Author: Robert Timlick

  • Leaked Credentials Up 160%: What Attackers Are Doing With Them

    Leaked Credentials Up 160%: What Attackers Are Doing With Them

    When an organization’s credentials are leaked, the immediate consequences are rarely visible—but the long-term impact is far-reaching. Far from the cloak-and-dagger tactics seen in fiction, many real-world cyber breaches begin with something deceptively simple: a username and password.
    According to Verizon’s 2025 Data Breach Investigations Report, leaked credentials accounted for 22% of breaches
  • GreedyBear Steals $1M in Crypto Using 150+ Malicious Firefox Wallet Extensions

    GreedyBear Steals $1M in Crypto Using 150+ Malicious Firefox Wallet Extensions

    A newly discovered campaign dubbed GreedyBear has leveraged over 150 malicious extensions to the Firefox marketplace that are designed to impersonate popular cryptocurrency wallets and steal more than $1 million in digital assets.
    The published browser add-ons masquerade as MetaMask, TronLink, Exodus, and Rabby Wallet, among others, Koi Security researcher Tuval Admoni said.
    What makes the
  • SocGholish Malware Spread via Ad Tools; Delivers Access to LockBit, Evil Corp, and Others

    SocGholish Malware Spread via Ad Tools; Delivers Access to LockBit, Evil Corp, and Others

    The threat actors behind the SocGholish malware have been observed leveraging Traffic Distribution Systems (TDSs) like Parrot TDS and Keitaro TDS to filter and redirect unsuspecting users to sketchy content.
    “The core of their operation is a sophisticated Malware-as-a-Service (MaaS) model, where infected systems are sold as initial access points to other cybercriminal organizations,” Silent Push
  • Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You Need

    Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You Need

    Python is everywhere in modern software. From machine learning models to production microservices, chances are your code—and your business—depends on Python packages you didn’t write.
    But in 2025, that trust comes with a serious risk.
    Every few weeks, we’re seeing fresh headlines about malicious packages uploaded to the Python Package Index (PyPI)—many going undetected until after they’ve caused
  • Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes

    Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes

    Cybersecurity researchers have discovered a set of 11 malicious Go packages that are designed to download additional payloads from remote servers and execute them on both Windows and Linux systems.
    “At runtime the code silently spawns a shell, pulls a second-stage payload from an interchangeable set of .icu and .tech command-and-control (C2) endpoints, and executes it in memory,” Socket security
  • Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups

    Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups

    Microsoft has released an advisory for a high-severity security flaw affecting on-premise versions of Exchange Server that could allow an attacker to gain elevated privileges under certain conditions.
    The vulnerability, tracked as CVE-2025-53786, carries a CVSS score of 8.0. Dirk-jan Mollema with Outsider Security has been acknowledged for reporting the bug.
    “In an Exchange hybrid deployment, an
  • Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You Need

    Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You Need

    Python is everywhere in modern software. From machine learning models to production microservices, chances are your code—and your business—depends on Python packages you didn’t write.
    But in 2025, that trust comes with a serious risk.
    Every few weeks, we’re seeing fresh headlines about malicious packages uploaded to the Python Package Index (PyPI)—many going undetected until after they’ve caused
  • Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft

    Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft

    Cybersecurity researchers have demonstrated an “end-to-end privilege escalation chain” in Amazon Elastic Container Service (ECS) that could be exploited by an attacker to conduct lateral movement, access sensitive data, and seize control of the cloud environment.
    The attack technique has been codenamed ECScape by Sweet Security researcher Naor Haziz, who presented the findings today at the
  • Fake VPN and Spam Blocker Apps Tied to VexTrio Used in Ad Fraud, Subscription Scams

    Fake VPN and Spam Blocker Apps Tied to VexTrio Used in Ad Fraud, Subscription Scams

    The malicious ad tech purveyor known as VexTrio Viper has been observed developing several malicious apps that have been published on Apple and Google’s official app storefronts under the guise of seemingly useful applications.
    These apps masquerade as VPNs, device “monitoring” apps, RAM cleaners, dating services, and spam blockers, DNS threat intelligence firm Infoblox said in an exhaustive
  • Merkley, Dexter: Congress must protect farmworkers from hazardous wildfire smoke, extreme heat

    Merkley, Dexter: Congress must protect farmworkers from hazardous wildfire smoke, extreme heat

    WASHINGTON, D.C. — Oregon’s U.S. Sen. Jeff Merkley and U.S. Rep. Maxine Dexter (OR-03) announced Aug. 6 they introduced the Farmworker Smoke and Excessive Heat Protection Act. The bicameral bill would put safeguards in place for farmworkers facing the dangers…