news.mlab.sh
Back to the feed
threat-intel

You were onto something with “It’s the Climb,” Miley

High
Image: Cisco Talos
Summary

This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-factor authentication. Simultaneously, ransomware operators are weaponizing legitimate remote management tools, such as MeshAgent and Zoho Assist, to establish stealthy, persistent access. The report emphasizes the need for organizations to transition beyond traditional defenses and adopt more robust methods, including FIDO2 and hardware security keys, alongside behavior-based monitoring and centralized logging. Several high-profile incidents are also detailed, including a coordinated cyberattack on Minnesota water systems, credential theft via compromised public Wi-Fi gateways, and a default Azure Automation setting that enabled cross-tenant identity takeover.

Read the full article at Cisco Talos

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.