Interesting, to say the least, is how I qualify the articles that we have for this week's review. It's fascinating to know what's possible and reading articles that challenge your reality is something that you and I can put in our autobiography sometime in the future. I mean, wow. Just wow. I bet you'll feel the same when you read each article that I have for you.
Now, what are you waiting for? Let's get started.
Malicious sites use JavaScript to build malware in browser memory
Just when you think that you have seen it all. You read something like this. What's the end goal? Avoiding detection. But, building malware in browser memory? I need to do more research on this. For now, read the excerpt below.
After building the final malware executable, the fake download page hands it to the service worker at the beginning of the process and triggers a same-origin download path. "From the browser’s point of view, the user is downloading an executable from the landing page domain,"
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
It's invisible to the naked eye. The way to detect this malware? During data exfiltration that goes through the network. Then, it might be too late.
From the article:
The hidden desktop allows the attacker to take full advantage of legitimate Windows tools without being observed by the user. The C2 is hardcoded into the malware but is relatively safe from observation. The result is a stealthy and persistent RAT. The only obvious mitigation is detection of unexpected data exfiltration.
For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
The difference between reality and Sci-Fi might appear far away. However, with the recent incidents at OpenAI—where an AI model escaped its sandbox and attacked Hugging Face—and Anthropic—where Claude breached three organizations and uploaded a PyPi malware during tests—you can say that it's only a matter of time.
From the article:
Generative AI is growing so fast that government and evaluation systems are struggling to keep pace with the technology. Countries around the world are cobbling together their own laws, some conflicting.
The technology was adopted by nearly 53% of the world’s population in three years, faster than the spread of the PC or the internet, according to a study released this year by Stanford University.
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Nine years. How many lives have been impacted? How many have cried with their tears never ending when they realized that they sent money for goods that never existed? How about the reputational damage suffered by the affected companies? And, I can go on.
From the article:
The scheme works by deceiving potential clients into visiting the replica sites, which have the contact details altered to lead them to the attackers.
Select instances have involved the threat actors hiring unsuspecting sales representatives to make cold calls, who are instructed to pass the customer to a "senior manager" once the negotiations reach the final stage.
From this point onwards, the customer's communications are with the fraudsters,
Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
It's one thing to attempt a phishing attack. It's another way to convince the user through the process without them being suspicious. In this campaign, the attackers are using the latter approach and leveraging Microsoft's legitimate login system.
From the article, here is how to prevent yourself from falling victim:
Check Point advises hovering over links before clicking, and treating it as a warning sign if several buttons in one email lead to the same URL. It also recommends checking whether the sender name, address, and domain line up, since display names can be spoofed even when the address looks internal.
Exposed credentials are giving attackers a head start many organizations don’t see
As the saying goes: modern attackers don't break in. They log in. Organizations should know this and act as if attackers are already in their systems.
From the article:
More than seven in 10 companies experienced an authentication-related incident during the past year, and two-thirds of the most recent incidents involved attackers signing in with valid credentials.
Exposed credentials often stay active long enough to be exploited, making early identification a key part of reducing credential-based risk.
Credits
Cover photo by Debby Hudson on Unsplash.
That's it for this week, and I'll see you next time.
Top comments (0)