<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CyberMaterial: Alerts]]></title><description><![CDATA[Find the latest cybersecurity alerts from patches, and updates to newest threat actors.]]></description><link>https://www.cybermaterial.com/s/alerts</link><image><url>https://substackcdn.com/image/fetch/$s_!nNgF!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c57d21-5644-4f88-bf07-ea44d2603e80_482x482.png</url><title>CyberMaterial: Alerts</title><link>https://www.cybermaterial.com/s/alerts</link></image><generator>Substack</generator><lastBuildDate>Thu, 18 Jun 2026 15:10:21 GMT</lastBuildDate><atom:link href="https://www.cybermaterial.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[CyberMaterial]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cybermaterial@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cybermaterial@substack.com]]></itunes:email><itunes:name><![CDATA[CyberMaterial]]></itunes:name></itunes:owner><itunes:author><![CDATA[CyberMaterial]]></itunes:author><googleplay:owner><![CDATA[cybermaterial@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cybermaterial@substack.com]]></googleplay:email><googleplay:author><![CDATA[CyberMaterial]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Critical Command Execution Flaw Patched in Cisco ISE]]></title><description><![CDATA[Cisco has released security patches for a critical vulnerability in its Identity Services Engine (ISE) platform that could allow authenticated attackers to execute arbitrary commands and gain root-level access to the underlying operating system.]]></description><link>https://www.cybermaterial.com/p/critical-command-execution-flaw-patched</link><guid isPermaLink="false">https://www.cybermaterial.com/p/critical-command-execution-flaw-patched</guid><pubDate>Thu, 18 Jun 2026 12:17:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CVlF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CVlF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CVlF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!CVlF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!CVlF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!CVlF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CVlF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:782800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202570272?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CVlF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!CVlF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!CVlF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!CVlF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6471020-c1c3-4c94-84db-aa8b14b61558_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Cisco has released security patches for a critical vulnerability in its Identity Services Engine (ISE) platform that could allow authenticated attackers to execute arbitrary commands and gain root-level access to the underlying operating system. The flaw represents a significant security risk for organizations relying on Cisco ISE for network access control and policy enforcement.<br><br>The vulnerability exists due to insufficient validation of user-supplied input within the ISE application. This weakness in input handling creates an opportunity for attackers who have already obtained valid credentials to inject malicious commands that the system processes without proper security checks.<br><br>Successful exploitation allows an authenticated attacker to break out of the application layer and interact directly with the underlying operating system. Once this initial access is achieved, the attacker can then escalate their privileges to root, giving them complete administrative control over the affected ISE deployment. This level of access would enable attackers to modify security policies, intercept authentication data, or use the compromised system as a pivot point for further network intrusion.<br><br>The impact of this vulnerability is particularly severe for enterprise environments where Cisco ISE serves as a central authentication and authorization platform. A compromised ISE deployment could undermine an organization's entire network security posture, potentially allowing attackers to bypass access controls, modify user permissions, or gain unauthorized access to sensitive network segments.<br><br>Cisco has made patches available to address this vulnerability. Security teams should prioritize applying these updates to all ISE deployments as soon as possible. Organizations should also review their ISE access logs for any suspicious authentication patterns or unusual administrative activity that might indicate attempted or successful exploitation. As an additional precaution, administrators should verify that ISE administrative access is restricted to trusted users and protected by strong authentication mechanisms.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/  </p>]]></content:encoded></item><item><title><![CDATA[CISA Orders Feds to Patch Critical Joomla Plugin Flaw]]></title><description><![CDATA[The U.S.]]></description><link>https://www.cybermaterial.com/p/cisa-orders-feds-to-patch-critical</link><guid isPermaLink="false">https://www.cybermaterial.com/p/cisa-orders-feds-to-patch-critical</guid><pubDate>Thu, 18 Jun 2026 12:16:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!w6g2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w6g2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w6g2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!w6g2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!w6g2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!w6g2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w6g2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1337a448-3dec-41ca-880a-61eab00aba50_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:882107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202570130?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w6g2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!w6g2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!w6g2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!w6g2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337a448-3dec-41ca-880a-61eab00aba50_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability in the Widget Factory Joomla Content Editor plugin to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch the flaw by a specified deadline. The vulnerability, tracked as CVE-2024-56359, carries a maximum CVSS severity score and is confirmed to be under active exploitation in the wild.<br><br>The JCE plugin is a widely used content editor for Joomla websites, providing enhanced editing capabilities for site administrators and content creators. This particular vulnerability affects versions of the plugin prior to the patched release, making thousands of Joomla installations potentially vulnerable to attack. The flaw's presence in such a common component amplifies the risk across the broader web ecosystem.<br><br>CVE-2024-56359 allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems without requiring any user interaction or valid credentials. This type of vulnerability represents one of the most severe security risks, as successful exploitation grants attackers complete control over affected web servers. Attackers can leverage this access to steal sensitive data, install malware, modify website content, or use compromised servers as launching points for further attacks.<br><br>The addition to CISA's KEV catalog signals that threat actors are already exploiting this vulnerability in real-world attacks. Federal agencies face mandatory patching deadlines under Binding Operational Directive 22-01, which requires remediation of known exploited vulnerabilities within specified timeframes. The active exploitation status means attackers have developed working exploit code and are scanning for vulnerable installations.<br><br>Organizations running Joomla websites with the JCE plugin should immediately verify their plugin version and apply available security updates. Website administrators should check their Joomla extension manager for updates to the JCE plugin and install the patched version without delay. Beyond patching, organizations should review web server logs for signs of compromise, monitor for unusual administrative activity, and consider implementing web application firewalls as an additional protective layer while patches are deployed.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-joomla-plugin-flaw-by-friday/ </p>]]></content:encoded></item><item><title><![CDATA[FBI warns of crypto scam couriers collecting cash]]></title><description><![CDATA[The FBI has issued an alert about an escalation in cryptocurrency investment fraud, where scammers are dispatching couriers to collect cash directly from victims at their homes.]]></description><link>https://www.cybermaterial.com/p/fbi-warns-of-crypto-scam-couriers</link><guid isPermaLink="false">https://www.cybermaterial.com/p/fbi-warns-of-crypto-scam-couriers</guid><pubDate>Wed, 17 Jun 2026 12:18:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3axJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3axJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3axJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!3axJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!3axJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!3axJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3axJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:717152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202423868?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3axJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!3axJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!3axJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!3axJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25cb0833-c3bc-4f9c-b5bc-2e6d07309690_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><span>The FBI has issued an alert about an escalation in cryptocurrency investment fraud, where scammers are dispatching couriers to collect cash directly from victims at their homes. This tactic represents a significant shift from traditional remote-only fraud schemes and introduces additional physical risk to victims.<br><br>The scams typically begin with contact through social media platforms, text messages, or dating apps, where fraudsters pose as investment advisors or romantic interests. Victims are gradually convinced to invest in cryptocurrency through what appear to be legitimate trading platforms. These platforms display fake account balances and fabricated investment returns designed to build trust and encourage victims to deposit increasingly larger sums.<br><br>When victims attempt to transfer funds and their financial institutions flag or block the suspicious transactions, scammers adapt their approach. They tell victims that cash collection is the only way to continue their investments or that in-person payments are required to cover taxes, fees, or other charges before they can access their supposed profits. The courier pickup method allows scammers to bypass banking security measures that might otherwise prevent the fraud.<br><br>The physical component of these schemes creates additional dangers beyond financial loss. Victims who allow strangers into their homes or meet them at other locations face potential safety risks. The courier tactic also makes it more difficult for law enforcement to trace the funds, as cash transactions leave fewer digital footprints than electronic transfers.<br><br>The FBI recommends that individuals be extremely skeptical of unsolicited investment opportunities, particularly those involving cryptocurrency. Anyone contacted by supposed investment advisors through social media should verify their credentials through independent sources. Most importantly, legitimate investment firms never send couriers to collect cash payments, and any request for in-person cash pickup should be treated as a clear warning sign of fraud. Victims or potential victims should report suspicious activity to the FBI's Internet Crime Complaint Center.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.helpnetsecurity.com/2026/06/16/crypto-scammers-couriers-cash-pickups-fbi-warning/ </p>]]></content:encoded></item><item><title><![CDATA[DragonForce abuses Microsoft Teams relays]]></title><description><![CDATA[The DragonForce ransomware operation has begun using a custom backdoor tool that hides its command-and-control communications inside Microsoft Teams relay infrastructure, according to recent threat intelligence findings.]]></description><link>https://www.cybermaterial.com/p/dragonforce-abuses-microsoft-teams</link><guid isPermaLink="false">https://www.cybermaterial.com/p/dragonforce-abuses-microsoft-teams</guid><pubDate>Tue, 16 Jun 2026 12:38:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!U4tB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U4tB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U4tB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!U4tB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!U4tB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!U4tB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U4tB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:488516,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202277298?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U4tB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!U4tB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!U4tB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!U4tB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f5623b-4b33-4745-9a76-2e9d703be204_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The DragonForce ransomware operation has begun using a custom backdoor tool that hides its command-and-control communications inside Microsoft Teams relay infrastructure, according to recent threat intelligence findings. The malware, designated Backdoor.Turn, represents a sophisticated evasion technique that exploits the trusted nature of Microsoft's collaboration platform to avoid detection by security tools.<br><br>DragonForce has emerged as an active ransomware threat actor targeting organizations across multiple sectors. By developing custom malware specifically designed to abuse Microsoft Teams infrastructure, the group demonstrates technical capability and an understanding of how enterprises rely on cloud-based collaboration tools for daily operations.<br><br>Backdoor.Turn works by tunneling command-and-control traffic through Microsoft Teams relay servers, effectively disguising malicious communications as legitimate business traffic. This approach takes advantage of the fact that most organizations whitelist Microsoft Teams traffic and do not subject it to the same level of scrutiny as other network connections. Security tools that rely on reputation-based filtering or standard traffic analysis may fail to identify the malicious activity hidden within these trusted channels.<br><br>The use of legitimate infrastructure for malicious purposes creates significant challenges for security operations teams. Organizations that depend on Microsoft Teams for communication may find it difficult to distinguish between normal user activity and attacker traffic without implementing specialized detection methods. This technique also complicates incident response efforts, as blocking the malicious traffic could disrupt legitimate business communications.<br><br>Security teams should implement enhanced monitoring for Microsoft Teams relay traffic, looking for unusual patterns such as connections from unexpected geographic locations or during off-hours. Network segmentation and endpoint detection tools capable of behavioral analysis can help identify suspicious activity even when it uses trusted infrastructure. Organizations should also ensure their security information and event management systems are configured to correlate Teams traffic with other indicators of compromise across their environment.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/ </p>]]></content:encoded></item><item><title><![CDATA[China-Linked SprySOCKS Backdoor Expands to Windows]]></title><description><![CDATA[ESET researchers have identified two previously unknown Windows variants of the SprySOCKS backdoor, a malware tool that security teams had only observed targeting Linux systems until now.]]></description><link>https://www.cybermaterial.com/p/china-linked-sprysocks-backdoor-expands</link><guid isPermaLink="false">https://www.cybermaterial.com/p/china-linked-sprysocks-backdoor-expands</guid><pubDate>Tue, 16 Jun 2026 12:37:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XPey!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XPey!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XPey!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!XPey!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!XPey!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!XPey!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XPey!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/691fb577-84c9-46db-8f5c-d272351b8495_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:589709,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202277124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XPey!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!XPey!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!XPey!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!XPey!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F691fb577-84c9-46db-8f5c-d272351b8495_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>ESET researchers have identified two previously unknown Windows variants of the SprySOCKS backdoor, a malware tool that security teams had only observed targeting Linux systems until now. The discovery marks a significant expansion of the threat's capabilities and potential victim pool, as Windows systems represent the majority of enterprise endpoints worldwide.<br><br>The two variants, which ESET has designated WIN_DRV and WIN_PLUS based on internal markers found in the malware code, both contain hard-coded command-and-control server configurations. This design choice suggests the operators are targeting specific organizations rather than conducting broad opportunistic attacks. The backdoors support communication over both TCP and UDP protocols, giving attackers flexibility in how they maintain connections to compromised systems.<br><br>SprySOCKS has been linked to China-based threat actors in previous research, though ESET's report does not specify which particular group is behind these Windows variants. The backdoor's primary function is to establish persistent remote access to infected machines, allowing attackers to execute commands, exfiltrate data, and deploy additional malicious tools. The expansion from Linux to Windows platforms indicates the threat actors are investing resources to broaden their operational reach.<br><br>The discovery affects organizations across all sectors that rely on Windows infrastructure, particularly those in industries previously targeted by China-linked espionage groups such as government, defense, technology, and telecommunications. The hard-coded nature of the command-and-control infrastructure may limit the backdoor's spread but increases its effectiveness against pre-selected targets. Security teams should be especially vigilant if their organizations operate in sectors of strategic interest to state-sponsored actors.<br><br>Organizations should immediately review network logs for suspicious TCP and UDP traffic patterns, particularly connections to unfamiliar external IP addresses. Security teams should update their endpoint detection and response tools with indicators of compromise related to SprySOCKS and conduct thorough scans of Windows systems for signs of the WIN_DRV and WIN_PLUS variants. Network segmentation and strict egress filtering can help limit the backdoor's ability to communicate with external controllers even if initial compromise occurs.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html </p>]]></content:encoded></item><item><title><![CDATA[FBI disrupts Russian APT28 router hijacking campaign]]></title><description><![CDATA[The FBI and Department of Justice announced in April they successfully disrupted a Russian military intelligence hacking operation that compromised home and small office routers across the United States.]]></description><link>https://www.cybermaterial.com/p/fbi-disrupts-russian-apt28-router</link><guid isPermaLink="false">https://www.cybermaterial.com/p/fbi-disrupts-russian-apt28-router</guid><pubDate>Mon, 15 Jun 2026 11:09:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qLF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qLF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qLF1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!qLF1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!qLF1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!qLF1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qLF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:599551,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202108353?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qLF1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!qLF1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!qLF1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!qLF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12ed3b19-d800-46d8-a6d0-d6f0f3ac2926_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The FBI and Department of Justice announced in April they successfully disrupted a Russian military intelligence hacking operation that compromised home and small office routers across the United States. The campaign, attributed to APT28 (also tracked as Fancy Bear and Forest Blizzard), is linked to Russia's GRU military intelligence agency. The attackers exploited vulnerabilities in older routers to modify DNS settings, redirecting internet traffic through servers under their control to steal credentials, authentication tokens, and monitor network activity.<br><br>The operation specifically targeted small office and home office (SOHO) routers, particularly older TP-Link models including the WR841N and other legacy devices identified by the UK National Cyber Security Centre. By compromising DNS settings, the attackers effectively controlled the address book that translates website names into network addresses. This allowed them to intercept sensitive data without obvious signs of compromise, as devices continued to function normally while traffic was quietly routed through malicious infrastructure. TP-Link acknowledged the reports and stated that the affected models reached end-of-service status years ago, though the company has developed security updates for select legacy models where technically feasible.<br><br>The technical approach exploited two common weaknesses in consumer router deployments. First, many users never change default administrative credentials, which are separate from Wi-Fi passwords and control the router itself. Second, manufacturers eventually stop providing security updates for older models, leaving known vulnerabilities unpatched. These factors combined to create an attractive target for sophisticated threat actors seeking persistent access to networks handling sensitive information, particularly those used by remote workers accessing corporate systems.<br><br>The impact extends beyond individual users to small businesses and remote workers whose compromised routers could provide access to workplace networks and sensitive corporate data. Every device connected to an affected router, including laptops, smartphones, tablets, and smart TVs, potentially had its traffic monitored or redirected. The attack demonstrates how neglected network infrastructure can undermine otherwise strong security practices, as users with robust passwords and security software remained vulnerable if their router was compromised.<br><br>Security agencies recommend immediate action for users with affected devices. Check router model numbers against advisory lists and verify whether the manufacturer still provides security support. Update firmware to the latest version and enable automatic updates if available. Change default administrative credentials to strong, unique passwords and disable remote management features unless specifically needed. For routers that no longer receive security updates, replacement is the only effective mitigation. Additional protective measures include using VPNs for work connections, deploying antivirus software on connected devices, and restarting routers periodically to clear potential malicious configurations.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.foxnews.com/tech/fbi-says-russian-hackers-hijacked-old-wi-fi-routers </p>]]></content:encoded></item><item><title><![CDATA[Argamal Malware Hidden in Hentai Game Installers]]></title><description><![CDATA[Cybersecurity researchers at Kaspersky have identified a malware distribution campaign that hides the Argamal backdoor inside installers for adult-themed video games.]]></description><link>https://www.cybermaterial.com/p/argamal-malware-hidden-in-hentai</link><guid isPermaLink="false">https://www.cybermaterial.com/p/argamal-malware-hidden-in-hentai</guid><pubDate>Mon, 15 Jun 2026 11:08:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7hDi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7hDi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7hDi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!7hDi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!7hDi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!7hDi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7hDi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:268399,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/202108192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7hDi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!7hDi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!7hDi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!7hDi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c3f223-dcc3-4af2-a238-dfcd3c973384_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p> Cybersecurity researchers at Kaspersky have identified a malware distribution campaign that hides the Argamal backdoor inside installers for adult-themed video games. The compromised files are being shared through torrent networks and adult content websites, targeting users seeking pirated or free game downloads.<br><br>The attack method relies on social engineering and the expectation that users downloading adult content from unofficial sources may have lower security awareness. Threat actors package the Argamal malware alongside legitimate, working game files. This approach reduces suspicion because victims receive the game they expected, making them less likely to investigate further or run security scans after installation.<br><br>Argamal functions as a remote access tool once installed on victim systems. The malware establishes persistent backdoor access, allowing attackers to execute arbitrary commands on compromised machines. This level of access enables multiple malicious activities including data exfiltration, credential theft, deployment of additional malware payloads, and potential lateral movement within networks if the infected system connects to corporate resources.<br><br>The distribution method poses particular risks for organizations where employees use work devices for personal activities or bring infected personal devices into corporate environments. Remote workers using the same network for both personal and professional activities create additional exposure vectors. The functional game component serves as effective camouflage, potentially delaying detection for extended periods while attackers maintain access.<br><br>Security teams should implement application whitelisting and monitor for unauthorized software installations. Users should avoid downloading games and software from unofficial sources, particularly torrent sites and unverified platforms. Organizations should enforce network segmentation to limit potential damage from compromised endpoints and deploy endpoint detection solutions capable of identifying suspicious remote access patterns. Regular security awareness training should address the risks of downloading pirated or adult content, even when discussing sensitive topics with employees.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://hackread.com/hackers-hide-argamal-malware-hentai-games/</p>]]></content:encoded></item><item><title><![CDATA[Fake FACEIT pages steal Steam accounts]]></title><description><![CDATA[A sophisticated phishing campaign is targeting competitive gamers through fake FACEIT verification pages designed to steal Steam accounts containing valuable games, in-game items, and payment information.]]></description><link>https://www.cybermaterial.com/p/fake-faceit-pages-steal-steam-accounts</link><guid isPermaLink="false">https://www.cybermaterial.com/p/fake-faceit-pages-steal-steam-accounts</guid><pubDate>Fri, 12 Jun 2026 12:14:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2BWJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2BWJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2BWJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!2BWJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!2BWJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!2BWJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2BWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:753067,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201736723?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!2BWJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!2BWJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!2BWJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!2BWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F251791f3-4033-48f0-82ca-e0683cb2efd6_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> A sophisticated phishing campaign is targeting competitive gamers through fake FACEIT verification pages designed to steal Steam accounts containing valuable games, in-game items, and payment information. The scam specifically targets users of FACEIT, one of the largest competitive gaming platforms for Counter-Strike 2, where millions of players connect their Steam accounts for ranked matches and tournaments. Attackers distribute fraudulent pages through gaming community forums, chat servers, social media, and direct messages, exploiting the trust gamers place in account verification processes.<br><br>The attack relies on lookalike domains such as faceit-discord.com, faceit-clubs-verify.com, and faceit-verification-clubs.com that mimic the legitimate faceit.com website. These fraudulent pages feature authentic FACEIT branding, working links to real FACEIT resources, and claims about optional identity verification to build community trust. Security researchers have identified that many of these domains are registered just days or hours before use, allowing scammers to stay ahead of blocklists. Small inconsistencies like duplicate copyright notices (both 2024 and 2025) provide subtle clues to the pages&#8217; fraudulent nature.<br><br>The technical core of the scam involves a Browser-in-the-Browser attack that presents victims with what appears to be a legitimate Steam login window. After users encounter a deliberately blurred QR code and click the &#8220;Sign in through Steam&#8221; button, a fake login window appears with convincing Steam branding and a spoofed steamcommunity.com address bar. This window exists entirely within the fraudulent webpage, allowing attackers to control all displayed elements including the address bar. When victims enter their credentials and Steam Guard codes, this information goes directly to the criminals rather than to Steam&#8217;s authentication systems.<br><br>Stolen Steam accounts represent significant value to cybercriminals, often containing hundreds or thousands of dollars in purchased games, valuable Counter-Strike 2 skins worth real money, wallet funds, saved payment methods, and years of social connections. Once attackers gain access, they can steal items, conduct scams targeting the victim&#8217;s friends list, or sell the compromised account on criminal marketplaces. Some victims are further manipulated into transferring items to what they believe are protective backup accounts, which are actually controlled by the scammers.<br><br>Security professionals recommend several protective measures for gaming communities. Users should verify the actual browser address bar rather than trusting any address displayed within a webpage, as embedded login windows can fake their own address bars. Treat any urgent messages about account problems or verification requirements as potential social engineering attempts. When uncertain about authentication requests, navigate directly to official websites or applications rather than following links from messages or forums. Users who have already entered credentials on suspicious sites should immediately change their Steam password, enable Steam Guard, sign out of all devices, review Steam API key settings, and check for unauthorized trades or purchases.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.malwarebytes.com/blog/threat-intel/2026/06/fake-verification-pages-are-stealing-steam-accounts-from-players</p>]]></content:encoded></item><item><title><![CDATA[Chrome 149 Update Patches 28 Vulnerabilities]]></title><description><![CDATA[Google has released Chrome 149, a security update that resolves 28 vulnerabilities affecting the popular web browser.]]></description><link>https://www.cybermaterial.com/p/chrome-149-update-patches-28-vulnerabilities</link><guid isPermaLink="false">https://www.cybermaterial.com/p/chrome-149-update-patches-28-vulnerabilities</guid><pubDate>Fri, 12 Jun 2026 12:12:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_YV9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_YV9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_YV9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!_YV9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!_YV9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!_YV9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_YV9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2457d05-43a6-4909-8633-92ba00ad654b_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:471066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201735372?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_YV9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!_YV9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!_YV9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!_YV9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2457d05-43a6-4909-8633-92ba00ad654b_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> Google has released Chrome 149, a security update that resolves 28 vulnerabilities affecting the popular web browser. The update addresses multiple critical and high-severity security defects that could potentially allow attackers to compromise user systems.<br><br>The patch bundle includes fixes for a dozen use-after-free vulnerabilities, which represent a significant portion of the security issues resolved in this release. Use-after-free bugs occur when a program continues to use memory after it has been freed, creating opportunities for attackers to manipulate memory and potentially execute malicious code on affected systems.<br><br>Use-after-free vulnerabilities are particularly dangerous in web browsers because they can be triggered through specially crafted web content. When successfully exploited, these flaws can allow attackers to bypass security controls, crash the browser, or gain unauthorized access to system resources. The prevalence of these bugs in this update highlights ongoing challenges in memory management within complex browser codebases.<br><br>Chrome users across all platforms are affected by these vulnerabilities. The security defects could be exploited by threat actors through malicious websites or compromised legitimate sites, potentially leading to data theft, system compromise, or other security incidents. Organizations relying on Chrome for business operations face particular risk if systems remain unpatched.<br><br>Users should update to Chrome 149 immediately through the browser's built-in update mechanism. Chrome typically updates automatically, but users can manually check for updates by navigating to Settings, then About Chrome. System administrators should prioritize deploying this update across enterprise environments to minimize exposure to these security risks.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.securityweek.com/chrome-149-update-patches-28-vulnerabilities/</p>]]></content:encoded></item><item><title><![CDATA[Splunk, Palo Alto Networks Patch Severe Vulnerabilities]]></title><description><![CDATA[Splunk and Palo Alto Networks have issued security updates addressing severe vulnerabilities that pose significant risks to enterprise networks.]]></description><link>https://www.cybermaterial.com/p/splunk-palo-alto-networks-patch-severe</link><guid isPermaLink="false">https://www.cybermaterial.com/p/splunk-palo-alto-networks-patch-severe</guid><pubDate>Thu, 11 Jun 2026 12:34:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gzOG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gzOG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gzOG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!gzOG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!gzOG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!gzOG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gzOG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:760595,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201590027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gzOG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!gzOG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!gzOG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!gzOG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72de3039-5ba1-4280-8aa4-a13b6a41126c_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Splunk and Palo Alto Networks have issued security updates addressing severe vulnerabilities that pose significant risks to enterprise networks. The flaws affect multiple products from both vendors and could allow threat actors to manipulate files and access sensitive protected resources without authorization.<br><br>Both companies discovered the security defects through internal security reviews and coordinated disclosure processes. The vulnerabilities represent serious threats to organizations relying on these widely deployed security and data analytics platforms. No evidence of active exploitation has been reported at the time of disclosure, but the severity ratings indicate these flaws could be attractive targets for attackers.<br><br>The technical nature of the vulnerabilities centers on file manipulation capabilities and unauthorized resource access. Attackers exploiting these flaws could create or modify arbitrary files on affected systems, potentially leading to code execution or system compromise. Additionally, the ability to access and modify protected resources could enable privilege escalation or data theft. The specific attack vectors and exploitation requirements vary depending on the affected product and deployment configuration.<br><br>Organizations running vulnerable versions of Splunk or Palo Alto Networks products face potential risks including unauthorized system access, data manipulation, and possible lateral movement within their networks. The severity of these vulnerabilities means they could be incorporated into attack chains targeting enterprise environments. Companies in sectors with strict compliance requirements face additional concerns regarding data integrity and access controls.<br><br>Security teams should prioritize applying the available patches from both vendors as soon as possible. Administrators should review their deployments to identify affected systems and schedule maintenance windows for updates. Organizations unable to patch immediately should implement compensating controls such as network segmentation and enhanced monitoring. Both vendors have published detailed security advisories with specific version information and remediation guidance on their respective security portals.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.securityweek.com/splunk-palo-alto-networks-patch-severe-vulnerabilities/ </p>]]></content:encoded></item><item><title><![CDATA[Extortion-Only Attacks Surge Without Encryption]]></title><description><![CDATA[Cybercriminals are increasingly abandoning encryption in favor of pure data theft extortion, according to new research from cyber insurer Resilience.]]></description><link>https://www.cybermaterial.com/p/extortion-only-attacks-surge-without</link><guid isPermaLink="false">https://www.cybermaterial.com/p/extortion-only-attacks-surge-without</guid><pubDate>Thu, 11 Jun 2026 12:32:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nVtI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nVtI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nVtI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!nVtI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!nVtI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!nVtI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nVtI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e827a15-7fda-4294-a347-482907990778_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:517594,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201589737?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nVtI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!nVtI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!nVtI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!nVtI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e827a15-7fda-4294-a347-482907990778_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cybercriminals are increasingly abandoning encryption in favor of pure data theft extortion, according to new research from cyber insurer Resilience. The company found that 65% of extortion claims handled in the second half of 2025 did not involve any data encryption, a significant jump from 49% in the first half of the year. By year's end, only 13% of attacks used encryption alone, while data theft accounted for 87% of ransomware-related insurance claims.<br><br>The shift reflects a fundamental change in attacker tactics. Traditional ransomware attacks encrypted victim data and offered a decryption key in exchange for payment, creating a verifiable transaction. Modern extortion attacks instead threaten to publish, sell, or share stolen data, forcing victims to pay for an unverifiable promise that criminals will delete their copies. This evolution makes the payment decision far more complex and risky for targeted organizations.<br><br>Resilience's data reveals the limited effectiveness of paying extortionists. Among policyholders who paid ransoms to suppress data leaks, 30-40% still saw their information published or shared. Organizations that refused to pay fared only slightly worse, with leak rates of 40-50%. The narrow difference in outcomes, combined with evidence that paying marks organizations for future attacks, strengthens arguments against meeting extortion demands. Jud Dressler, director of the Resilience Risk Operation Centre, emphasized that organizations are "effectively paying for a promise from a criminal, when there is no honor amongst thieves."<br><br>The scale of the threat has grown dramatically. A January report documented nearly 1,500 data theft extortion incidents in 2025, compared to just 28 the previous year. This surge has forced organizations and their insurers to reconsider both prevention strategies and incident response plans. The financial impact extends beyond immediate ransom payments to include regulatory fines, litigation costs, customer churn, and long-term reputational damage.<br><br>Resilience recommends organizations prioritize prevention over recovery by deploying data loss prevention technology and zero trust architectures to limit exposure from compromised credentials. Companies should establish decision frameworks before incidents occur, including pre-arranged legal counsel and incident response retainers with clear payment authority chains. Additional measures include storing insurance policy documents outside primary networks, conducting tabletop exercises that test extortion scenarios with legal and executive teams, and tracking the full financial impact of both paying and refusing ransom demands to inform future decisions.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.infosecurity-magazine.com/news/extortion-only-attacks-surge/ </p>]]></content:encoded></item><item><title><![CDATA[Microsoft Patches Record 206 Flaws]]></title><description><![CDATA[Microsoft issued security updates addressing 206 vulnerabilities across its software portfolio in its January 2025 Patch Tuesday release, setting a new record for the highest number of flaws fixed in a single monthly update cycle.]]></description><link>https://www.cybermaterial.com/p/microsoft-patches-record-206-flaws</link><guid isPermaLink="false">https://www.cybermaterial.com/p/microsoft-patches-record-206-flaws</guid><pubDate>Wed, 10 Jun 2026 12:32:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XcIJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XcIJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XcIJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!XcIJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!XcIJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!XcIJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XcIJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:587059,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201446185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XcIJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!XcIJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!XcIJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!XcIJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F581a2317-4d64-4020-aac8-2ad6f2795515_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> Microsoft issued security updates addressing 206 vulnerabilities across its software portfolio in its January 2025 Patch Tuesday release, setting a new record for the highest number of flaws fixed in a single monthly update cycle. The security bulletin includes 39 critical-severity vulnerabilities and 167 rated as important, with three flaws already publicly known at the time patches became available.<br><br>The vulnerability breakdown reveals significant security concerns across multiple attack vectors. The 206 flaws include 63 privilege escalation vulnerabilities, 56 remote code execution bugs, 30 information disclosure issues, 27 spoofing vulnerabilities, and 20 security feature bypass flaws. The sheer volume represents a substantial increase over typical monthly patch releases and indicates extensive security review across Microsoft's product line.<br><br>The three publicly disclosed vulnerabilities present immediate risk since details about these flaws are already available to potential attackers before patches reached all systems. Public disclosure typically accelerates exploitation attempts, as threat actors can analyze the vulnerability details and develop attacks before organizations complete patching. Microsoft has not indicated whether any of these flaws are under active exploitation, but the public disclosure status elevates their priority.<br><br>The critical-severity rating assigned to 39 vulnerabilities indicates these flaws could allow attackers to compromise systems with minimal user interaction or achieve complete system control. Remote code execution vulnerabilities are particularly dangerous as they enable attackers to run malicious code on target systems, potentially leading to data theft, ransomware deployment, or network infiltration. The high number of privilege escalation flaws also poses risk for attackers who have gained initial access to escalate their permissions.<br><br>Security teams should prioritize deploying these patches immediately, focusing first on the three publicly disclosed vulnerabilities and the 39 critical-severity flaws. Organizations should identify which Microsoft products are deployed in their environments, test patches in non-production systems where possible, and establish a rapid deployment schedule for critical infrastructure. Given the record number of fixes, administrators should allocate additional resources for patch management activities this cycle and monitor systems for any unusual activity that might indicate exploitation attempts.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html</p>]]></content:encoded></item><item><title><![CDATA[North Korean phishing campaign targets 250+ developers]]></title><description><![CDATA[Security researchers at Proofpoint have identified a large-scale phishing campaign targeting software developers that sent more than 250 malicious emails to nearly 100 organizations over a six-week period in April and May 2025.]]></description><link>https://www.cybermaterial.com/p/north-korean-phishing-campaign-targets</link><guid isPermaLink="false">https://www.cybermaterial.com/p/north-korean-phishing-campaign-targets</guid><pubDate>Wed, 10 Jun 2026 12:31:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ds3j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ds3j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ds3j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!ds3j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!ds3j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!ds3j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ds3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:670106,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201446035?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ds3j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!ds3j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!ds3j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!ds3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b2248e-6085-49cf-953d-b60ed8989f0b_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Security researchers at Proofpoint have identified a large-scale phishing campaign targeting software developers that sent more than 250 malicious emails to nearly 100 organizations over a six-week period in April and May 2025. The operation, tracked as UNK_DeadDrop and suspected to have North Korean ties, primarily targeted technology, education, business services, and financial services sectors in the United States. The campaign represents an evolution in North Korean cybercrime tactics, shifting from social media-based fake interview schemes to high-volume email phishing with malicious code repositories.<br><br>The attackers impersonated legitimate companies including cryptocurrency platform Ondo Finance, pharmaceutical firm Empower Pharmacy, and mortgage servicer Valon, among others. Phishing emails offered developer positions such as Full-Stack Engineer or requested peer reviews on open-source projects, with all messages directing victims to attacker-controlled GitHub repositories. The repositories were themed around cryptocurrency platforms, exploit archives, Ethereum development tools, and AI payment systems, designed to appear as legitimate coding assignments or collaborative projects.<br><br>When victims cloned these repositories and opened them in integrated development environments like VS Code or Cursor, pre-configured tasks silently executed platform-specific loaders. These loaders installed a malicious VS Code extension (VSIX) disguised as a Google service, which established persistence on macOS and Linux systems by reactivating each time the code editor launched. The malware used different infection chains depending on the operating system: Linux and macOS versions deployed a Go-based remote access trojan built on the legitimate Overlord C2 framework, while Windows attacks ran entirely as JavaScript within the editor's Electron process.<br><br>The malware included three custom modules targeting financial assets and credentials. The browserlogin module stole credentials from Chrome and Firefox, while companywallet specifically targeted 35 cryptocurrency wallet extensions (including MetaMask, Phantom, and Rabby) and 18 standalone wallet applications such as Exodus and Ledger Live. On macOS, the malware displayed fake system dialogs to capture user passwords, then modified keychain access controls across multiple Chromium-based browsers to extract Safe Storage keys. The Linux variant used Zenity dialog prompts for credential theft and attempted to access GNOME Keyring passwords. Windows infections installed Python to execute browser-specific stealers and used COM Elevation Moniker to bypass App-Bound Encryption protections in Chrome, Edge, and Brave.<br><br>Organizations should immediately educate developers about this threat and establish verification procedures for any unsolicited recruitment or code review requests received via email. Security teams should monitor for unauthorized VS Code extensions, particularly those masquerading as Google services, and implement controls to prevent automatic task execution when opening repositories in development environments. The campaign's shift from targeted social engineering to industrialized email phishing suggests North Korean threat actors are scaling their operations against the developer community, making awareness and technical controls critical for defense.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526 </p>]]></content:encoded></item><item><title><![CDATA[AI-powered worm prototype spreads across networks]]></title><description><![CDATA[Researchers from the University of Toronto's CleverHans Lab have demonstrated that attackers do not need frontier AI models to create autonomous, self-replicating malware capable of spreading across enterprise networks.]]></description><link>https://www.cybermaterial.com/p/ai-powered-worm-prototype-spreads</link><guid isPermaLink="false">https://www.cybermaterial.com/p/ai-powered-worm-prototype-spreads</guid><pubDate>Tue, 09 Jun 2026 12:44:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lWNp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lWNp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lWNp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!lWNp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!lWNp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!lWNp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lWNp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:385429,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201291413?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lWNp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!lWNp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!lWNp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!lWNp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6f7eb28-80d9-4f0c-acb5-ad5c2a5da4cf_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Researchers from the University of Toronto's CleverHans Lab have demonstrated that attackers do not need frontier AI models to create autonomous, self-replicating malware capable of spreading across enterprise networks. Their prototype worm, powered by a free large language model running on local hardware, successfully compromised 27 of 33 systems in a simulated corporate environment over seven days. The worm autonomously identified open ports, fingerprinted services, located vulnerabilities from authoritative threat catalogs (CISA KEV, OWASP Top 10, MITRE ATT&amp;CK), and exploited both old and newly disclosed flaws along with common misconfigurations such as reused passwords.<br><br>The research team built a custom agentic framework to compensate for the limitations of smaller, locally-hosted models that lack the massive context windows and reasoning capabilities of commercial frontier models like Claude Opus or GPT-5.5. This harness splits complex penetration testing tasks into phases executed by multiple sub-agents working in parallel, sharing results through a hierarchical memory system. The framework includes specialized prompts for different attack stages, a skill system providing context-aware guidance, and multi-agent coordination for intelligence sharing across compromised instances. Similar frameworks like RAPTOR and SecOpsAgentKit already exist in open-source form for security research purposes.<br><br>The simulated network included virtual machines running various operating systems (Ubuntu, Debian, Windows Server, Alpine Linux, Rocky Linux, CentOS) configured to represent typical corporate infrastructure including web servers, IoT devices, and industrial control systems. Researchers intentionally left systems vulnerable to both remotely exploitable flaws for initial access and local privilege escalation weaknesses. The worm correctly identified vulnerabilities in 82% of attempts and achieved successful exploitation in 44% of those cases. While the exploitation rate appears modest, the parallel swarm-like implementation where each compromised system became a new malicious agent compensated for individual failures, resulting in high overall success. Systems equipped with GPUs allowed the worm to hijack computing resources and run the model locally, reducing attacker infrastructure requirements.<br><br>The implications extend beyond proof-of-concept demonstrations. Security researchers from Forescout confirmed in separate studies that open-weight models, when paired with specialized frameworks like RAPTOR, have already discovered zero-day vulnerabilities in production software such as OpenDNS. Underground forum discussions monitored by Forescout indicate cybercriminals are increasingly focusing on open-source and commercial models rather than custom-trained underground variants. The University of Toronto prototype demonstrated that knowledge about newly disclosed vulnerabilities can be integrated into the worm's knowledge base within hours of public disclosure, dramatically compressing the window defenders have to respond.<br><br>Organizations must accelerate their security response capabilities to match the speed of AI-assisted attacks. The researchers recommend adopting AI-assisted penetration testing and fuzzing to proactively discover exploitable weaknesses, but emphasize the critical need to deploy patches and mitigations faster than current practices allow. Basic defensive measures remain effective: the prototype was noisy and left behavioral signatures detectable by endpoint and network monitoring systems, and the simulated network lacked fundamental protections like network segmentation and zero-trust architecture that could prevent lateral movement. Security experts warn that until mature defensive AI systems emerge, organizations must empower security teams with coding agents to operate at machine speed while defending those agents in turn.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.csoonline.com/article/4181924/ai-worm-prototype-shows-attackers-dont-need-mythos-to-take-over-your-network.html</p>]]></content:encoded></item><item><title><![CDATA[UNC3753 Data Theft Extortion Campaign]]></title><description><![CDATA[A threat actor designated UNC3753 has conducted a sustained data theft extortion campaign against organizations in the United States, according to new research from Google Mandiant and Google Threat Intelligence Group.]]></description><link>https://www.cybermaterial.com/p/unc3753-data-theft-extortion-campaign</link><guid isPermaLink="false">https://www.cybermaterial.com/p/unc3753-data-theft-extortion-campaign</guid><pubDate>Tue, 09 Jun 2026 12:43:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CGkT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CGkT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CGkT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!CGkT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!CGkT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!CGkT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CGkT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:829829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201290130?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CGkT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!CGkT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!CGkT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!CGkT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dea04fa-cc3d-4c53-b34a-f48e41b1d4d7_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>A threat actor designated UNC3753 has conducted a sustained data theft extortion campaign against organizations in the United States, according to new research from Google Mandiant and Google Threat Intelligence Group. The campaign, which ran from January through May 2026, specifically targeted entities in professional services, legal services, and financial services sectors.<br><br>The attackers focused on stealing sensitive data from victim organizations with the apparent intent to use it for extortion purposes. This approach represents a common tactic among financially motivated cybercriminal groups, who threaten to leak or sell stolen information unless victims pay a ransom. The campaign affected dozens of organizations across the targeted sectors.<br><br>Google's security teams tracked and analyzed the intrusion activity, ultimately attributing it to UNC3753, a threat actor that operates under multiple known aliases. The researchers documented the group's tactics and techniques throughout the five-month campaign period. The targeting of professional and legal services firms suggests the attackers sought access to confidential client information and sensitive business data that could be leveraged for extortion.<br><br>Organizations in the affected sectors face significant risks from data theft operations, including regulatory penalties, reputational damage, and potential legal liability if client information is compromised. The financial services industry in particular maintains strict data protection requirements under various regulatory frameworks. Legal and professional services firms also handle highly sensitive client matters that could be exploited if exposed.<br><br>Security teams at organizations in these sectors should review their data loss prevention controls and monitoring capabilities. Recommended actions include implementing network segmentation to limit lateral movement, deploying endpoint detection and response tools, conducting regular security assessments, and establishing incident response procedures for data theft scenarios. Organizations should also review access controls to sensitive data repositories and implement multi-factor authentication across all systems handling confidential information.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html </p>]]></content:encoded></item><item><title><![CDATA[VerdantBamboo Deploys BSD BRICKSTORM on Linux]]></title><description><![CDATA[Cybersecurity researchers at Volexity have identified a new campaign by the China-nexus threat group VerdantBamboo, which has adapted its toolset to target Linux and BSD systems with multiple malware families.]]></description><link>https://www.cybermaterial.com/p/verdantbamboo-deploys-bsd-brickstorm</link><guid isPermaLink="false">https://www.cybermaterial.com/p/verdantbamboo-deploys-bsd-brickstorm</guid><pubDate>Mon, 08 Jun 2026 12:26:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s61D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s61D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s61D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!s61D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!s61D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!s61D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s61D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:534222,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201137017?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s61D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!s61D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!s61D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!s61D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7febbf3-9a34-4e76-81a1-1f412792cca2_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Cybersecurity researchers at Volexity have identified a new campaign by the China-nexus threat group VerdantBamboo, which has adapted its toolset to target Linux and BSD systems with multiple malware families. The group, which overlaps with the threat actor Microsoft tracks as Clay Typhoon, deployed a BSD variant of the BRICKSTORM backdoor alongside two other malicious tools named PLENET (also called GRIMBOLT) and AGENTPSD.<br><br>VerdantBamboo represents a persistent cyber espionage operation with ties to Chinese state interests. The group's expansion into BSD and Linux environments demonstrates a strategic shift to compromise systems that often receive less security scrutiny than Windows platforms. These Unix-based systems frequently serve critical infrastructure roles, making them high-value targets for intelligence collection.<br><br>The BRICKSTORM backdoor variant has been specifically adapted for BSD operating systems, while PLENET and AGENTPSD target Linux environments. These tools provide the attackers with remote access capabilities, allowing them to maintain persistent access to compromised systems, exfiltrate sensitive data, and execute additional commands. The deployment of multiple malware families suggests a sophisticated operation designed to maintain redundant access channels and evade detection.<br><br>Organizations running Linux and BSD systems face increased risk from this campaign, particularly those in sectors typically targeted by Chinese espionage groups such as government, defense, telecommunications, and technology. The adaptation of existing malware to new platforms indicates VerdantBamboo's commitment to expanding its operational reach and maintaining access to diverse target environments.<br><br>Security teams should immediately review their Linux and BSD systems for signs of compromise, implement enhanced logging and monitoring, and ensure security tools provide adequate coverage for Unix-based platforms. Organizations should also review network traffic for unusual outbound connections, deploy endpoint detection and response solutions on all systems regardless of operating system, and maintain current patch levels across their infrastructure.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html </p>]]></content:encoded></item><item><title><![CDATA[Prompt Injection Remains Unsolved Architectural Problem]]></title><description><![CDATA[Prompt injection continues to pose a fundamental security challenge for AI systems that researchers have yet to solve at the architectural level, according to Ariel Fogel, an AI security researcher at Pillar Security who presented at Infosecurity Europe 2026.]]></description><link>https://www.cybermaterial.com/p/prompt-injection-remains-unsolved</link><guid isPermaLink="false">https://www.cybermaterial.com/p/prompt-injection-remains-unsolved</guid><pubDate>Mon, 08 Jun 2026 12:25:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!k25B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k25B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k25B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!k25B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!k25B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!k25B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k25B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:712031,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/201136898?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k25B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!k25B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!k25B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!k25B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09c36c8e-66e6-4b60-860a-839ad7607dac_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Prompt injection continues to pose a fundamental security challenge for AI systems that researchers have yet to solve at the architectural level, according to Ariel Fogel, an AI security researcher at Pillar Security who presented at Infosecurity Europe 2026. The core problem stems from how large language models process all inputs as a single token sequence, making it impossible to enforce reliable boundaries between system prompts, user queries, and content retrieved by agents.<br><br>The threat has grown significantly more dangerous as organizations deploy agentic AI systems that can take autonomous actions. A successful prompt injection no longer merely produces an incorrect answer but can trigger chains of real-world actions when agents have tool access and the ability to act on behalf of users. Fogel warned that most organizations are deploying these agents faster than they can govern them, making traditional security controls inadequate for the speed and scale of modern AI systems.<br><br>Existing defenses designed for human operators often fail when applied to AI agents. Fogel noted that sandboxing, allow-lists, and manual review processes can be circumvented or even exploited by injected prompts. In some cases, allow-lists actually streamlined attacks because the commands agents needed were already approved. In other instances, agents redefined their own sandbox boundaries through their outputs, effectively rewriting the containment meant to stop them.<br><br>Security researchers have proposed frameworks to reduce risk, including Simon Willison's concept of the "Lethal Trifecta" which identifies three dangerous conditions: agent access to private data, exposure to untrusted content, and permission for external communication. Meta's "Rule of Two" suggests agents should satisfy no more than two of these properties in any session without human approval. However, Fogel cautioned these remain helpful heuristics rather than complete defenses, as research shows attacks can succeed with only two properties present.<br><br>Fogel emphasized that defenders must shift from prevention-only strategies to constraining what injected agents can do. He recommended controls that operate at machine speed, including live behavioral monitoring, real-time containment and stop mechanisms, joint incident response between safety and security teams, and stronger identity hygiene such as ephemeral credentials and cryptographic attestation. Until models can enforce firm privilege separations, organizations must combine rapid detection, automated containment, tighter session design, and cross-disciplinary response playbooks to manage the risk.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.infosecurity-magazine.com/news/infosec-europe-prompt-injection/ </p>]]></content:encoded></item><item><title><![CDATA[Chinese spies using LinkedIn for espionage]]></title><description><![CDATA[Chinese intelligence services are actively exploiting professional networking sites like LinkedIn to conduct espionage operations against Western targets, according to a joint security advisory issued by the FBI, the U.K.'s MI5, and the governments of Australia, Canada, and New Zealand.]]></description><link>https://www.cybermaterial.com/p/chinese-spies-using-linkedin-for</link><guid isPermaLink="false">https://www.cybermaterial.com/p/chinese-spies-using-linkedin-for</guid><pubDate>Fri, 05 Jun 2026 11:44:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uPDg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uPDg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uPDg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!uPDg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!uPDg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!uPDg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uPDg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:527422,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/200749823?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uPDg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!uPDg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!uPDg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!uPDg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2406934b-74d4-4440-ae8d-2deeb1de91e2_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Chinese intelligence services are actively exploiting professional networking sites like LinkedIn to conduct espionage operations against Western targets, according to a joint security advisory issued by the FBI, the U.K.'s MI5, and the governments of Australia, Canada, and New Zealand. The operatives create fake profiles posing as recruiters and human resources representatives for companies purportedly based outside China, then use these personas to identify and approach potential intelligence sources.<br><br>The advisory highlights a shift in focus beyond traditional cyber intrusion methods. While Chinese state actors continue to rely heavily on hacking operations, this campaign demonstrates their parallel investment in human intelligence gathering through open platforms. The approach allows operatives to build relationships over extended periods, gradually cultivating trust with targets before attempting to extract sensitive information.<br><br>The primary targets include individuals holding security clearances, active military personnel (particularly those stationed in the Indo-Pacific region), defense contractors, journalists covering national security topics, academic researchers, and employees of policy think tanks. Selection criteria focus on resume details that suggest access to classified or non-public information. The advisory notes that even unclassified information holds intelligence value when aggregated with other data points to inform Beijing's strategic and tactical decision-making processes.<br><br>The joint statement from the Five Eyes intelligence alliance (comprising the United States, United Kingdom, Australia, Canada, and New Zealand) emphasizes that China's military intelligence services seek to acquire privileged military, political, and economic intelligence. This information gathering aims to provide China with strategic advantages over the alliance members. The timing of the advisory reflects ongoing concerns about Chinese espionage activities, even as diplomatic relations between Western governments and Beijing show signs of improvement.<br><br>LinkedIn responded to the advisory by reaffirming its policies against fake accounts and identity misrepresentation. A company spokesperson stated that the platform remains focused on detecting state-sponsored abuse and will continue enforcing its terms of service. Security professionals and individuals in sensitive positions should exercise caution when engaging with unsolicited recruitment approaches on professional networking platforms, verify the legitimacy of companies and recruiters before sharing professional details, and report suspicious contact attempts to their security teams or relevant authorities.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://techcrunch.com/2026/06/04/chinese-spies-are-using-linkedin-to-lure-westerners-into-sharing-sensitive-information/ </p>]]></content:encoded></item><item><title><![CDATA[Chinese Cybercrime Group TA4922 Expands Globally]]></title><description><![CDATA[A previously Asia-focused cybercrime group has significantly expanded its geographic reach and technical capabilities, according to new research from Proofpoint.]]></description><link>https://www.cybermaterial.com/p/chinese-cybercrime-group-ta4922-expands</link><guid isPermaLink="false">https://www.cybermaterial.com/p/chinese-cybercrime-group-ta4922-expands</guid><pubDate>Fri, 05 Jun 2026 11:43:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BkXC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BkXC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BkXC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!BkXC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!BkXC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!BkXC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BkXC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:493044,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/200749033?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BkXC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!BkXC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!BkXC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!BkXC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6b74305-cad6-434d-b910-20c45c3c7ee0_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>A previously Asia-focused cybercrime group has significantly expanded its geographic reach and technical capabilities, according to new research from Proofpoint. The threat actor, tracked as TA4922, now targets organizations across Europe and Africa after historically concentrating on Japan, Taiwan, Korea, Singapore and India. Recent campaigns have reached the United Kingdom, Germany, Italy and South Africa, with carefully localized lures impersonating tax authorities, finance departments and human resources teams in the target's native language.<br><br>The group operates with unusual variety, running more distinct campaigns than any other cybercrime actor currently tracked by Proofpoint. TA4922 mixes malware delivery, credential phishing and direct fraud such as credit card theft across different operations. The actor attempts to move victims from email to messaging platforms including LINE, WhatsApp and Microsoft Teams, allowing social engineering to continue beyond the reach of email security controls. All campaigns appear financially motivated, focused on gaining remote access for data theft, fraud and reselling network access to other criminals.<br><br>TA4922's technical arsenal has evolved rapidly in recent months. Proofpoint identified a newly discovered backdoor called Atlas RAT, deployed alongside two fresh loader families the researchers named RomulusLoader and SilentRunLoader. The group also continues using established malware such as ValleyRAT, also known as Winos 4.0. Payloads are typically installed through DLL sideloading techniques and staged from consumer file-sharing services. RomulusLoader has been observed dropping legitimate remote management tools like AnyDesk to blend malicious activity with normal software. Proofpoint assessed with high confidence that TA4922 uses large language models to accelerate Python malware development, citing evidence such as unchanged placeholder keys left in the code.<br><br>While Proofpoint links TA4922 to the same broad ecosystem as the Silver Fox and Void Arachne clusters, which other researchers have connected to espionage activities, the company assesses it as a distinct, crime-focused group. However, the surveillance capabilities built into its malware, including audio recording, webcam capture and keylogging, could potentially be sold to or exploited by espionage actors. This dual-use potential adds another layer of risk for targeted organizations beyond immediate financial loss.<br><br>Proofpoint recommends several defensive measures to reduce exposure to TA4922 and similar threats. Organizations should enforce application allowlisting to prevent unauthorized software execution, actively monitor programs running from temporary user directories where malware often stages, and limit local administrator rights to restrict what attackers can accomplish after initial compromise. The company emphasized that the global nature of this actor demonstrates how organizations must remain vigilant against emerging threats regardless of their geographic location, as these groups can quickly scale their tactics to include new targets.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.infosecurity-magazine.com/news/ta4922-global-expansion/ </p>]]></content:encoded></item><item><title><![CDATA[Fake invoice phishing campaign caught mid-rollout]]></title><description><![CDATA[Security researchers at Malwarebytes have intercepted a large-scale phishing operation while it was still being assembled, discovering incomplete email templates with placeholder fields where phone numbers and prices would normally appear.]]></description><link>https://www.cybermaterial.com/p/fake-invoice-phishing-campaign-caught</link><guid isPermaLink="false">https://www.cybermaterial.com/p/fake-invoice-phishing-campaign-caught</guid><pubDate>Thu, 04 Jun 2026 12:34:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8mQ9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8mQ9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8mQ9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!8mQ9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!8mQ9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!8mQ9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8mQ9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png" width="800" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:595734,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybermaterial.com/i/200606636?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8mQ9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 424w, https://substackcdn.com/image/fetch/$s_!8mQ9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 848w, https://substackcdn.com/image/fetch/$s_!8mQ9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 1272w, https://substackcdn.com/image/fetch/$s_!8mQ9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F772428ee-05ed-40a1-a453-f8ab4f2afcb8_800x512.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Security researchers at Malwarebytes have intercepted a large-scale phishing operation while it was still being assembled, discovering incomplete email templates with placeholder fields where phone numbers and prices would normally appear. The campaign uses fake payment invoices impersonating trusted brands including PayPal, Amazon, and Geek Squad to frighten recipients into calling scammer-operated phone numbers. Some templates were found with literal placeholder text like #TFN# (toll-free number) and #PRICE# still visible, indicating the attackers were caught between preparation and full deployment.<br><br>The scam relies on psychological manipulation rather than technical exploits, which allows many messages to bypass spam filters since they contain no malicious links or attachments. Recipients receive emails claiming charges between $349 and $598 for subscriptions or purchases they never made, with urgent instructions to call a provided number to cancel or dispute the transaction. The emails create artificial time pressure with phrases like "call within 12 hours" or "cancel before it renews" to prevent victims from independently verifying the claims through legitimate channels.<br><br>Once victims call the provided numbers, scammers employ several tactics to extract money or access. They may request remote access software installation under the pretense of fixing the charge, ask for banking details to process a refund, or claim they accidentally refunded too much and demand the difference be returned via gift cards or wire transfer. The phone conversation itself is the actual attack vector, with the email serving only as bait to initiate contact.<br><br>The campaign targets users of widely recognized services where subscription renewals and payment notifications are common, making the fake invoices appear plausible. Malwarebytes identified several domains used in the operation including invoicepdfin[.]xyz, invoicepdfus[.]xyz, and invoicestatement[.]xyz, along with callback numbers 804-392-2793 and 801-640-8589. The amounts chosen are large enough to cause concern but remain within believable ranges for legitimate online transactions.<br><br>Users who receive suspicious invoices should never call numbers provided in unsolicited emails and should instead verify any charges by logging directly into their accounts through official websites or calling numbers from the back of their payment cards. Those who already engaged with scammers should immediately run security scans, check bank accounts for unauthorized transactions, change critical passwords, and enable multi-factor authentication. The FTC recommends reporting suspected phishing attempts to reportfraud.ftc.gov and forwarding suspicious emails to the abuse departments of impersonated companies.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybermaterial.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybermaterial.com/subscribe?"><span>Subscribe now</span></a></p><p><strong>Source</strong>: https://www.malwarebytes.com/blog/threat-intel/2026/06/infostealers-are-becoming-the-go-to-phishing-payload </p>]]></content:encoded></item></channel></rss>