Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

A New Malware Technique Emerges: Cruciferra Crypter Leverages BYOVD and Process Ghosting to Evade Detection The cybersecurity landscape continues to evolve, with attackers finding innovative ways to evade traditional defenses. A recent discovery has shed light on a sophisticated malware technique known as Cruciferra Crypter, which uses two stealthy methods – Bring Your Own Vulnerability … Read more

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub, one of the world’s largest code repositories, has implemented an emergency measure to prevent the spread of malicious code. The company has introduced a three-day cooldown period for its Dependabot feature, which automatically updates dependencies in open-source projects, after researchers discovered a vulnerability that allowed hackers to inject poisoned packages into popular software. The … Read more

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

A sophisticated threat actor, known as TELESHIM, has been exploiting Telegram’s built-in features to establish command and control (C2) channels for malicious activities targeting governments in the Middle East. The alarming trend reveals the growing reliance of cyber attackers on social media platforms to launch attacks. TELESHIM’s tactics involve leveraging Telegram’s “secret chats” feature, which … Read more

MCBS Data Breach Affects 1.2 Million Individuals

A massive data breach has affected over 1.2 million individuals after hackers compromised the systems of Atlanta-based medical business management company MCBS (Medical Computer Business Services) in September last year. The cyberattack, carried out by the PEAR ransomware group, has exposed sensitive personal and medical information. MCBS’s data breach notification reveals that attackers had access … Read more

ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)

A Major Flaw Exposed in Popular DNS Service, Leaving Thousands Vulnerable to Spoofing Attacks A critical vulnerability has been discovered in the DNS (Domain Name System) service provided by a major internet infrastructure company. The flaw, which affects thousands of organizations and individuals worldwide, makes it possible for malicious actors to intercept and manipulate online … Read more

MCBS Data Breach Affects 1.2 Million Individuals

A massive data breach affecting over 1.2 million individuals has come to light in a cyberattack on Atlanta-based medical business management company MCBS, also known as Medical Computer Business Services. The incident occurred last September and was carried out by the PEAR ransomware group, which claims to have stolen more than 3 terabytes of sensitive … Read more

ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)

A Devastating New Malware Strain Emerges, Threatening Businesses Worldwide A major cybersecurity threat has emerged in recent days, with reports of a highly sophisticated malware strain compromising networks and systems across the globe. The malware, which has been dubbed “Eclipse,” is spreading rapidly, infecting companies of all sizes and industries, from finance to healthcare. At … Read more

Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)

A popular Chinese document management system has been found to be vulnerable to basic security threats due to its use of well-known default passwords. ESAFENET’s Content Data Guard (CDG) 3, a product marketed as a secure solution for document management and data leakage prevention, has been targeted by scans looking to exploit these weaknesses. The … Read more

GitHub, PyPI add time-absed defenses against supply chain attacks

In a significant move to bolster their defenses against supply chain attacks, GitHub and Python Package Index (PyPI) have introduced time-based mechanisms to prevent malicious actors from exploiting vulnerabilities in their ecosystems. The changes come after a string of high-profile attacks on development platforms over the past year. The introduction of a “cooldown” feature by … Read more

Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)

A Secure Document Management System Exposed by Default Passwords Security researchers have detected a surge in scans targeting ESAFENET’s CDG (Content Data Guard) document management system, which appears to be vulnerable to exploitation due to weak logins. The company, focused on secure document management and data leakage prevention solutions, has been affected by this issue … Read more