The New Normal: Backups as Targets, Linux as the Attack Surface
News
Ransomware Now Wipes Cloud Backups Before Encryption
This isn't just encryption anymore, it's scorched-earth. Attackers are deliberately erasing cloud backups to remove recovery options, forcing victims into a pay-or-lose-everything dilemma. Your backup strategy is now part of your attack surface.
Qilin Ransomware Adds Native Linux ESXi Encryptor
The Qilin group is now shipping a dedicated Linux encryptor to hit ESXi hypervisors. This is a direct move against the infrastructure layer where virtual machines and critical data reside. If you're running ESXi, you're a target.
Pumabot Malware Campaign Targets Linux Systems via SSH
A new campaign is using SSH brute-forcing to deploy Pumabot malware on Linux servers. It's a reminder that basic credential hygiene and network segmentation are non-negotiable for any exposed Linux host.
SSRF Flaw Found in AI Service Gateway
Researchers found a Server-Side Request Forgery vulnerability in an AI service gateway. This highlights the expanding attack surface as AI tools get integrated into core infrastructure. Treat AI endpoints like any other critical web app.
FBI Warns of Luna Moth Callback Phishing Campaign
The FBI is out with a warning on a sophisticated callback phishing operation by Luna Moth. They're using fake subscription emails to trick victims into calling for support, then deploying remote access tools. It's social engineering 2.0.
Tools
New Nuclei Template for Detecting Qilin Ransomware Artifacts
The community is already building detection for the Qilin Linux encryptor. This Nuclei template lets you scan for known indicators. It's a good example of how open-source tooling can compress the defender's response time.
Stay Ahead
Delivered each morning.