Skip to main content

Tag: cloudsek

5 articles

Software development workspace with laptop, notes, and package documentation on a cluttered surface.

Attackers Exploit npm Trusted Publishing in GHAPPIER Supply Chain Campaign

Malicious actors have cleverly exploited npm's trusted publishing feature to unleash a supply-chain attack, using a hijacked maintainer account to distribute a sneaky loader called GHAPPIER. They got away with it by hiding behind a valid provenance attestation, highlighting a loophole in the system.

Analyst 207
Business office setting with computers and papers, one screen showing a blurry login page.

Microsoft 365 Phishing Op Exposes Thousands of Credentials

A recent phishing operation exposed a staggering 5,137 records from 461 organizations, including 1,032 plaintext passwords and 474 fully authenticated Microsoft 365 sessions that could be easily exploited. This massive haul highlights the alarming vulnerability of sensitive credentials to clever phishing tactics.

Analyst 207
Server room with rows of computer servers and networking equipment.

Microsoft Credentials Targeted in BigBear 2 PhaaS Campaign

Security researchers just uncovered a massive phishing operation targeting Microsoft 365 credentials, with a staggering 5,137 compromised records and 3,331 unique victim IPs exposed. The researchers even gained admin access to the operation's control panel, revealing a vast network of 42 VPS nodes used to carry out the attacks.

Analyst 207
Office workers in background, foreground laptop screen blank and blurred.

Phishing Service BigBear Exposes 258 Firms to MFA Bypass

BigBear 2.0, a sneaky phishing-as-a-service operation, has compromised 258 companies by bypassing multi-factor authentication (MFA) for Microsoft 365 users worldwide, swiping 5,137 credential records in the process. This cunning attack used an adversary-in-the-middle approach to intercept passwords, MFA tokens, and session cookies, allowing hackers to hijack authenticated sessions with ease.

Analyst 207
Concerned individuals in a cloud computing setting review a laptop amidst rows of servers.

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft

Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

Analyst 207