Backups Are the Bullseye: Linux Ransomware and Management Plane Bugs
News
CISA Puts Ivanti EPMM on the Spot with KEV Addition
CISA officially added an Ivanti Endpoint Manager Mobile (EPMM) vulnerability to its Known Exploited Vulnerabilities catalog. If you're running Ivanti in your stack, this is now a mandatory patch under CISA's directive; non-compliance is a liability.
Aviatrix Controller's Critical Cloud Network Flaw Revealed
Aviatrix's controller had a critical flaw that could have allowed attackers to compromise your entire cloud network fabric. This is a prime example of why compromising the management plane is the endgame for cloud attackers today.
FBI Flags Luna Moth’s Low-Tech Callback Phishing Strategy
Luna Moth is skipping the malware and hitting companies with callback phishing to get remote access directly. It's a low-tech, high-yield attack that completely blows past your EDR if your users are trained to call 'support' on their own.
Tactics
Ransomware Gangs Now Targeting Cloud Backup Deletion
Ransomware gangs are now hitting cloud backups, meaning your disaster recovery plan might get deleted first. You need immutable, air-gapped backups, or you're just betting that your S3 bucket permissions are perfect.
Tools
Nuclei Templates Updated for New AI SSRF Flaw
Nuclei just shipped new templates for finding that AI SSRF flaw researchers discovered last week. For builders, this is a direct way to pipeline the proof-of-concept into your scanning workflow without waiting for vendor patches.
Threat Intel
Qilin Ransomware Expands to Linux Attack Vectors
The Qilin ransomware group is shipping a dedicated Linux encryptor, specifically aiming at ESXi and other hypervisors. This confirms that the 'Linux as a soft spot' thesis is the standard operating procedure for top-tier gangs now.
Stay Ahead
Delivered each morning.