Tag Mandiant

Please Avoid Feeding the Dispersed Lapsus Shiny Hunters – Krebs on Security

Scattered Lapsus Shiny Hunters: A New Threat in Cyber Extortion A notorious cyber extortion group known as Scattered Lapsus Shiny Hunters (SLSH) has been making headlines for its aggressive tactics in seeking ransoms from compromised organizations. This group employs a unique and harrowing approach that goes beyond conventional ransomware schemes,…

Read MorePlease Avoid Feeding the Dispersed Lapsus Shiny Hunters – Krebs on Security

Social Engineering Attackers Target Okta’s Single Sign-On System

Fraud Management & Cybercrime, Identity & Access Management, Security Operations ShinyHunters Campaign Utilizes Voice Phishing to Circumvent MFA and Compromise Corporate Data Mathew J. Schwartz (euroinfosec) • January 28, 2026 Image: Oleksandr Yashchuk/Shutterstock Security experts are advising customers of identity provider Okta utilizing its single-sign-on (SSO) services to remain vigilant…

Read MoreSocial Engineering Attackers Target Okta’s Single Sign-On System

Part II: These 7 Major Cyber Attacks Show That No One is Safe from Hacking

In an increasingly interconnected world, recent cyber incidents underscore the vulnerabilities that organizations face today. A notable highlight includes a series of impactful cyber attacks that exemplify the pressing need for robust cybersecurity measures across various sectors. One alarming case involved the hacking of vehicles, particularly the Jeep Cherokee. Security…

Read MorePart II: These 7 Major Cyber Attacks Show That No One is Safe from Hacking

Real-Time Phishing Kits Now Targeting Okta, Microsoft, and Google

Cybersecurity experts are currently grappling with a surge of voice-phishing attacks aimed at single sign-on (SSO) tools. These coordinated efforts have led to instances of data theft and extortion, as various cybercrime groups, including one claiming ties to ShinyHunters, harness sophisticated voice calls and phishing kits to deceive victims into…

Read MoreReal-Time Phishing Kits Now Targeting Okta, Microsoft, and Google

Critical Zero-Day Vulnerabilities in Atera Windows Installers Put Users at Risk of Privilege Escalation Attacks

Recent findings from cybersecurity firm Mandiant reveal significant zero-day vulnerabilities in Windows Installers associated with Atera’s remote monitoring and management software. These vulnerabilities could potentially be exploited to initiate privilege escalation attacks against affected systems. Identified on February 28, 2023, these vulnerabilities have been allocated the identifiers CVE-2023-26077 and CVE-2023-26078.…

Read MoreCritical Zero-Day Vulnerabilities in Atera Windows Installers Put Users at Risk of Privilege Escalation Attacks

Casino Files Lawsuit Against Cybersecurity Firm for Inability to Prevent Hackers

A cybersecurity firm, Trustwave, is facing legal action from Affinity Gaming, a casino operator based in Las Vegas. The lawsuit alleges that Trustwave conducted an investigation deemed “woefully inadequate” in response to a network breach that exposed the casino’s systems. The action highlights growing concerns regarding the effectiveness of cybersecurity…

Read MoreCasino Files Lawsuit Against Cybersecurity Firm for Inability to Prevent Hackers

Hackers Use “SUBMARINE” Backdoor in Barracuda Email Security Gateway Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently revealed critical details regarding a sophisticated backdoor malicious software identified as SUBMARINE. This malware has reportedly been employed by threat actors in connection with an exploit targeting Barracuda Email Security Gateway (ESG) appliances, which has raised alarms within the cybersecurity landscape.…

Read MoreHackers Use “SUBMARINE” Backdoor in Barracuda Email Security Gateway Attacks