EncryptHub abuses Brave Support in new campaign exploiting MSC EvilTwin flaw

EncryptHub actor exploits Windows flaw CVE-2025-26633 (“MSC EvilTwin”) with rogue MSC files and social engineering to drop malware.

Security Affairs
🎭 Ah, #EncryptHub unmasked: where #ChatGPT plays detective and #OPSEC blunders are the plot twist! 💥 Because who needs #cybersecurity when you can have a soap opera of digital mishaps? 🙃
https://outpost24.com/blog/unmasking-encrypthub-chatgpt-partner-crime/ #digitalmishaps #HackerNews #ngated
Unmasking EncryptHub: Help from ChatGPT & OPSEC blunders  

Understand EncryptHub’s cybercrime journey and how he used ChatGPT as an accomplice, uncovering the methods behind his actions.

Outpost24

Imagine a hacker who not only exploited zero-days to breach over 600 organizations but also played the hero by patching vulnerabilities for Microsoft. How does one person walk the line between cybercrime and cybersecurity?

https://thedefendopsdiaries.com/decrypting-encrypthub-a-cybersecurity-enigma/

#cybersecurity
#encrypthub
#bugbounty
#ethicalhacking
#cybercrime

Decrypting EncryptHub: A Cybersecurity Enigma

Explore EncryptHub's dual role as a cybercriminal and bug-bounty researcher, revealing ethical dilemmas in cybersecurity.

The DefendOps Diaries
The controversial case of the threat actor EncryptHub

Microsoft credited controversial actor EncryptHub, a lone actor with ties to cybercrime, for reporting two Windows flaws.

Security Affairs
EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational security.

GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Hey Cyber Security Pros! 👋

Ready to dive into the latest security updates and breaches that should be on your radar? We've got you covered.

🗞️ https://opalsec.io/daily-news-update-wednesday-march-26-2025-australia-melbourne/

At a high level, here are the main stories:

- EncryptHub's Zero-Day Exploits: Trend Micro links EncryptHub (a.k.a. Water Gamayun) to attacks leveraging a Microsoft Management Console (MMC) zero-day vulnerability (CVE-2025-26633). Discover how they're bypassing Windows protections and deploying various payloads.

- Windows NTLM Hash Leak Zero-Day: A new zero-day flaw allows remote attackers to steal NTLM credentials. Learn how this vulnerability affects all Windows versions and how 0Patch is providing unofficial fixes. Don't forget about those older, unpatched vulnerabilities too!

- HaveIBeenPwned Gets Phished: Even security experts aren't immune! Troy Hunt shares his experience of a sophisticated Mailchimp phishing attack. Lessons learned on OTP security and the importance of monitoring password manager behavior.

- Oracle Breach Controversy: Customers are confirming the legitimacy of leaked data despite Oracle Cloud's denial. Could this lead to supply chain and ransomware attacks? Ensure you're rotating those SSO and LDAP credentials and enforcing strong MFA!

- Astral Foods Cyberattack: South Africa's largest chicken producer faced a $1 million loss due to a recent cyberattack.

- Android Malware Evolution: New Android malware is using .NET MAUI to evade detection. Learn how it's disguising itself and targeting users in China and India.

- CS2 Phishing Attacks: Browser-in-the-Browser attacks are targeting Counter-Strike 2 players' Steam accounts.

- VMware Tools Vulnerability: Broadcom warns of an authentication bypass vulnerability in VMware Tools for Windows. Update those systems ASAP!

- CrushFTP Unauthenticated Access Flaw: CrushFTP warns users to patch an unauthenticated HTTP(S) port access vulnerability.

- Kubernetes IngressNightmare: Wiz researchers uncovered critical vulnerabilities in Ingress-Nginx Controller that could lead to complete cluster takeovers.

- Trump Officials' Signal SNAFU: High-profile officials accidentally shared classified Yemen airstrike plans in a Signal group with a journalist.

- FCC Investigates Huawei: The FCC is scrutinizing Chinese manufacturers for circumventing US regulations.

- Privacy-Boosting Tech: A new report suggests governments should prioritize privacy-enhancing technologies to prevent breaches.

Check out the full blog post 👉 https://opalsec.io/daily-news-update-wednesday-march-26-2025-australia-melbourne/

#cybersecurity #infosec #securitybreach #zeroday #phishing #malware #cloudsecurity #vulnerabilitymanagement #kubernetes #dataprotection #privacy #threatintel #ransomware #NTLM #EncryptHub #Windows #Android #VMware #CrushFTP #Kubernetes #HaveIBeenPwned #Oracle #Signal #CounterStrike #cyberattack #cybercrime

Daily News Update: Wednesday, March 26, 2025 (Australia/Melbourne)

Audio Summary: Wednesday, March 26, 2025 (Australia/Melbourne)0:00/305.0161× EncryptHub Linked to MMC Zero-Day Attacks on Windows Systems Trend Micro have linked the threat actor EncryptHub to attacks exploiting a zero-day vulnerability in Microsoft Management Console (MMC) vulnerability dubbed 'MSC EvilTwin' (CVE-2025-26633), as far back as April

Opalsec
Understanding the CVE-2025-26633 Vulnerability in Microsoft Management Console

Explore the CVE-2025-26633 vulnerability in Microsoft Management Console and its exploitation by threat actors like EncryptHub.

The DefendOps Diaries

Researchers have uncovered #EncryptHub cybercrime gang's multi-stage malware campaign, exposing its infrastructure and tactics due to critical OPSEC failures.

Read: https://hackread.com/encrypthub-opsec-failures-expose-malware-operation/

#CyberSecurity #CyberCrime #Malware

EncryptHub’s OPSEC Failures Expose Its Malware Operation

Follow us on Bluesky, Twitter (X) and Facebook at @Hackread

Hackread - Latest Cybersecurity, Tech, AI, Crypto & Hacking News
Unveiling EncryptHub: Analysis of a multi-stage malware campaign
#EncryptHub
https://outpost24.com/blog/unveiling-encrypthub-multi-stage-malware/
Unveiling EncryptHub: Analysis of a multi-stage malware campaign 

Learn what our threat intelligence researchers have uncovered about a new threat actor using multi-stage malware: EncryptHub.

Outpost24