Filter
Exclude
Time range
-
Near
@icydus_yaoi cim ping cause . hatebot or enemybot or whatever uou call them
1
2
229
This weekโ€™s threat landscape was marked by a series of urgent security updates and active exploitation cases across major platforms: ๐Ÿ”น Samsung & Google patched zero-day flaws exploited in the wild ๐Ÿ”น Case Theme Users plugin exploited immediately after disclosure ๐Ÿ”น WhatsApp & Delmia Apriso vulnerabilities remain actively targeted ๐Ÿ”น Botnets EnemyBot, Sysrv-k, Andoryu, Androxgh0st, Mirai, Bashlite, Tsunami & BrickerBot ramped campaigns targeting GitLab, cloud gateways, PHP apps & EirD1000 routers ๐Ÿ”น ESET uncovered HybridPetya ransomware exploiting unpatched systems ๐Ÿ”น LILIN DVR flaw abused by Chalubo, FBot & Moobot ๐Ÿ”น Akira ransomware leverages SonicWall vulnerability against Australian orgs Rapid patching, proactive monitoring, and layered defenses remain critical. Full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #Vulnerability #Intelligence #InfoSec #ThreatIntel #Samsung #Google #Zeroday #WordPress #EnemyBot #DelmiaApriso #WhatsApp #Andoryu #Androxgh0st #Mirai #Bashlite #HybridPetya #Ransomware #Malware #Chalubo #Botnet #FBot #Moobot #Akira #SonicWall
1
2
44
This week's cybersecurity landscape has been marked by continued exploitation of critical vulnerabilities across enterprise and consumer technologies: ๐Ÿ”น CISA added - Dassault Systรจmes DELMIA Apriso vulnerability to its KEV catalog ๐Ÿ”น SAP S/4HANA flaw under active exploitation ๐Ÿ”น Vulnerabilities in TP-Link, WhatsApp, Android, and Linux kernel continue to be exploited. ๐Ÿ”น Botnets EnemyBot, Sysrv-k, Andoryu, Androxgh0st, Mirai, Bashlite, Tsunami & BrickerBot ramped campaigns targeting GitLab, cloud gateways, PHP apps & EirD1000 routers. ๐Ÿ”น 360Netlab flagged LILIN DVR exploits spreading Chalubo, FBot & Moobot. ๐Ÿ”น ACSC alerts about Akira ransomware intrusions in Australia The message is clear: adversaries are diversifying their targets across enterprise software, consumer devices, and IoT ecosystems. Rapid patching and layered defense remain mission-critical. Full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #Threat #SAP #CISA #Vulnerabilities #InfoSec #KEV #WhatsApp #Google #Linux #Kernel #TPLink #Botnet #Andoryu #DVR #Androxgh0st #LILIN #Chalubo #FBot #Moobot #SonicWall #SSLVPN
1
3
64
This Week in Cybersecurity: ๐Ÿ”น CISA expanded its KEV catalog with 7 high-risk vulnerabilities, including flaws in TP-Link, WhatsApp, Android, and Sitecore. ๐Ÿ”น Confirmed exploit attempts observed against DELMIA Apriso. ๐Ÿ”น Botnets EnemyBot, Sysrv-k, Andoryu, Androxgh0st, Mirai, Bashlite, Tsunami & BrickerBot ramped campaigns targeting GitLab, cloud gateways, PHP apps & EirD1000 routers. ๐Ÿ”น Threat intel linked Quad 7 botnet (Storm-0940) to TP-Link chained exploits, while attacks deployed WEEPSTEEL and tools like EARTHWORM, DWAgent & SharpHound on vulnerable Sitecore instances. Stay Patched. Stay resilient!! Check out the full report here : loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #VulnerabilityIntelligence #Vulnerabilities #Threats #InfoSec #CISAKEV #TPLink #Google #Android #Meta #WhatsApp #SitecoreXP #DELMIAApriso #Botnet #Mirai #Andoryu #Androxgh0st #Sekoia #Quad7 #CovertNetwork1658 #Storm0940 #Mandiant #WEEPSTEEL #EARTHWORM #DWAgent
1
3
57
๐—ง๐—ต๐—ถ๐˜€ ๐—ช๐—ฒ๐—ฒ๐—ธ ๐—ถ๐—ป ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: ๐Ÿ”นCISA added four vulnerabilities to its KEV catalog ๐Ÿ”นBotnets EnemyBot, Sysrv-k, Andoryu, and Androxgh0st targeted GitLab, Cloud Gateway, and PHP, while IoT botnets hit EirD1000 routers. ๐Ÿ”นGayfemboy Botnet resurges, exploiting flaws in DrayTek, TP-Link, Raisecom, and Cisco. ๐Ÿ”นCrowdStrike linked MURKY PANDA to cloud-based espionage with zero-days, while Glacial Panda targeted telecom providers to steal call records via privilege escalation. Secure your systems. Secure your future Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #Vulnerability #Intelligence #CISA #KEV #Threat #Citrix #Netscaler #SessionRecording #Git #Botnet #Andoryu #Androxgh0st #EnemyBot #SysrvK #Mirai #IoT #Fortinet #Gayfemboy #DrayTek #TPLink #Raisecom #Cisco #GlacialPanda #MURKYPANDA
1
2
145
๐—ง๐—ต๐—ถ๐˜€ ๐—ช๐—ฒ๐—ฒ๐—ธ ๐—ถ๐—ป ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: โ€ข CISA added two vulnerabilities to its KEV catalog. โ€ข PoC exploits emerged for critical SAP NetWeaver bugs โ€ข Botnets EnemyBot, Sysrv-k, Andoryu, and Androxgh0st targeted GitLab, Cloud Gateway, and PHP, while IoT botnets hit EirD1000 routers. โ€ข Malware activity surged with SAP web shells, DripDropper, and long-running espionage by Static Tundra. Secure your systems. Secure your future. Check the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #Mirai #VulnerabilityIntelligence #InfoSec #ThreatInfo #Malware #Ransomware #Threats #ThreatIntell #CISAKEV #TrendMicro #Apple #Zerodays #Botnet #Andoryu #Androxgh0st #Sysrv_k #EnemyBot #SAPNetWeaver #ApacheActiveMQ #Cisco #DripDropper
2
3
74
This weekโ€™s threat landscape saw a sharp rise in exploitation and malware delivery: โ€ข CISA adds 3 D-Link vulnerabilities to its KEV catalog โ€ข Trend Micro confirmed active attempts to exploit Apex One flaws โ€ข Botnets like EnemyBot, Andoryu, and Mirai exploited GitLab, PHP apps, and EirD1000 routers. โ€ข Kaspersky uncovered an AV killer used in MedusaLocker attacks; malware included Zenpak & Farfli trojans. โ€ข Ransomware deployed via active exploitation of Rejetto HFS servers. Stay patched. Stay ahead. Stay Secured. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #VulnerabilityIntelligence #ThreatIntell #InfoSec #Vulnerabilities #CISAKEV #DLink #Rejetto #HFSserver #Farfli #Zenpak #Ransomware #Malware #AVKiller #MedusaLocker #Botnet #Mirai #Androxgh0st #EnemyBot #TrendMicro #ApexOne
1
1
2
86
This Weekโ€™s threat landscape was marked with intensified exploitation by advanced threat actors: โ€ข CISA added 3 vulnerabilities to its KEV catalog. โ€ข Active exploitation observed in a WordPress theme โ€ข Botnets like Mirai, Andoryu, and EnemyBot hit GitLab and Eir D1000 routers โ€ข SAP NetWeaver flaw used to deploy Auto-Color backdoor โ€ข China-based APTs hit SharePoint, deploying Warlock Ransomware Patch swiftly. Monitor continuously. Stay secure. Full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #Vulnerability #Intelligence #Threat #InfoSec #Microsoft #Cisco #Papercut #WordPress #WordFence #CISAKEV #EnemyBot #Mirai #Bashlite #Tsunami #BrickerBot #SharePoint #Storm2603 #WarlockRansomware #SAPNetWeaver #LinenTyphoon #Malware #APT
1
2
43
Replying to @BubbyBlu29353
Summary of Todayโ€™s Cyber Attacks and DoS Activities (July 25, 2025) Based on the latest reports, hereโ€™s a concise overview of ongoing cyber threats, focused on key incidents. Ongoing Espionage and Targeted Attacks: โ€ข Russian aerospace and defense sectors hit by a new backdoor malware called EAGLET, aimed at intelligence gathering. โ€ข Chinese APT groups (e.g., Linen Typhoon/APT27 and Violet Typhoon/Storm-2603) exploiting Microsoft SharePoint zero-days, affecting over 400 global organizations in critical infrastructure. โ€ข State-sponsored actors like Patchwork (India-linked) and Fire Ant (possibly North Korea-linked) targeting Turkish and Russian defense via spear-phishing and virtualization exploits. Ransomware and Malware Campaigns: โ€ข Chaos RaaS group (possibly ex-BlackSuit members) launching big-game hunts with double extortion, using spam, social engineering, and data exfiltration tools. โ€ข Soco404 cryptomining campaign exploiting cloud vulnerabilities (Linux/Windows), hiding payloads in fake 404 pages on Google Sites. โ€ข New VoIP botnet expanding from rural New Mexico, targeting routers with default passwords and Telnet exploits, impacting IoT devices like Cambium networks. Denial of Service (DoS/DDoS) Incidents: โ€ข Moroccan Black Cyber Army claiming DDoS attacks on Algerian sites, including Akhbar Dzair, Gulf Bank Algรฉrie, National Library of Algeria, Algeria-dz.com, and Plant Ecology Lab. โ€ข Thai and foreign hackers conducting ongoing DDoS against Cambodian websites. โ€ข Escalating DDoS threats to global ports (80% of world trade), involving Russian, Iranian, and Chinese state actors, ransomware groups, and hacktivists targeting vessel traffic and access systems. โ€ข Ransomware outfits like Storm-2603 and DragonForce incorporating DDoS in attacks on critical infrastructure. โ€ข Pay2Key.I2P RaaS (Tehran-linked) offering bonuses for attacks on U.S./Israeli targets, potentially including DDoS. Other Emerging Threats: โ€ข Cybercriminals using purchased malware to hit U.S./EU banks, governments, and corporations via initial access brokers. โ€ข Surge in crypto address poisoning attacks, with stolen funds up by $500K in recent weeks and incidents rising to 83.8M. โ€ข CISA warnings on hardware vulnerabilities in Honeywell, Medtronic, Mitsubishi, LG devices that could enable DoS. โ€ข Botnets (Mirai, Andoryu, EnemyBot) attacking GitLab and Eir D1000 routers; Mimo Loader exploiting Craft CMS for miners and proxyware. Stay vigilantโ€”monitor CISA and threat intel sources for updates. #CyberSecurity #DDoS #Ransomware

2
1
3
353
๐—ง๐—ต๐—ถ๐˜€ ๐—ช๐—ฒ๐—ฒ๐—ธ ๐—ถ๐—ป ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† โ€ข CISA adds 8 new vulns to KEV - including Microsoft, SysAid, Fortinet & Chrome โ€ข Cisco ISE exploited via unauthenticated API flaws โ€ข Botnets like Mirai, Andoryu, EnemyBot hit GitLab, Eir D1000 routers โ€ข Chinese APTs linked to active exploits on SharePoint โ€ข Mimo Loader campaign targets Craft CMS via RCE to deploy miner & proxyware Secure swiftly. Monitor closely. Stay resilient. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #ThreatIntel #InfoSec #Vulnerabilities #CISAKEV #CraftCMS #SharePoint #ChinaAPT #EnemyBot #IoTBotnet #SysAid #CiscoISE #Androxgh0st #XMRig #Proxyjacking #APT27 #Storm2603 #MicrosoftSharePoint #LinenTyphoon #VioletTyphoon #Mimo
1
3
71
๐—ง๐—ต๐—ถ๐˜€ ๐—ช๐—ฒ๐—ฒ๐—ธ ๐—ผ๐—ป ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† โ€ข CISA adds Wing FTP vulnerability to its KEV โ€ข Active exploitations hit Chrome, Citrix, Zimbra and more โ€ข Botnets like Mirai & EnemyBot ramp up attacks on GitLab, IoT โ€ข UNC6148 deploys stealthy OVERSTEP backdoor on SonicWall EOL devices Secure swiftly. Monitor closely. Stay resilient. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Loginsoft #VulnerabilityIntelligence #ThreatIntel #InfoSec #Vulnerabilities #CISAKEV #Botnet #WingFTPServer #Google #Chrome #Zimbra #PHPMailer #RubyonRails #Andoryu #UNC6148 #SMA100 #SonicWall #OVERSTEP #Backdoor
1
2
67
Here's a breakdown of the latest developments that shaped this week's threat landscape: โ€ข CISA added five vulnerabilities to its KEV catalog โ€ข Botnet activity spiked, with EnemyBot, Androxgh0st, and Mirai exploiting flaws in GitLab, Cloud Gateway, PHP apps, and IoT devices like Eir D1000. โ€ข Espionage campaigns surged, as Fortinet exposed the RondoDox botnet, ASEC reported active GeoServer exploitation, and SentinelLabs detailed a China-linked PurpleHaze campaign using Ivanti, ConnectWise, and GeoTools vulnerabilities. Patch fast. Monitor actively. Stay ahead. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Vulnerability #Intelligence #ThreatIntel #InfoSec #CISAKEV #LookingGlass #PHPMailer #RubyOnRails #Zimbra #Malware #Fortinet #CyberEspionage #RondoDox #Botnet #TBKDVR #GeoServer #XMRig #Ivanti #ConnectWise #Mirai #Andoryu #Androxgh0st #EnemyBot #PurpleHaze #GoReShell #CitrixNetscaler
1
2
61
This Week in Cybersecurity โ€ข Four CISA KEV inclusions โ€ข Active exploitations reported in Citrix NetScaler โ€ข Botnet activity spiked, compromising exposed infrastructure across popular platforms โ€ข "LapDogsโ€ espionage campaign hits over a thousand SOHO devices โ€ข Houken threat actor exploited Ivanti CSA zero-days Patch fast. Monitor actively. Stay ahead. Check out the report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #Vulnerability #Intelligence #ThreatIntel #Malware #Threat #CISAKEV #Google #Chrome #ReliaQuest #Citrix #TeleMessage #TMSGNL #Mirai #EnemyBot #Androxgh0st #LapDogs #ShortLeash #Ivanti #Houken #ThreatActor #ShortLeash #Backdoor
1
2
54
๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐˜€ ๐—˜๐˜€๐—ฐ๐—ฎ๐—น๐—ฎ๐˜๐—ฒ: ๐—ž๐—˜๐—ฉ ๐—œ๐—ป๐—ฐ๐—น๐˜‚๐˜€๐—ถ๐—ผ๐—ป๐˜€, ๐—•๐—ผ๐˜๐—ป๐—ฒ๐˜ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ถ๐˜๐˜†, ๐—ฎ๐—ป๐—ฑ ๐— ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—–๐—ฎ๐—บ๐—ฝ๐—ฎ๐—ถ๐—ด๐—ป๐˜€ ๐—ž๐—ฒ๐˜† ๐—ต๐—ถ๐—ด๐—ต๐—น๐—ถ๐—ด๐—ต๐˜๐˜€ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐˜„๐—ฒ๐—ฒ๐—ธ: โ€ข CISA added 3 critical vulnerabilities to the KEV catalog โ€ข Active exploitations detected in Motors WordPress theme, Citrix NetScaler ADC/ Gateway and in Linksys E-Series routers. โ€ข Botnet activity spiked, with malware families like EnemyBot, Androxgh0st, and Mirai aggressively compromising exposed infrastructure across popular platforms. โ€ข APT Action: Salt Typhoon exploited Cisco IOS XE flaw, while TheMoon worm targeted Linksys routers. Meanwhile, vulnerability in FreeType was linked to Graphite spyware. Patch now. Monitor logs. Harden systems. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #LOVI #ActiveExploitation #Threats #Malware #CISAKEV #AMIMegaRAC #DLinkDIR #Botnets #Mirai #EnemyBot #Androxgh0st #TheMoon #Citrix #Fortinet #FortiOS #Spyware #MotorsTheme #WordFence #SaltTyphoon #Graphite #Cisco
2
3
27
The 5th week of May 2025, underscored a sharp rise in both financially motivated and state-sponsored attacks, exploiting critical vulnerabilities at scale. ๐—ž๐—ฒ๐˜† ๐—ต๐—ถ๐—ด๐—ต๐—น๐—ถ๐—ด๐—ต๐˜๐˜€: โ€ข Craft CMS under active attack allowing threat actors to deploy cryptominers and proxyware โ€ข TI WooCommerce Wishlist Plugin suffers a critical unpatched file upload flaw โ€ข ASUS routers exploited to form โ€œAyySSHushโ€ botnet โ€ข Botnets like Mirai, EnemyBot, Andoryu, and Androxgh0st ramp up targeting Cloud Gateway, GitLab & IoT. โ€ข DragonForce launched a supply chain ransomware attack via SimpleHelp exploitation. โ€ข ViciousTrap compromised thousands of Cisco routers to build a honeypot-like surveillance network. โ€ข Threat actor โ€œMimoโ€ leveraged Craft CMS flaws to install miners & proxyware. โ€ข China-linked UNC5221 exploited Ivanti EPMM, while UAT-6382 abused a Trimble Cityworks zero-day to infiltrate U.S. local governments. Donโ€™t wait - patch, audit, and monitor before you become the next target. Check out the full report: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #Threatintelligence #LOVI #Botnets #ActiveExploitation #Andoryu #Androxgh0st #Ivanti #UNC5221 #UAT6382 #TrimbleCityWorks #Mimo #CraftCMS #ViciousTrap #DragonForce #Ransomware #SimpleHelp #Cryptomining #EnemyBot #Botnet #Asus #AyySSHush #WishlistPlugin #WordPress
1
2
25
just recently invented a guy. calling this one "haterbot" / "enemybot". he does not help you he deceives you and is evil. i hope you like him.
6
61
409
10,427
This weekโ€™s cyber threat landscape is dominated by rapid zero-day exploitation across major enterprise platforms: ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜„๐—ต๐—ฎ๐˜ ๐˜†๐—ผ๐˜‚ ๐—ป๐—ฒ๐—ฒ๐—ฑ ๐˜๐—ผ ๐—ธ๐—ป๐—ผ๐˜„: โ€ข 7 new vulnerabilities were added to CISA KEV, including 5 zero-days targeting Microsoftโ€™s core systems for SYSTEM-level access โ€ข Fortinet patches an actively exploited zero-day affecting multiple products. โ€ข TeleMessage TM SGNL leak exposes sensitive plaintext archives, raising privacy alarms. โ€ข Google Chrome & Ivanti also face zero-day exploits โ€ข Botnets like Mirai, EnemyBot, Andoryu, and Androxgh0st ramp up targeting Cloud Gateway, GitLab & IoT. โ€ข Tรผrkiye-linked espionage group Marbled Dust exploits a zero-day in Output Messenger for stealthy intrusions. โ€ข Mirai abuses flaw in MagicINFO 9 Server, triggering urgent Samsung patch. โ€ข Multiple threat actors actively exploiting a critical SAP NetWeaver vulnerability, attracting both cybercriminals and state-sponsored groups As threat actors pivot to zero-day exploits at scale, the ability to respond swiftly and build resilient, threat-aware infrastructure is more critical than ever. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #Threatintelligence #Botnets #Mirai #CISA #ActiveExploitation #Andoryu #Androxgh0st #Ransomwares #Microsoft #Windows #Samsung #SAPNetWeaver #TeleMessage #Ivanti #Fortinet #GoogleChrome
1
2
36
Recent exploitation patterns reveal a sharp shift toward targeting vulnerabilities in widely used business infrastructure. ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜„๐—ต๐—ฎ๐˜ ๐˜†๐—ผ๐˜‚ ๐—ป๐—ฒ๐—ฒ๐—ฑ ๐˜๐—ผ ๐—ธ๐—ป๐—ผ๐˜„: โ€ข Six vulnerabilities were recently added to the CISA KEV catalog, including two affecting end-of-life GeoVision IoT devices and one each in Commvault Command Center, Langflow, the Yii PHP Framework, and FreeType. โ€ข A vulnerability in Ottokit WordPress Plugin was rapidly weaponized by threat actors following its public disclosure. โ€ข Samsung MagicINFO 9 Server actively exploited to deploy Mirai malware โ€ข Botnets like Mirai, EnemyBot, Andoryu, and Androxgh0st ramp up targeting Cloud Gateway, GitLab & IoT โ€ข Play ransomware affiliates exploited a Windows CLFS vulnerability as a zero-day during a targeted attack on a U.S entity. โ€ข Discontinued GeoVision IoT devices were actively exploited to deliver Mirai malware. Update your systems quickly, isolate unsupported devices, and stay vigilant on exposed assets. Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #Threatintelligence #Botnets #Mirai #CISA #ActiveExploitation #Andoryu #Androxgh0st #Commvault #Ransomwares #Microsoft #Windows #PlayRansomware #EOL #Samsung #Ottokit #WordPress
1
3
49
๐—ช๐—ฒ๐—ฒ๐—ธ ๐—ผ๐—ณ ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ: ๐—›๐—ถ๐—ด๐—ต-๐—œ๐—บ๐—ฝ๐—ฎ๐—ฐ๐˜ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—ง๐—ฟ๐—ฒ๐—ป๐—ฑ๐˜€ ๐—จ๐—ป๐—ณ๐—ผ๐—น๐—ฑ In a sharp escalation, this weekโ€™s threat landscape saw an uptick in active exploitation targeting core infrastructure Hereโ€™s what you need to know: โ€ข Commvault Web Server - Added to CISA KEV due to in-the-wild attacks. โ€ข Craft CMS - Hit by a chained attack targeting developer environments. โ€ข SonicWall SMA - Issued a critical alert following live exploitation of remote access vulnerabilities. โ€ข Botnets like Mirai, EnemyBot, Andoryu, and Androxgh0st ramp up targeting Cloud Gateway, GitLab & IoT โ€ข Attackers deployed DslogdRAT, a stealthy RAT built for persistence and evasion, by exploiting a flaw in Ivanti Connect Secure. In parallel, Fog Ransomware operators chained legacy Microsoft vulnerabilities to achieve full domain compromise. Threat actors are chaining legacy flaws with modern zero-days, actively exploiting both enterprise and IoT systems to maximize reach and control. Attackers Donโ€™t Wait. Neither Should You!! Check out the full report here: loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #Threatintelligence #Botnets #Microsoft #Mirai #CISA #ActiveExploitation #Andoryu #Androxgh0st #SonicWall #CraftCMS #FogRansomware #Commvault #Ransomwares #RAT #DslogdRAT
1
3
23
๐—ง๐—ต๐—ถ๐˜€ ๐˜„๐—ฒ๐—ฒ๐—ธ ๐—ถ๐—ป ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†: Active exploits, Growing botnets, and Nation-state actors Hereโ€™s what you need to know: โ€ข Active! mail & Brocade Fabric OS flaws exploited in the wild โ€ข Botnets like Mirai, EnemyBot, Andoryu, and Androxgh0st ramp up targeting Cloud Gateway, GitLab & IoT โ€ข Kimsukyโ€™s Larva-24005 campaign resurfaces via RDP flaws โ€ข RustoBot targets TOTOLINK & DrayTek routers across Asia Past Fast! Monitor Faster!! For more details, check out the full report:loginsoft.com/reports/weeklyโ€ฆ #Cybersecurity #Threatintelligence #Botnets #Microsoft #Mirai #Malware #Windows #ActiveExploitation #Andoryu #Androxgh0st #ActiveMail #Brocade #Kimsuky #Larva24005 #APTGroup
1
2
120