Threat Report LUMMA AFFILIATES Cybercriminals operating within a vast information-stealing ecosystem Threat Overview The threat report published by AlienVault on 2025-08-20T18:39:43.148Z titled 'Behind the Curtain: How Lumma Affiliates Operate' provides an in-depth analysis of the complex
Continue ReadingBlog
Legitimate Chrome VPN Extension Turns to Browser Spyware
Threat Report LEGITIMATE CHROME VPN EXTENSION TURNS TO BROWSER SPYWARE A popular Chrome VPN extension with over 100,000 installs has transformed into spyware. Threat Overview A recently published threat report by AlienVault on August 19, 2025,
Continue ReadingMicrosoft 365 Direct Send Abuse Phishing Risks & Security Recommendations
Threat Report MICROSOFT 365 DIRECT SEND ABUSE Threat actors are exploiting Microsoft 365's Direct Send feature to deliver phishing emails, bypassing perimeter security solutions. Threat Overview The threat report published by AlienVault on August 18, 2025,
Continue ReadingSAP Ariba Quote Isnt What It Seems Its Ransomware
Threat Report LeeMe Ransomware Campaign A sophisticated ransomware campaign masquerading as a new SAP Ariba tool. Threat Overview A recently published threat report by AlienVault on August 15, 2025, has uncovered a sophisticated ransomware campaign that
Continue ReadingPhantomCard New NFC-driven Android malware emerging in Brazil
Threat Report PHANTOM CARD A new Android Trojan targeting banking customers in Brazil with potential for global expansion. Threat Overview PhantomCard is a newly identified Android Trojan that specifically targets banking customers in Brazil. This malware
Continue ReadingCoordinated Brute Force Campaign Targets Fortinet SSL VPN
Threat Report COORDINATED BRUTE FORCE CAMPAIGN TARGETS FORTINET SSL VPN A coordinated brute force campaign targeting Fortinet SSL VPNs was observed on August 3, with over 780 unique IPs triggering the Fortinet SSL VPN Bruteforcer tag.
Continue ReadingMalvertising campaign leads to PS1Bot a multi-stage malware framework
Threat Report PS1Bot Malware Framework A sophisticated multi-stage malware implemented in PowerShell and C# Threat Overview A new threat report published by AlienVault on August 12, 2025, highlights a malvertising campaign distributing PS1Bot, an advanced multi-stage
Continue ReadingFrom ClickFix to Command A Full PowerShell Attack Chain
Threat Report From ClickFix to Command: A Full PowerShell Attack Chain A targeted intrusion campaign impacting Israeli organizations has been identified, leveraging compromised internal email infrastructure to distribute phishing messages. Threat Overview The threat report published
Continue ReadingKeys to the Kingdom Erlang OTP SSH Vulnerability Analysis and Exploits Observed in the Wild
Threat Report Erlang/OTP SSH Vulnerability A critical vulnerability (CVE-2025-32433) in Erlang/OTP's SSH daemon allows unauthenticated remote code execution, affecting critical infrastructure and operational technology networks. Threat Overview The threat report published by AlienVault on 2025-08-11T14:56:49.748Z highlights
Continue ReadingExposed JDWP Exploited in the Wild What Happens When Debug Ports Are Left Open
Threat Report Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open Threat Overview The latest threat report from AlienVault, published on 2025-08-08, details a rapid exploitation of an exposed Java Debug
Continue Reading