InfoSec

@infosec.skyfleet.blue

Relay Tracking News & Blogs about infosec, cybersec - source removal/addition suggestions welcome ! CVE : check out @cve.skyfleet.blue 🆘 @skyfleet.blue

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools

Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official government portals can be weaponized against enterprise targets. Threat intelligence research from ANY.RUN reveals that attackers across the United States, Europe, and Brazil systematically exploited routine corporate workflows to bypass perimeter security controls, harvest credentials, and maintain long-term access to systems. Hackers Turn Trusted Sites Into Attack Tools The defining trend across July’s threat landscape was the exploitation of platform legitimacy. Phishing operations systematically routed targets through SharePoint, OneDrive, Microsoft Forms, and legitimate authentication interfaces before delivering malicious payloads. A phishing-as-a-service (PhaaS) platform known as Kratos deployed document-sharing and DocuSign-style lures to funnel Microsoft 365 users through trusted cloud infrastructure toward credential-harvesting pages. Because these redirect chains mirrored standard administrative workflows, both automated security gateways and human targets allowed the traffic through. Kratos phishing attack flow (Image Source: ANY.RUN) Concurrently, a campaign tracked as Kali365 abused Microsoft’s genuine device-code authentication flow. By directing victims to authentic Microsoft login endpoints and inducing them to enter attacker-generated authorization codes, adversaries obtained OAuth tokens. These stolen identity tokens granted persistent cloud access to email archives and shared repositories without harvesting account passwords. The campaign recorded over 80 weekly sandbox detections across manufacturing, healthcare, government, and consulting sectors. Kratos sandbox analysis view (Image Source: ANY.RUN) Adversaries further expanded delivery mechanisms by abusing legitimate Zoom Event pages, creating fake summits branded around OpenAI, Anthropic, and Meta partner conferences. Tapping the “Continue to register” button redirected targets to device-code phishing interfaces or adversary-in-the-middle (AiTM) proxies. Zoom event lure templates (Image Source: ANY.RUN) As detailed in campaign analysis from the ANY.RUN, regional Cyber threat operations similarly weaponized trusted public-sector domains. In Brazil, the PhantomEnigma campaign compromised over 20 municipal and police web portals ( .gov.br ) to host malware. Hijacked municipal email accounts dispatched phishing lures that successfully passed SPF, DKIM, and DMARC verification checks. PhantomEnigma activity timeline (Image Source: ANY.RUN) Single-device intrusions frequently cascaded into enterprise-wide operational risk. Modular payloads such as DestinyStealer harvested browser credentials, session cookies, Outlook data, VPN profiles, FileZilla logins, and cryptocurrency wallets, exfiltrating data across parallel HTTP and TCP channels. These specialized infostealer malware strains continue to evade traditional static antivirus detection. OVERLORD live C2 channel (Image Source: ANY.RUN) During one active intrusion, researchers monitored an operator deploying OVERLORD RAT via a live command-and-control channel. Within 45 minutes, the attacker exfiltrated 86 MB of sensitive files, browser sessions, internal messaging logs, and crypto wallet stores. Meanwhile, variant updates to Banana RAT introduced randomized file structures and encrypted WebSocket communications, while secondary campaigns deployed DARTHVADER Stealer via malicious shortcut files using native Windows utilities, AutoIt, and PowerShell script chains. Adversaries rely on this resilient command infrastructure to maintain persistent access following initial endpoint execution. Campaign / Threat Core Weaponization Vector Operational Impact Kratos PhaaS Trusted cloud redirects & DocuSign lures M365 credential theft & cloud access Kali365 OAuth device-code login flow abuse Passwordless persistent token harvesting Zoom Lure Operations Counterfeit AI summit event registration pages AiTM redirection & credential harvesting PhantomEnigma Compromised .gov.br portals & government mail Legitimate mail auth bypass & RAT delivery OVERLORD / Banana RAT Live C2 channels & encrypted WebSockets Real-time data exfiltration & persistent access A critical finding from these July campaigns is that threat actors rotate infrastructure far faster than traditional blacklists can update. Simple password resets often fail to remediate intrusions when active OAuth tokens or session cookies remain valid in attacker hands. Security teams must move beyond static IOC blocking toward behavior-based telemetry, continuous session monitoring, and campaign-level correlation to identify multi-stage attack chains before lateral movement occurs. The post Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools appeared first on Cyber Security News .

cybersecuritynews.com

Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year

Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year

Microsoft has awarded more than $20 million to 562 security researchers through its bug bounty program , marking the largest annual payout in the company’s history. Researchers from 64 countries reported security flaws that could have affected Microsoft customers, cloud users, businesses, and consumers worldwide. The Microsoft Security Response Center, also known as MSRC, said the results show the value of coordinated vulnerability disclosure. Under this process, security researchers privately report weaknesses to Microsoft before attackers can exploit them. Microsoft then investigates the issue, creates a fix, and releases security updates to protect customers. The new record is a major increase from the previous year. Microsoft paid $17 million to 344 researchers from 59 countries last year. The latest figures show that the company is receiving more reports, rewarding more researchers, and expanding the reach of its vulnerability research programs. Microsoft Awards $20M in Record Bounty Year Bug bounty programs are an important part of modern cybersecurity. Independent researchers test products, services, and platforms for weaknesses that internal security teams may not find. Their work helps companies identify risks before they become public incidents, data breaches, ransomware attacks, or zero-day exploits . Microsoft said every valid vulnerability report allows its engineers to reduce risk before criminals can use the flaw against customers. The company highlighted the research community’s role in securing cloud services, artificial intelligence systems, enterprise software, and consumer technologies. The growth was especially noticeable during the second half of the year, when Microsoft received a higher volume of submissions. The company said increased researcher participation and wider use of AI tools in security research contributed to this rise. AI can help researchers review code, analyze attack paths, identify unusual behavior, and test complex systems more efficiently. Microsoft’s Zero Day Quest event also played a key role in the record year. The live hacking event brought researchers from 20 countries to Microsoft’s Redmond campus. Participants worked directly with Microsoft security and engineering teams to examine high-priority scenarios involving cloud and AI technologies. During Zero Day Quest, researchers submitted nearly 700 vulnerability reports and received $2.3 million in awards. The event allowed Microsoft to collect reports rapidly while helping researchers better understand the company’s products, security priorities, and vulnerability reporting process. Microsoft has also expanded the scope of its bounty rewards program. Eligible findings can now include certain open-source software, third-party components, and Microsoft cloud services that may not have qualified under older bounty rules. Since this expansion, Microsoft has received more than 300 additional reports and paid over $800,000 for vulnerabilities that previously may have gone unrewarded. According to the MSRC report , the record payout highlights the growing reliance on external security researchers as modern software environments span cloud platforms, identity systems, AI services, open-source software, and third-party dependencies. Microsoft said finding weaknesses across its broad attack surface requires collaboration with the global security community, thanking researchers whose reports, technical expertise, and coordinated disclosures help strengthen security for billions of users worldwide. Researchers interested in participating can learn more about Microsoft’s vulnerability rewards programs through the company’s official bug bounty portal at aka.ms/bugbounty.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post Microsoft Awards Record $20 Million to 562 Researchers in Biggest Bug Bounty Year appeared first on Cyber Security News .

cybersecuritynews.com

New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable

New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable

Las Vegas, United States, August 5th, 2026, CyberNewswire Pulse Security AI calls for boards and security leaders to define cyber risk appetite in new report: The CISO-Board Communication Gap Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident their board walks away understanding the true state of the program, and 55% of boards have never formally defined what cyber risk the company is willing to accept.  Pulse Security AI unveiled these findings today in The CISO-Board Communication Gap , a research report drawing on more than 80 senior practitioners, examining how security leaders report to their boards and what gets lost between the two. “For a decade, the industry has told security leaders to communicate better with the board,” said Mike Armistead, CEO and co-founder of Pulse Security AI. “Our data says the problem is upstream of that. You cannot report status against a baseline that was never set.” Here are the top five insights from the research: The Confidence Gap is Measurable. Just 12.5% of security leaders are very confident their board accurately understands the program after a presentation. 41% land at somewhat confident, and 38% are neutral or mixed. Both sides leave the room, and the cycle continues largely unchanged. The Baseline Was Never Set. 55% of boards have never formally defined cyber risk appetite, and another 27% define it only qualitatively. Without an agreed baseline, external noise fills the vacuum: roughly 70% of security leaders say board members bring third-party ratings and press coverage into the room, and 42% had to defend a commercial security score in the past 12 months. Board Prep is an Operational Tax. 71% of security leaders spend 10 or more hours preparing for each board cycle, one to two full working days every quarter, and 39% involve four or more contributors per presentation. The top time sinks: building slides, gathering data across tools, and translating findings into business language. Governance Runs on Instinct, Not Instrumentation . Half of boards made no explicit decision to accept, mitigate, or transfer cyber risk in the past year. 48% of security leaders have no private executive session access, 23% have no predefined threshold for board-level escalation, and 33% say their own legal exposure shapes what they tell the board. Trust is Recoverable, and a Breach Shouldn’t Be the Trigger . 53% of security leaders say board trust increased after a material security incident. A real event forces a shared, concrete understanding of risk that quarterly updates rarely produce. The report details five practices, drawn from leaders with the highest board trust, for creating that alignment. Armistead continues, “You cannot assemble a clear picture of the business when the underlying information lives in a dozen disconnected places. Security leaders have earned the room. What they need now is the operating layer underneath it.” Download the full report, The CISO-Board Communication Gap: https://pulsesecurity.ai/newsroom/ciso-board-communication-gap/ Methodology Findings draw on a 42-respondent survey of security leaders and corporate directors, more than 20 in-depth interviews with sitting and former CISOs, and two moderated workshops with roughly 22 CISOs. Seventy percent of survey respondents are CISOs or heads of security. Industries represented include technology and software (34%), financial services (25%), healthcare and life sciences (9%), and manufacturing (9%). These are not nationally representative statistics. Their value is depth and seniority: participants are the people who sit in audit committee meetings. Percentages are computed on those answering each question. A small corporate-director sub-sample is treated as directional only. Quotes are anonymized at participants’ request. About Pulse Security AI Pulse Security AI is redefining how cybersecurity programs are run. Pulse is an operational management platform for security leaders, where security professionals and AI agents work together to execute procedures, capture decisions, and deliver real-time program visibility without the manual overhead. The result is a security organization that runs faster, costs less, and gives leaders clear confidence in where their program stands.  Contact Carmen Angela Harris Pulse Security carmen@pulsesecurity.ai The post New Research: The Confidence Gap Between CISOs and Their Boards Is Real, and It’s Measurable appeared first on Cyber Security News .

cybersecuritynews.com

Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance

Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance

SIngapore, Singapore, August 5th, 2026, CyberNewswire Uppsala Security , a Singapore-based blockchain intelligence and crypto forensics company, announced today that it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the alliance. CTA is a nonprofit organization that brings cybersecurity organizations together to share actionable threat intelligence, improve situational awareness and strengthen collective defenses against malicious actors. Uppsala Security’s membership adds an on-chain perspective to CTA’s intelligence-sharing community at a time when cybercrime increasingly spans both traditional digital infrastructure and blockchain networks. Many cyber incidents begin with phishing, ransomware, malware, compromised credentials or unauthorized access. Stolen assets may then move through blockchain wallets, exchanges, bridges, mixers and other digital asset services. Although these activities may be part of the same incident, evidence from the initial compromise and the subsequent movement of assets is often analyzed by different teams using separate data sources. This separation can make it difficult to understand the full progression of an incident, from the initial attack to the movement of stolen funds. Through its participation in CTA, Uppsala Security plans to contribute relevant on-chain threat intelligence, including malicious wallet activity, suspicious transaction patterns, illicit fund movements and other blockchain-based indicators. When combined with traditional cyber threat indicators such as malicious infrastructure, malware artifacts, domains and IP addresses, on-chain intelligence can help investigators and security teams develop a more complete understanding of an incident. “Cybercrime does not stop when an attacker leaves a network. Stolen assets can continue moving on-chain, and those movements may preserve important evidence about how an incident developed and where the proceeds are going,” said Patrick Kim, Founder and CEO of Uppsala Security. “Joining CTA gives us an opportunity to connect that on-chain perspective with the cyber threat intelligence already shared by its members. By bringing these two areas together, we can help the wider cybersecurity community understand incidents more completely and respond more effectively,” Patrick added. In its official membership announcement, CTA said Uppsala Security brings a different type of threat intelligence from that of a typical cybersecurity company. CTA also noted that combining different forms of intelligence and insight can increase the value of the information shared among its members. Uppsala Security will also draw on the experience of CTA members to better understand the infrastructure, tactics and indicators associated with cyber incidents before stolen assets move on-chain. The membership is expected to support closer cooperation among cybersecurity companies, blockchain intelligence providers, financial institutions, digital asset businesses and law enforcement agencies responding to cyber and financial crimes that operate across borders. Uppsala Security plans to use its CTA membership to expand international information sharing, exchange investigative experience with other members and contribute to more coordinated responses to cybercrime involving digital assets. About Uppsala Security Founded in Singapore in 2018, Uppsala Security is a blockchain intelligence and crypto forensics company providing threat intelligence, forensic technologies and investigation services. The company supports law enforcement agencies, regulators, financial institutions, digital asset businesses and enterprises in identifying crypto-related threats, tracing illicit assets and investigating financial crime. Its work combines blockchain data, cyber threat intelligence and investigative analysis to help organizations detect, understand and respond to activity across digital asset networks. About the Cyber Threat Alliance The Cyber Threat Alliance is a nonprofit organization committed to strengthening the security of the global digital ecosystem through the sharing of actionable threat intelligence among cybersecurity practitioners. CTA members collaborate to improve situational awareness, strengthen collective defenses and more effectively disrupt malicious actors. Contact Media Contact Uppsala Security info@uppsalasecurity.com The post Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance appeared first on Cyber Security News .

cybersecuritynews.com

77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data

77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data

A wave of counterfeit Open VSX extensions has exposed how easily a familiar developer tool can become a data collection channel. Seventy-seven packages copied the names, namespaces, and descriptions of legitimate extensions, then contacted the same newly registered domain. The campaign appeared between July 26 and August 1, 2026. Most packages sent basic device details, but 19 contained a far more intrusive reconnaissance routine that collected repository and continuous integration information from developer workstations and build environments. Researchers at Manifold identified the operation and found that the packages were published by accounts unrelated to extension authors. Manifold said in a report shared with Cyber Security News (CSN) that the listings presented the activity as telemetry, a label that concealed the real reach of the code. ciIdentity() function within extension.js collecting CI identity data (Source – Manifold) Private repository names, project paths, branch details, and CI identifiers can reveal an organisation’s internal development work, making it useful for targeted phishing, follow-on intrusion attempts, or mapping a software supply chain. 77 Evil Twin Open VSX Extensions The rogue packages used a simple but effective impersonation method. They reused familiar extension identities, often at version 0.0.1, while replacing the extension.js content with code designed to beacon information outward. This mirrors the risk seen in  malicious VSCode marketplace extensions , where familiar tools can mask harmful behavior. Fifty-eight of the packages were lightweight beacons that reported a hostname and sometimes a workspace folder or editor version. The 19 reconnaissance variants activated within seconds and gathered the hostname, operating-system username, editor details, device identifiers, location settings, workspace name, and full local path. The more serious variants also inspected Git metadata. They pulled the host and organisation from origin and upstream remote URLs, the domain portion of the configured commit email, the current branch, and the latest commit identifier. Notice the ‘telemetry’ section on the extension’s readme webpage (Source – Manifold) On a build runner, CI variables could expose the full name or path of a private repository. The code checked for values for GitHub Actions, GitLab CI, Azure DevOps, Buildkite, CircleCI, Codespaces, and Gitpod. It also listed installed extensions and read the editor’s telemetry preference, but transmitted the collected information even when that setting indicated an opt-out. That behavior is especially troubling because the marketplace pages claimed CI values would remain on the machine. The researchers found code sent both CI marker names and their values. Readers tracking the broader trend can see similar supply-chain exposure in  trusted developer tooling attacks . Persistence Raises Supply Chain Risk The infrastructure was designed for persistence. Packages used multiple hosts under the same domain, retried connections for up to seven days, and treated any HTTP response as a successful delivery. If hardcoded endpoints failed, the code could query DNS TXT records for a replacement collection address. This matters because extension installation is increasingly automated. Devcontainer configurations, editor setup scripts, and provisioning workflows may install an extension by name without checking publisher ownership, download history, or project lineage. The problem resembles recent  Open VSX sleeper extensions , which showed how malicious packages can wait inside development ecosystems. As of August 3, the packages had been removed from Open VSX, but removal does not erase code already placed in workstation images, build systems, or repository configuration. Teams should search developer and CI images for matching entries in .vscode/extensions.json, .devcontainer/devcontainer.json, and .devcontainer.json, then verify the extensions installed. Organisations should block the identified domain, pin internally mirrored packages by publisher and version, and treat unverified publisher warnings as a stopping point for automated installations. Security teams should also alert on editor processes contacting newly registered domains shortly after startup and on DNS TXT lookups using _beacon labels. The incident reinforces that code editor extensions deserve the same scrutiny as any other software dependency. Reviewing runtime behavior, controlling automated installs, and validating publisher identity can reduce the chance that a copied name becomes a route into private engineering data across distributed software development teams globally. Indicators of compromise (IoCs):- Type Indicator Description Domain mangorbit[.]com Primary campaign domain used by all 77 identified packages Host pulse.mangorbit[.]com Beacon collection endpoint Host pulse2.mangorbit[.]com Secondary beacon collection endpoint Host api.mangorbit[.]com Beacon endpoint used by one observed sample Host pattern *.cb.mangorbit[.]com Randomised callback subdomains used by one observed sample URI path /t/<24-hex tracking id> Tracking endpoint path URI path /api/v1/metrics Metrics collection endpoint URI path /api/v1/events Event collection endpoint DNS TXT query _beacon.<domain> Mechanism used to retrieve a replacement collection URL DNS TXT response pattern base=https:// Prefix expected in the TXT-record response User-Agent vscode-ext-metrics/1.0 User-Agent used for outbound beacon traffic File name extension.js Modified extension file containing beacon and reconnaissance code Malicious extension ID lego-education.ev3-micropython  version  0.0.2 Observed counterfeit Open VSX extension Malicious extension ID better-ts-errors.better-ts-errors  version  0.0.1 Observed counterfeit Open VSX extension Malicious extension ID groksrc.ruby  version  0.0.1 Observed counterfeit Open VSX extension Malicious extension ID maptz.regionfolder  version  0.0.1 Observed counterfeit Open VSX extension Malicious extension ID mitsuhiko.insta  version  0.0.1 Observed counterfeit Open VSX extension Malicious extension ID SBSnippets.pytorch-snippets  version  0.0.1 Observed counterfeit Open VSX extension Malicious extension ID slb235.vscode-coffeelint  version  0.0.1 Observed counterfeit Open VSX extension Malicious extension ID amd.gaia-vscode  version  0.0.1 Observed reconnaissance extension Malicious extension ID artsy.artsy-studio-extension-pack  version  0.0.1 Observed reconnaissance extension Malicious extension ID configcat.configcat-feature-flags  version  0.0.1 Observed reconnaissance extension Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stop new phishing & malware before they compromise your business.  Integrate live intel from 15K SOCs around the world The post 77 Evil Twin Open VSX Extensions Exfiltrate Private Git Repository and CI Data appeared first on Cyber Security News .

cybersecuritynews.com

15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution

A set of 15 vulnerabilities in TP-Link’s Omada Zero-Touch Provisioning (ZTP) could enable attacks against enterprise networks, with the findings set to be presented at Black Hat USA 2026. TP-Link Omada is widely used to manage routers, switches, gateways, and wireless access points from a central controller. ZTP helps administrators deploy large numbers of devices quickly. When a new device connects, it finds the controller and receives configuration details, credentials, and firmware updates without manual setup. This convenience creates a high-value target. If attackers can compromise the trust relationship between a controller and its managed devices, they may gain access to an entire fleet rather than a single router. The newly reported flaws affect Omada cloud, software, and hardware controllers, as well as Omada and Festa VPN routers. Some issues may also extend to TP-Link IP cameras , smart-home products, cloud accounts, and multiple Android applications, including Tapo, Kasa, Deco, Tether, and Omada Guard. The vulnerabilities fall into four major categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications. TP-Link Omada ZTP Flaws Several flaws involve hard-coded cryptographic keys , predictable serial numbers, weak password-hash protections, insecure certificate validation, and poor authentication during device adoption. One critical issue, CVE-2025-15628, involves a hard-coded TLS certificate and private key used by version 2 of the Omada protocol. This can undermine the chain of trust between controllers and client devices. Another issue, CVE-2025-15627, affects version 1 of the protocol through a hard-coded private key. Attackers may use these weaknesses to impersonate trusted systems or intercept protected communications. Forescout researchers also identified a cloud adoption race condition, tracked as CVE-2025-15630, that could allow attackers to spoof a device’s MAC address during registration and steal configuration data, including administrator credential hashes, site credentials, and VPN keys. CVE-2025-9289 could allow cross-channel scripting in the controller web interface due to improperly sanitized device-adoption values. This could enable attackers to inject malicious JavaScript into an administrator session, steal credentials through fake login prompts, or extract controller data. When combined with previously disclosed flaws CVE-2025-7850 and CVE-2025-7851, the issues could support a complete attack chain. An attacker could identify unadopted devices, impersonate one during provisioning, obtain sensitive controller data, compromise an administrator account, and then use the controller to modify network settings or target managed routers. In some cases, this could lead to root-level code execution on vulnerable devices. Organizations should apply TP-Link’s available updates for controllers, devices, and mobile applications. Administrators should avoid shared provisioning passwords, use strong unique credentials, enable multifactor authentication for TP-Link IDs, and rotate VPN credentials that may have been exposed. Network defenders should also limit local man-in-the-middle risks through 802.1X, network access control, port security, Dynamic ARP Inspection, wireless client isolation, and segmentation. Continuous intrusion detection and monitoring are important because compromised provisioning systems can appear to be legitimate network management activity.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post 15 TP-Link Omada ZTP Flaws Enable Router Hijacking and Root Code Execution appeared first on Cyber Security News .

cybersecuritynews.com