroyed after ChatGPT reads his coffee, a woman dumps her husband to marry an AI called Leo, and Graham wonders whether it’s time to upload his brain into a lunchbox-packing robot.

Meanwhile, a humanoid robot goes full Michael Crawford in a Chinese factory, the UK government launches an AI to read angry public consultations, and Mark dreams of a world where robots finally have common sense – and swear like sailors.

Plus Graham uncovers how AI is wrecking relationships and inventing soulmates, and Mark explains why Google’s Gemini-powered bots might be smarter, more dexterous, and more emotionally stable than most of your exes.

All this and much more is discussed in the latest edition of “The AI Fix” podcast by Graham Cluley and Mark Stockley.

South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware 

South Asian Ministries Hit by SideWinder APT Using Old Office Flaws and Custom Malware 

High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as SideWinder.
“The attackers used spear phishing emails paired with geofenced payloads to ensure that only victims in specific countries received the malicious content,” Acronis researchers Santiago Pontiroli, Jozsef Gegeny, and Prakas

AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation 

AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation 

Cybersecurity researchers have discovered risky default identity and access management (IAM) roles impacting Amazon Web Services that could open the door for attackers to escalate privileges, manipulate other AWS services, and, in some cases, even fully compromise AWS accounts.
“These roles, often created automatically or recommended during setup, grant overly broad permissions, such as full S3

The Crowded Battle: Key Insights from the 2025 State of Pentesting Report 

The Crowded Battle: Key Insights from the 2025 State of Pentesting Report 

In the newly released 2025 State of Pentesting Report, Pentera surveyed 500 CISOs from global enterprises (200 from within the USA) to understand the strategies, tactics, and tools they use to cope with the thousands of security alerts, the persisting breaches and the growing cyber risks they have to handle. The findings reveal a complex picture of progress, challenges, and a shifting mindset

Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization 

Chinese Hackers Deploy MarsSnake Backdoor in Multi-Year Attack on Saudi Organization 

Threat hunters have exposed the tactics of a China-aligned threat actor called UnsolicitedBooker that targeted an unnamed international organization in Saudi Arabia with a previously undocumented backdoor dubbed MarsSnake.
ESET, which first discovered the hacking group’s intrusions targeting the entity in March 2023 and again a year later, said the activity leverages spear-phishing emails using

Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse 

Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse 

Cybersecurity researchers are calling attention to a new Linux cryptojacking campaign that’s targeting publicly accessible Redis servers.
The malicious activity has been codenamed RedisRaider by Datadog Security Labs.
“RedisRaider aggressively scans randomized portions of the IPv4 space and uses legitimate Redis configuration commands to execute malicious cron jobs on vulnerable systems,”

Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts 

Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts 

Cybersecurity researchers have uncovered malicious packages uploaded to the Python Package Index (PyPI) repository that act as checker tools to validate stolen email addresses against TikTok and Instagram APIs.
All three packages are no longer available on PyPI. The names of the Python packages are below –

checker-SaGaF (2,605 downloads)
steinlurks (1,049 downloads)
sinnercore (3,300 downloads)

NEW CUSTOMERS CALL TODAY: 720.221.6804  |  EXISTING CUSTOMERS REQUIRING SUPPORT: 303.617.6442

X