Author: Cybernoz

Week in review: Salesloft Drift breach investigation results, malicious GitHub Desktop installers
14
Sep
2025

Week in review: Salesloft Drift breach investigation results, malicious GitHub Desktop installers

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Salesloft Drift data breach: Investigation…

FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration
14
Sep
2025

FBI Unveils IOCs for Cyber Attacks Targeting Salesforce Instances for Data Exfiltration

The Federal Bureau of Investigation (FBI) has released a flash alert detailing the activities of two cybercriminal groups, UNC6040 and…

Silent Ransom Group targeting law firms, the FBI warns
13
Sep
2025

FBI Warns of Salesforce attacks by UNC6040 and UNC6395

FBI warns of Salesforce attacks by UNC6040 and UNC6395 groups Pierluigi Paganini September 13, 2025 The U.S. FBI issued a…

Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems
13
Sep
2025

Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems

IBM X-Force researchers have uncovered sophisticated new malware campaigns orchestrated by the China-aligned threat actor Hive0154, also known as Mustang…

600 GB of Alleged Great Firewall of China Data Published in Largest Leak Yet
13
Sep
2025

600 GB of Alleged Great Firewall of China Data Published in Largest Leak Yet

Hackers leaked 600 GB of data linked to the Great Firewall of China, exposing documents, code, and operations. Full details…

AI Pentesting Tool ‘Villager’ Merges Kali Linux with DeepSeek AI for Automated Security Attacks
13
Sep
2025

AI Pentesting Tool ‘Villager’ Merges Kali Linux with DeepSeek AI for Automated Security Attacks

Security researchers at Straiker’s AI Research (STAR) team have uncovered Villager, an AI-native penetration testing framework developed by Chinese-based group…

Qrator Labs Mitigated Record L7 DDoS Attack from 5.76M-Device Botnet
13
Sep
2025

Qrator Labs Mitigated Record L7 DDoS Attack from 5.76M-Device Botnet

In early September, Qrator Labs detected and mitigated one of the most significant L7 DDoS attacks seen this year, carried…

A CISO’s Guide to Managing Cyber Risk in Healthcare
13
Sep
2025

A CISO’s Guide to Managing Cyber Risk in Healthcare

Now more than ever before, our healthcare data is under attack. Of all of the sensitive information available on the…

Why The Open Web Application Security Project (OWASP) Mobile Application Security (MAS) Project Is Critical
13
Sep
2025

Why The Open Web Application Security Project (OWASP) Mobile Application Security (MAS) Project Is Critical

The OWASP MAS project continues to lead the way in mobile application security. This article describes the resources and tools…

HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya
13
Sep
2025

HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya

HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya Pierluigi Paganini September 13, 2025 HybridPetya ransomware bypasses UEFI Secure Boot to…

New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts
13
Sep
2025

New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts

Okta Threat Intelligence exposes VoidProxy, a new PhaaS platform. Learn how this advanced service uses the Adversary-in-the-Middle technique to bypass…

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks
13
Sep
2025

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks

The U.S. Federal Bureau of Investigation (FBI) has issued a flash alert to release indicators of compromise (IoCs) associated with…