Indicator of Compromise

23 Followers
53 Following
436 Posts
CISA Shares New Threat Detections for Actively Exploited WSUS Vulnerability

In a critical update issued on October 29, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) has provided organizations with enhanced guidance on detecting and mitigating threat activity related to the actively exploited CVE-2025-59287 vulnerability in Microsoft's Windows Server Update Services (WSUS).

Cyber Security News
[RADIANT] - Ransomware Victim: Spijkermat - RedPacket Security

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating

RedPacket Security
Tata Motors Data Leak – 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys https://cybersecuritynews.com/tata-motors-data-leak/ #CyberSecurityNews #cybersecuritynews #CyberSecurity #dataleak
Tata Motors Data Leak - 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys

Critical vulnerabilities in Tata Motors' systems that exposed over 70 terabytes of sensitive data, including customer personal information, financial reports, and fleet management details.

Cyber Security News
Ransomware Attacks Demystified A Practical Guide for 2025 - RedPacket Security

Ransomware attacks have evolved into sophisticated, real-time extortion operations that target organisations of all sizes. In this weekly security series, we

RedPacket Security
New Phishing Attack Using Invisible Characters Hidden in Subject Line Using MIME Encoding https://cybersecuritynews.com/new-phishing-attack-using-invisible-characters/ #CyberSecurityNews #cybersecuritynews #cybersecurity #Threats
New Phishing Attack Using Invisible Characters Hidden in Subject Line Using MIME Encoding

Cybercriminals have developed a sophisticated phishing technique that exploits invisible characters embedded within email subject lines to evade automated security filters. This attack method leverages MIME encoding combined with Unicode soft hyphens to disguise malicious intent while appearing legitimate to human readers. The technique represents an evolution in social engineering tactics, targeting email filtering mechanisms […]

Cyber Security News

New, by me: Aisuru Botnet Shifts from DDoS to Residential Proxies

Aisuru, the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and sustainable business: Renting hundreds of thousands of infected Internet of Things (IoT) devices to proxy services that help cybercriminals anonymize their traffic. Experts say a glut of proxies from Aisuru and other sources is fueling large-scale data harvesting efforts tied to various artificial intelligence (AI) projects, helping content scrapers evade detection by routing their traffic through residential connections that appear to be regular Internet users.

I included a section at the end mentioning that the latest Aisuru botnet code apparently tells infected systems to check in at the host fuckbriankrebs[.]com. When I heard this, I wondered what its use might be other than to just say what the domain says. But we also noticed the domain was unregistered....

Happily, the domain name was deftly snatched up last week by Philippe Caturegli, “chief hacking officer” for the security intelligence company Seralys.

Caturegli enabled a passive DNS server on that domain and within a few hours received more than 700,000 requests for unique subdomains on fuckbriankrebs[.]com.

But even with that visibility into Aisuru, it is difficult to use this domain check-in feature to measure its true size, Brundage said. After all, he said, the systems that are phoning home to the domain are only a small portion of the overall botnet.

“The bots are hardcoded to just spam lookups on the subdomains,” he said. “So anytime an infection occurs or it runs in the background, it will do one of those DNS queries.”

Read more:
https://krebsonsecurity.com/2025/10/aisuru-botnet-shifts-from-ddos-to-residential-proxies/

Windows 11 KB5067036 update rolls out Administrator Protection feature - ​​Microsoft has released the KB5067036 preview cumulative update for Windows 11 24H2 and ... https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5067036-update-rolls-out-administrator-protection-feature/ #microsoft #security
Windows 11 KB5067036 update rolls out Administrator Protection feature

​​Microsoft has released the KB5067036 preview cumulative update for Windows 11 24H2 and 25H2, which begins the rollout of the Administrator Protection cybersecurity feature and an updated Start Menu.

BleepingComputer
Advertising giant Dentsu reports data breach at subsidiary Merkle - Japanese advertising giant Dentsu has disclosed that its U.S.-based subsidiary Merkle suf... https://www.bleepingcomputer.com/news/security/advertising-giant-dentsu-reports-data-breach-at-subsidiary-merkle/ #security
Advertising giant Dentsu reports data breach at subsidiary Merkle

Japanese advertising giant Dentsu has disclosed that its U.S.-based subsidiary Merkle suffered a cybersecurity incident  that exposed staff and client data.

BleepingComputer

Red Hat has revealed they were victim of a data breach

Timeline: The attack happened approximately 2 weeks ago

Impact: 570 GB of data was stolen from one of Red Hat Consulting division's GitLab instances, including some sensitive customer internal infrastructure info from big companies

Attacker: The Crimson Collective extortion group has claimed responsibility

Remediation:
- Breach notifications to be sent to affected customers

#cybersecurity #databreach #RedHat

https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-breach-gitlab-instance/

Red Hat confirms security incident after hackers breach GitLab instance

An extortion group calling itself the Crimson Collective claims to have stolen nearly 570GB of compressed data across 28,000 internal development respositories, with the company confirming it was a breach of one of its GitLab instances.

BleepingComputer
Tesla Cybertruck’s faulty door handles caused woman’s death, lawsuit alleges

Tesla is facing a wrongful death lawsuit over claims that its “defective” door handle design trapped 19-year-old Krysta Tsukahara inside a burning Cybertruck.

The Verge