Insights
Another AI Threat – Slopsquatting

Slopsquatting is another form of AI hallucinations. This time tied to code development that can infect the output of the AI system. The AI systems hallucinated over 20% of the repository dependencies. Very dangerous.

 

More AI hallucinations=more risks


Crypto Developers Targeted by Python Malware Disguised as Coding Challenges

Another attack on software developers uses job ads. When someone replies, they are sent an infected assignment. Opening it compromises and infects their systems!

 

Developers beware


ResolverRAT Campaign Targets Healthcare, Pharma via Phishing and DLL Side-Loading

A new RAT, Remote Access Trojan, has been found allowing attackers to penetrate and take control of systems. Phishing emails are how it arrives. Healthcare and pharmaceuticals are current targets.

 

New RAT discovered


MITRE Hackers’ Backdoor Has Targeted Windows for Years

The same technique that was used to compromise MITRE has been found to have been used against Windows systems for a few years. It is a complex sophisticated attack.   

 

Windows backdoor attack going on for years


Man Helped Chinese Nationals Get Jobs Involving Sensitive US Government Projects

Much was written about North Koreans being unknowingly hired by many US companies. Now Chinese nationals are getting into US companies through someone who lied and scammed the companies. Vetting new hires is getting more difficult but is more important than ever. 

 

Chinese nationals infiltrate American companies


Insider Threats – Growing More Dangerous

Insiders are always under attack through phishing, smishing, vishing and more. Why? Because attackers know insiders are users that already have access to the desired data. Learn more about this in this Insight.  

 

Insiders can be the worst threats


Threat Actors Use 'Spam Bombing' Technique to Hide Malicious Motives

Spam after spam after spam after spam after spam after spam, etc. That is a new technique attackers are using as a lead in to social engineering attacks. 

 

Spam to social enginnering attacks


Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day

Another big month for Microsoft patches. Be sure to determine which of your systems and applications are affected, the risk for each, then begin installing. Do not delay. 

 

Big month for Microsoft patches


Google Releases Android Update to Patch Two Actively Exploited Vulnerabilities

Actively exploited vulnerabilities are those that cyberattackers are using now to get into systems. Be sure to install the update sooner rather than later.  

 

Actively exploited vulns in Android


10 Bugs Found in Perplexity AI's Chatbot Android App

AI Chatbots come with many vulnerabilities and issues. Now the Android AI Perplexity chatbot was found to have 10 bugs. This makes it less secure than chatbots from ChatGPT and DeepSeek. 

 

Bugs in AI Chatbot