Ransomware Targets Backups and ESXi While Callback Phishing Resurges
News
FBI Warns of Resurgent "Luna Moth" Callback Phishing Campaigns
The FBI's IC3 is sounding the alarm on a fresh wave of callback phishing campaigns. Attackers are impersonating help desks from major brands to trick victims into installing remote access tools on their endpoints—a classic pivot that bypasses email filters.
Malware
Qilin Ransomware Deploys New Linux/ESXi Encryptor
The Qilin group is expanding beyond Windows, shipping a new encryptor specifically designed for VMware ESXi hypervisors. If you're running virtualized infrastructure, this is a direct signal to harden your hypervisor access controls.
PumaBot Campaign Targets IoT via SSH Credential Stuffing
PumaBot is a new Go-based botnet aggressively brute-forcing weak SSH credentials to compromise Linux-based IoT devices. Once inside, it drops cryptocurrency miners and uses the host for proxy jacking.
Incident Response
Ransomware Groups Now Systematically Wiping Cloud Backups
Modern ransomware operations are shifting tactics to target cloud-based backups and object storage (S3/GCS) early in an attack chain. This makes immutable backups and air-gapped recovery copies non-negotiable for any contingency plan.
Vulnerabilities
SSRF Flaw Found in AI Service Deployment
Security researchers identified a Server-Side Request Forgery (SSRF) flaw in an AI service, highlighting the continuous need to harden APIs even in newer AI-driven stacks. It's a reminder that not all vulnerabilities are in legacy code.
Tools
Nuclei Templates Repository Gets Major Update
Projectdiscovery just merged a major update to the nuclei templates repository, adding detection logic for over 110 new vulnerabilities. If Nuclei is part of your scanning pipeline, pulling this update should be on your to-do list for the week.
Stay Ahead
Delivered each morning.