The Bullseye Has Moved: Backups Are the New Encryption Target
News
FBI Alert: Luna Moth Callback Phishing Bypasses Email Filters
The FBI flagged a sophisticated social-engineering campaign where attackers pose as IT helpdesk staff, tricking victims into installing remote desktop tools. This 'callback' phishing bypasses email filters entirely. If you support users, training them to verify help requests via out-of-band channels is now mandatory risk management.
Ransomware Actors Now Actively Erasing Cloud and Local Backups
Ransomware groups are skipping encryption and simply deleting backups before detonation, aiming to destroy recovery options. This shifts the defense priority from 'good backups' to 'backups the attacker cannot access at all,' requiring immutable, air-gapped, or heavily access-controlled storage architectures.
Ivanti EPMM Vulnerability Added to CISA's Actively Exploited List
CISA has added a critical Ivanti EPMM flaw to its 'Known Exploited Vulnerabilities' catalog, confirming active exploitation in the wild. Power dynamics shift fast: if you run EPMM, patching is no longer a risk-based decision. The window for 'test and stage' has closed.
RansomHub Overtakes LockBit as Most Active Ransomware Operation
RansomHub has overtaken LockBit as the most active ransomware-as-a-service operation, leveraging affiliate recruitment and rapid exploit adoption. The fragmentation of the ransomware market means defenders are now tracking a dozen capable threat actors rather than focusing on one apex predator. Incident response plans need to account for distinct TTPs, not just 'ransomware.'
Lazarus-Linked Maui Ransomware Returns With Updated Tactics
North Korean operators behind the Maui ransomware have resurfaced with new obfuscation techniques and updated encryption modules. This suggests state-sponsored threat actors are iterating on tooling independently of the commercial ransomware market. Financial institutions and critical infrastructure should treat this as a separate threat category from common RaaS payloads.
Qilin Ransomware Deploys New Linux Encryptor Targeting Hypervisors
Qilin ransomware now has a fully functional Linux encryptor, targeting hypervisors and ESXi servers. Attackers are optimizing for the infrastructure layer where organizations consolidate critical workloads. Defenders running VMware-heavy environments should verify backup isolation and test restore procedures immediately.
Tools
New Nuclei Templates Released for Latest Vulnerability Checks
New Nuclei templates were added to Project Discovery for detecting recently disclosed vulnerabilities. This keeps automated scanning pipelines current without manual fingerprinting. For teams running continuous vulnerability assessment, pulling the latest template set daily is a high-leverage habit.
Stay Ahead
Delivered each morning.