data theft

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
This week's cybersecurity landscape features several significant threats, including the abuse of legitimate signed drivers for kernel operations, a large-scale cyber espionage campaign by an Iran-based group targeting universities, and malware utilizing DLL sideloading. Additionally, advancements in AI safety are being explored by OpenAI and Google, while a new service, Kriminal AI, offers unfiltered AI responses, raising concerns about misuse. Apple is also modifying its App Tracking Transparency feature in Germany following regulatory scrutiny.

Rogue ransomware affiliate poses as recovery firm to steal payments
A threat actor, operating under the guise of a ransomware recovery service named 'Ransom Busters,' is contacting victims before attacks are publicly disclosed. This entity claims to offer decryption keys and data deletion services for a fee, but evidence suggests it is actually the ransomware affiliate responsible for the attacks. The group is suspected of exploiting vulnerabilities to gain access to encryption keys and victim data, then attempting to extort victims directly, potentially defrauding both the victims and the ransomware gangs they work with.

New Helix Group Targets SharePoint Data via Vishing and MFA Abuse
A newly identified cybercriminal group, known as Helix, is employing sophisticated identity-based attacks to exfiltrate data from SharePoint environments. Their methods include voice phishing, device code phishing, and the abuse of multi-factor authentication systems.

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
A recent phishing campaign has been identified that utilizes sophisticated techniques including obfuscated JavaScript and PowerShell. The attackers employ process hollowing and a variant of the PureLogs malware to exfiltrate sensitive user data.