Introducing: What to Watch, Patch, and Secure This Week
Starting this week, we’re bringing you a curated roundup of key cybersecurity stories, vulnerabilities, and threat trends that security teams should keep on their radar.
🔹 Spain government employee doxing case
A reminder that attackers don’t always need to breach systems. Aggregated employee data from past leaks, public sources, and OSINT can still fuel phishing, impersonation, and account-compromise attempts.
hexnode.com/blogs/spain-gove…
🔹 DriveSurge malware campaign
Compromised websites are redirecting visitors to malware-delivery infrastructure using ClickFix and FakeUpdates lures, targeting both Windows and macOS users.
hexnode.com/blogs/drivesurge…
🔹 Kali365 phishing kit expansion
Kali365 has expanded beyond Microsoft 365, abusing device-code OAuth flows to target cloud and identity platforms like AWS and Okta.
hexnode.com/blogs/kali365-ph…
🔹 Miasma malware and Red Hat npm supply-chain attack
More than 30 npm packages under Red Hat’s namespace were compromised to deliver Miasma malware, targeting developer environments and CI/CD pipelines for sensitive credentials.
hexnode.com/blogs/miasma-mal…
🔹 Dashlane brute force attack
Automated login attempts against Dashlane accounts triggered verification-code requests, new-device registration attempts, and temporary lockouts, highlighting password vault account takeover risks.
hexnode.com/blogs/dashlane-b…
Stay informed, prioritize what matters, and strengthen your security posture one week at a time.