Today’s cybercriminals no longer need advanced skills to breach defenses. Armed with AI-powered tools and ready-to-deploy botnets, attackers target organizations of all sizes using fake identities and hijacked infrastructure to bypass security measures undetected.
## Threat of the Week: Critical SAP NetWeaver Vulnerability
A critical security flaw in SAP NetWeaver (CVE-2025-31324, CVSS score: 10.0) is being actively exploited by threat actors to upload JSP web shells, enabling unauthorized file uploads and code execution. Attackers are utilizing the Brute Ratel C4 post-exploitation framework and the Heaven’s Gate technique to bypass endpoint protections.
## Top News Highlights
### Darcula Phishing Kit Enhanced with AI
The Darcula phishing-as-a-service platform has been upgraded with generative AI capabilities, allowing criminals to easily create customized phishing forms in multiple languages. This user-friendly platform enables even novice scammers to generate convincing spoofed versions of legitimate brand sites.
### North Korean Fake Hiring Scheme
North Korean threat actors behind “Contagious Interview” have established front companies (BlockNovas LLC, Angeloper Agency, SoftGlide LLC) to distribute malware during fake hiring processes. These operations use AI-enhanced tools to create synthetic personas and manage multiple identities across communication channels.
### Russian Hackers Target Microsoft 365 Accounts
Russia-linked threat actors are aggressively targeting individuals and organizations with Ukraine ties to gain unauthorized access to Microsoft 365 accounts. These attacks rely on one-on-one interaction with targets and operate entirely on Microsoft’s official infrastructure.
### Google Infrastructure Exploited for Phishing
Threat actors have leveraged Google’s infrastructure to send fraudulent emails that redirect recipients to credential-harvesting sites. This sophisticated attack bypassed email authentication checks to steal Google Account credentials.
### Chinese Espionage Campaign in Southeast Asia
The China-linked Lotus Panda group has compromised multiple organizations in Southeast Asia using DLL side-loading techniques to deploy the Sagerunex backdoor and credential stealers targeting Google Chrome.
## Critical Vulnerabilities to Address
This week’s critical vulnerabilities include flaws in Craft CMS, SAP NetWeaver, Rack, Commvault Command Center, Lantronix Xport, WinZip, Microsoft Windows, Synology DiskStation Manager, FireEye EDR Agent, GitLab, SonicWall SonicOS, Langflow, Redis, NVIDIA NeMo Framework, Spring Framework, and ScreenConnect.
## Cybersecurity Developments
– **Lumma Stealer**: This information stealer is being widely distributed through pirated media and fake Telegram channels, using advanced evasion techniques like DLL side-loading and code flow obfuscation.
– **SessionShark**: A new adversary-in-the-middle phishing kit designed to bypass Microsoft 365 multi-factor authentication is being marketed on underground forums.
– **Elusive Comet Campaign**: Sophisticated social engineering tactics are being used to trick victims into installing malware for cryptocurrency theft, with attackers abusing Zoom’s remote control feature.
– **Power Parasites Campaign**: Targeting individuals in Bangladesh, Nepal, and India with job and investment scams through deceptive websites masquerading as energy firms.
– **Chrome Extensions Risk**: 58 suspicious Google Chrome extensions with risky features have been discovered, installed on approximately 5.98 million devices.
– **MITRE ATT&CK v17**: The latest version introduces new techniques targeting VMware ESXi and refines existing categories.
– **Magecart Campaigns**: New credit card skimming attacks are injecting malicious code into e-commerce sites to intercept payment data.
– **Cybercrime Costs**: FBI reports $16.6 billion in losses from cybercrime in 2024, a 33% increase from 2023, with investment scams, BEC, and tech support fraud causing the most damage.
## Security Tip: Protect Yourself During Video Calls
Attackers are using fake meeting invites to gain remote access during video calls. To stay safe:
– Disable remote control features when not needed
– Verify who’s requesting access
– Use browser-based tools like Google Meet when possible
– Block apps from getting special permissions
– Be suspicious of invites from unusual email addresses or links
Effective cybersecurity requires looking beyond technology to examine how your team handles trust, communication, and unusual behavior. Map potential blind spots where human judgment meets automation to strengthen your defenses.
