Backup Wipers, Callback Phishing, and the Rush to Patch Ivanti
News
FBI Issues Warning on Luna Moth Callback Phishing Targeting Businesses
The FBI is sounding the alarm on a callback phishing campaign where attackers send fake invoices to trick employees into calling a number. This bypasses email filters and uses social engineering to gain initial access, a tactic that targets human trust in financial processes.
Ransomware Actors Are Actively Wiping Cloud Backups
Threat actors are now systematically deleting cloud backups after deploying ransomware, eliminating the safety net organizations rely on for recovery. This tactic forces a harder choice between paying the ransom or accepting permanent data loss.
CISA Orders Patching for Actively Exploited Ivanti EPMM Vulnerability
CISA has added a critical Ivanti EPMM vulnerability to its Known Exploited Vulnerabilities catalog, mandating patching for federal agencies. This signals active exploitation in the wild, meaning private sector organizations should treat this with the same urgency.
Qilin Ransomware Adds New Linux Encryptor to Its Arsenal
The Qilin ransomware group has expanded its toolset with a new Linux encryptor, directly targeting hypervisors and the servers where backup data often resides. This move to encrypt the hypervisor layer can paralyze entire virtualized environments from a single point of failure.
Tools
New Nuclei Templates Added for Aviatrix Controller RCE Vulnerability
The community-driven Nuclei scanning engine received a large template update to detect the critical Aviatrix Controller RCE flaw. If you run Nuclei in your CI/CD or attack surface management pipeline, pulling this update is a quick way to check your exposure.
Stay Ahead
Delivered each morning.