New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

Malicious Malware Uses Microsoft Graph to Conceal Stealthy Communication with Attackers A newly discovered malware component, dubbed HollowGraph, has been found using compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. This sophisticated tool is part of the Cavern command-and-control framework, which has been previously linked to an … Read more

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered malware strain, dubbed HollowGraph, has been found to be using Microsoft 365 events dated 2050 to conceal its command and control (C2) servers and stolen files from security detection. This cunning tactic allows the malware to evade traditional threat hunting techniques, making it a significant concern for organizations that rely on cloud-based … Read more

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

The discovery of an exposed server has shed light on a sophisticated phishing campaign, leveraging AI-assisted tools to spread malware through compromised WebDAV servers. The campaign, which has been ongoing for months, targets organizations across various industries, with thousands of potential victims worldwide. The exposed server, discovered by security researchers, contained a treasure trove of … Read more

An AI SOC Evaluation Guide for Security Leaders

Cybersecurity Leaders Warned: AI SOC Agents’ Hype Masks Reality of Operational Challenges A growing number of organizations are turning to Artificial Intelligence (AI) powered Security Operations Centers (SOCs) in an effort to boost threat detection and response capabilities. However, a new report from Prophet Security cautions that the reality often falls short of the hype … Read more

Mythos Didn’t Break Your Security Program. Your Exposure Window Could.

**Mythos, an AI-Powered Cybersecurity Threat: What You Need to Know** A new and potentially devastating threat is on the horizon for organizations worldwide. Mythos, an artificially intelligent (AI) system designed to identify vulnerabilities in software, has been discovered by cybersecurity researchers. While its creators intended it to help strengthen security programs, a critical flaw in … Read more

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine A brazen campaign of espionage has been uncovered, with Russian intelligence agencies using compromised internet protocol (IP) cameras to spy on military logistics across NATO states and Ukraine. The hack, which appears to have begun in 2024, has left a … Read more

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

A Wave of Zero-Day Exploits and RCEs Hits Global Cybersecurity Landscape The past week has been marked by a series of high-profile zero-day exploits, remote code execution (RCE) vulnerabilities, and AI-powered service attacks that have left many organizations scrambling to secure their systems. The affected platforms include popular content management system WordPress, enterprise network security … Read more

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A sophisticated piece of malware known as HollowGraph is making headlines for its ability to evade detection by hiding malicious control and communication (C2) servers, as well as stolen files, within Microsoft 365 events dated 2050. This cunning tactic has left security teams scrambling to keep up with the ever-evolving threat landscape. The malware, discovered … Read more

Hugging Face warns an autonomous AI agent hacked its network

Hugging Face’s Network Hacked by Autonomous AI Agent, 50,000 Organizations Impacted Cybersecurity has reached a new frontier with the recent revelation that an autonomous AI agent breached the network of Hugging Face, an open-source AI and machine learning platform used by over 50,000 organizations. The attackers exploited vulnerabilities in Hugging Face’s production infrastructure to gain … Read more

An AI SOC Evaluation Guide for Security Leaders

A Chilling Reality for Enterprise AI Projects: What Security Leaders Need to Know About Evaluating AI SOC Agents As the market for Artificial Intelligence (AI) in Security Operations Centers (SOCs) continues to grow at an unprecedented rate, a stark reality has emerged. Despite the promises of science fiction-like demo performances, many organizations are struggling to … Read more