The Signal
Must Know
Vulnerability · Securityaffairs
What happened
Symantec tracks the group behind Warlock ransomware as Longlegs, also known as Storm-2603, and reports that it continues exploiting unpatched SharePoint flaws for initial access. [1]
In the past two months, Longlegs reportedly hit at least four organizations—a water utility, telecom provider, regional government body, and university—in Portuguese- or Spanish-speaking countries. [1]
Why it matters
In one critical-infrastructure intrusion, security-disabling tooling reached at least 40 hosts in about two hours, and Warlock was then deployed on at least 33 hosts through the domain’s SYSVOL share. [1]
Identity · Securityaffairs
What happened
Jamf Threat Labs identified CloudSyncD as a fake macOS Zoom installer that uses invisible zero-width Unicode characters to conceal a phished password. [2]
The disk image presents a Zoom-branded volume and instructs users to bypass Gatekeeper because the app is only ad-hoc signed. [2]
Why it matters
The second-stage implant checks in every 8 to 16 seconds with a hardware identifier and can receive either a compressed archive or a complete executable to unpack or run. [2]
AI & Agents · The Hacker News
What happened
TA419, described as a China-nexus cyber espionage group, has been attributed to multiple credential-phishing campaigns targeting AI experts at U.S. think tanks, universities, and legal-sector organizations. [3]
The campaigns impersonated prominent economists, AI policymakers, and a prominent Anthropic employee to target an AI policy expert. [3]
Why it matters
Impersonation of policy and research figures makes recipients’ professional context part of the targeting surface rather than a generic lure. [3]
Security · Securityaffairs
What happened
A suspected ShinyHunters member, Saif al-Din Khader, was detained in Jordan and is reportedly cooperating with the FBI and international law enforcement. [4]
One source said Khader was showing investigators his devices and digital communications to help identify former associates. [4]
Why it matters
Reuters reported that a leaked ShinyHunters sample included personal information, sensitive job-related data, and psychiatric and medical records concerning FBI employees. [4]