Spike in Fortinet VPN brute-force attacks raises zero-day concerns

Picus Blue Report 2025

A massive spike in brute-force attacks targeted Fortinet SSL VPNs earlier this month, followed by a switch to FortiManager, marked a deliberate shift in targeting that has historically preceded new vulnerability disclosures. The campaign, detected by threat monitoring platform GreyNoise, manifested in two waves, on August 3 and August 5, with the second wave pivoting … Ler mais

AI Applications in Cybersecurity – Schneier on Security

HomeBlog AI Applications in Cybersecurity There is a really great series of online events highlighting cool uses of AI in cybersecurity, titled Prompt||GTFO. Videos from the first three events are online. And here’s where to register to attend, or participate, in the fourth. Some really great stuff here. Tags: AI, cybersecurity, videos Posted on August … Ler mais

Pennsylvania attorney general's email, site down after cyberattack

Picus Blue Report 2025

The Office of the Pennsylvania Attorney General has announced that a recent cyberattack has taken down its systems, including landline phone lines and email accounts. As Attorney General Dave Sunday revealed on social media on Monday, the office staff is currently working to restore affected services and investigate the incident with the help oflaw enforcement … Ler mais

10 Best Purple Teaming Companies in 2025

10 Best Purple Teaming Companies in 2025

The landscape of cybersecurity in mid-2025 is undergoing a profound transformation. As threats become more sophisticated and persistent, organizations are realizing that siloed security teams are no longer sufficient. In response, many are turning to Purple Teaming Services to foster better collaboration between offensive and defensive security efforts, ensuring a more proactive and unified approach … Ler mais

Deepfake AI Trading Scams Target Global Investors

Deepfake AI Trading Scams Target Global Investors

A surge in fraudulent “AI-powered” trading platforms has been observed exploiting deepfake technology and fabricated online content to deceive investors. According to a new investigation by Group-IB, scammers are deploying convincing fake videos, phony reviews and targeted online ads to lure victims into fraudulent investment schemes. At the heart of these campaigns are AI-generated deepfake … Ler mais

SmartLoader Malware Masquerades as Legitimate GitHub Repository to Infect Users

UAC-0099 Hackers Weaponize HTA Files to Deploy MATCHBOIL Loader Malware

AhnLab Security Intelligence Center (ASEC) has uncovered a sophisticated campaign involving the massive dissemination of SmartLoader malware through GitHub repositories designed to mimic legitimate software projects. These repositories target users searching for popular illicit content such as game cheats, software cracks, and automation tools, appearing at the top of search results on platforms like Google … Ler mais

Hackers Deploy Dedicated Phishlet for FIDO Authentication Downgrade Attacks

Hackers Deploy Dedicated Phishlet for FIDO Authentication Downgrade Attacks

Proofpoint researchers have uncovered a novel technique allowing threat actors to bypass FIDO-based authentication through downgrade attacks, leveraging a custom phishlet within adversary-in-the-middle (AiTM) frameworks. This method exploits gaps in browser compatibility and user agent handling, forcing victims to revert to less secure multi-factor authentication (MFA) mechanisms, thereby enabling credential theft and session hijacking. While … Ler mais

Staffing Company Manpower Discloses Large-Scale Data Breach

Staffing Company Manpower Discloses Large-Scale Data Breach

Manpower, one of the world’s leading staffing agencies, has confirmed that a data breach has affected 144,189 people. In a filing with the Office of the Main Attorney General, Manpower said it notified affected individuals on August 11 that their personal information, including their names, had been compromised. The breach occurred months ago, with the … Ler mais

ShinyHunters May Have Teamed Up With Scattered Spider in Salesforce Attack Campaigns

ShinyHunters May Have Teamed Up With Scattered Spider in Salesforce Attack Campaigns

The financially motivated threat group ShinyHunters has returned with a sophisticated series of attacks targeting Salesforce instances across high-profile enterprises in industries like retail, aviation, and insurance, after a year of relative quiet following member arrests in June 2024. ReliaQuest’s analysis reveals a coordinated infrastructure of ticket-themed phishing domains and credential-harvesting pages, such as ticket-lvmh[.]com … Ler mais

Microsoft removes PowerShell 2.0 from Windows 11, Windows Server

Picus Blue Report 2025

Microsoft will remove PowerShell 2.0 from Windows starting in August, eight years after announcing its deprecation and keeping it around as an optional feature. The 14-year-old command processor introduced with Windows 7 was already removed for Windows Insiders as of July 2025, with the release of Windows 11 Insider Preview Build 27891 to the Canary … Ler mais