📰 LemonDuck Cryptomining Malware Spreads via PowerShell in New Campaign

🍋 LemonDuck cryptomining malware is back, using PowerShell to hijack endpoints and build a botnet. Barracuda also reports a 55% spike in password spraying from Iran targeting Fortigate VPNs. VPNs. 🛡️ #Malware #CryptoMining #CyberSecurity #PowerShell

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/lemonduck-malware-hijacks-endpoints-for-cryptomining-in-new-campaign/?utm_source=m…

PowerShell Weekly for June 26, 2026 is out now with Announcements, Community highlights, Fun sections, and more. Check it out!
#PowerShell #Automation #TechNews
https://psweekly.dowst.dev/?p=9025
DOWST.DEV | June 26, 2026

PowerShell Weekly for June 26, 2026

https://programming.dev/post/52590673

PowerShell Weekly for June 26, 2026 - programming.dev

## Blogs, Articles, and Posts - Taming AI Tool Sprawl: A PowerShell Guide to Auditing and Governing Unauthorized AI Applications [https://adamtheautomator.com/taming-ai-tool-sprawl-powershell-guide-auditing/] This guide teaches you how to use PowerShell to detect, audit, and govern unauthorized AI applications using Microsoft Graph, Entra ID, and Defender for Cloud Apps. - Using Graph Delta Queries with Entra ID Groups [https://office365itpros.com/2026/06/25/graph-delta-queries-entra-id-groups/] Delta queries can be used to track changes in Microsoft 365 groups, but they are not suitable for long-term reporting. Instead, delta links can be used to check for modifications from a specific point forward. The article explains how to create a delta link and use it to track changes to specific groups. - How to Reset Windows Security App in Windows 11 [https://techviral.net/reset-windows-security-windows-11/] This article provides three methods to reset the Windows Security app on Windows 11: using PowerShell, Settings, or Command Prompt. - How to Use PowerShell to Identify Inactive Teams Channels [https://office365itpros.com/2026/06/24/find-inactive-channels/] This article explains how to use PowerShell and the Microsoft Graph SDK to identify inactive Teams channels in a Microsoft 365 tenant. It provides a script that generates a report file containing details of channels and their last message, along with information on team owners. - Selectable Export PowerShell Engine arrives for the Granfeldt PowerShell Management Agent [https://blog.darrenjrobinson.com/selectable-export-powershell-engine-arrives-for-the-granfeldt-powershell-management-agent/] The Granfeldt PowerShell Management Agent now supports a selectable export engine, allowing connectors to choose between different PowerShell engines for improved flexibility and compatibility. - How to Find if a Hard Drive is HDD or SSD on Windows [https://techviral.net/find-if-a-hard-drive-is-hdd-or-ssd/] This article provides three methods to determine whether a hard drive in a Windows PC is a Hard Disk Drive (HDD) or Solid State Drive (SSD): using File Explorer, PowerShell, and freeware apps. - Managing Microsoft Defender Antivirus through PowerShell cmdlets [https://4sysops.com/archives/managing-microsoft-defender-antivirus-through-powershell-cmdlets/] Microsoft offers robust PowerShell cmdlets to manage security features on Windows devices, allowing for automated security tasks and consistent protection. - PowerShell Terminal tips and tricks [https://powershellisfun.com/2026/06/19/powershell-terminal-tips-and-tricks/] Harm Veenstra shares useful PowerShell terminal tips and tricks for automating tasks and improving productivity. ## Projects, Scripts, and Modules - PowerShell updated from 7.4 to 7.6 LTS on all runner images [https://github.com/actions/runner-images/issues/14150] All Github runners should now have PowerShell 7.6! ## Books, Media, and Learning Resources - The Microsoft DSC Handbook [https://leanpub.com/themicrosoftdschandbook] Microsoft Desired State Configuration (DSC) is the next step of Desired State Configuration, bringing in even more cross-platform support so you can define and enforce system state across Windows, Linux, and macOS. ## Community - Certificates Are Not Optional with Leo D’Arcy [https://powershellpodcast.podbean.com/e/certificates-are-not-optional-with-leo-darcy/] Leo D’Arcy discusses the importance of certificates in IT, the difference between self-signed and proper CA infrastructure, and the value of integrating signing into a CI/CD pipeline. - Don’t ask Microsoft to do it all [https://www.linkedin.com/posts/sassdawe_powershell-polyglot-polyglossy-share-7474581509765632000-_TCF/?rcm=ACoAAAuj21EBN-5GJdIHeR6r3oqvZ3UNgi5Eslc] Hayden Barnes makes a really good point here. ## Fun - Making Memes [https://pckt.blog/b/posh/making-memes-47vra1t] It’s Friday. Let’s have some Fun! Let’s write fun servers in PowerShell. About a week ago, I released Fun. It’s a fun functional server in PowerShell. ## Events - PowerShell Pro Series [https://www.recastsoftware.com/resources/powershell-pro-series/] This two-part series led by Microsoft MVPs is designed to help IT admins strengthen their PowerShell scripting skills, from core fundamentals to more advanced techniques. Part 2 takes place on June 30th. Check out psweekly.dowst.dev [https://psweekly.dowst.dev/] for all past editions as well as a searchable archive.

Dew Drop Weekly Newsletter #489 - Week Ending June 26, 2026

Dew Drop Weekly Newsletter #489 - Week Ending June 26, 2026

Zoho Campaigns

Authentication Laundering e TonRAT: come il malware Node.js prende di mira il settore hospitality

Microsoft Threat Intelligence ha scoperto TonRAT, un implant Node.js che colpisce l'industria dell'ospitalità usando una tecnica di evasione inedita: l'authentication laundering via servizi legittimi come Calendly e Google redirect.

https://spcnet.it/authentication-laundering-e-tonrat-come-il-malware-node-js-prende-di-mira-il-settore-hospitality/

Gestire Microsoft Defender Antivirus con PowerShell: cmdlet pratici per sysadmin

Una guida completa ai cmdlet PowerShell di Microsoft Defender Antivirus: verifica dello stato, configurazione delle preferenze, gestione esclusioni, avvio scansioni, aggiornamento firme e automazione degli audit di sicurezza.

https://spcnet.it/gestire-microsoft-defender-antivirus-con-powershell-cmdlet-pratici-per-sysadmin/

Do you really understand how #PowerShell handles subprocesses?

At #PSConfEU, @[email protected] explains:
✅ Process invocation methods
✅ Why NOT to use Invoke-Expression
✅ Streams, encoding & exit codes

Better control = better #automation.

👉 youtu.be/vrJWLNELoGI?si=SAh...

#IT #DevOps

- YouTube
Spawn of a Shell - Handling Sub Processes - Jordan Borean - PSConfEU 2026

YouTube
Saving #PowerShell Notebooks - David Sass - #PSConfEU 2026 with @sassdawe https://youtu.be/1r4NWZbL3BY
Saving PowerShell Notebooks - David Sass - PSConfEU 2026

YouTube

Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access

Since April 2026, a sophisticated multi-stage intrusion campaign has targeted hospitality and hotel organizations across Europe and Asia. The operation uses photo-themed ZIP archives containing malicious shortcut files disguised as images. When executed, these shortcuts initiate an attack chain involving obfuscated PowerShell, Node.js-based implants, and dual registry persistence mechanisms. The threat actor exploits legitimate services like Calendly and Google redirects for phishing delivery, employing authentication laundering to bypass email security controls. The campaign evolved through two waves, introducing .NET DLL compilation, Cloudflare-fronted infrastructure, and refined obfuscation techniques. Post-compromise activities include command-and-control beaconing over non-standard ports, forced shutdowns, and portable executable compilation, suggesting preparation for additional malicious operations.

Pulse ID: 6a3df8979895cc716bfbf931
Pulse Link: https://otx.alienvault.com/pulse/6a3df8979895cc716bfbf931
Pulse Author: AlienVault
Created: 2026-06-26 03:57:11

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Asia #Cloud #CyberSecurity #Email #Europe #Google #Hospital #InfoSec #NET #Nodejs #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RCE #SMS #ZIP #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange