Symantec tracks the group behind Warlock ransomware as Longlegs, also known as Storm-2603, and reports that it continues exploiting unpatched SharePoint flaws for initial access. In the past two months, Longlegs reportedly hit at least four organizations—a water utility, telecom provider, regional government body, and university—in Portuguese- or Spanish-speaking countries.
Why it matters
In one critical-infrastructure intrusion, security-disabling tooling reached at least 40 hosts in about two hours, and Warlock was then deployed on at least 33 hosts through the domain’s SYSVOL share.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · Securityaffairs
What happened
Jamf Threat Labs identified CloudSyncD as a fake macOS Zoom installer that uses invisible zero-width Unicode characters to conceal a phished password. The disk image presents a Zoom-branded volume and instructs users to bypass Gatekeeper because the app is only ad-hoc signed.
Why it matters
The second-stage implant checks in every 8 to 16 seconds with a hardware identifier and can receive either a compressed archive or a complete executable to unpack or run.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
AI & Agents · The Hacker News
What happened
TA419, described as a China-nexus cyber espionage group, has been attributed to multiple credential-phishing campaigns targeting AI experts at U.S. think tanks, universities, and legal-sector organizations. The campaigns impersonated prominent economists, AI policymakers, and a prominent Anthropic employee to target an AI policy expert.
Why it matters
Impersonation of policy and research figures makes recipients’ professional context part of the targeting surface rather than a generic lure.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.