Treasury Sanctions Iran’s Nobitex Exchange as Ransomware Gangs Bypass VPN MFA

The US Treasury sanctioned Nobitex, Iran’s largest crypto exchange, for facilitating ransomware-linked and terrorism-related payments, while separate research shows ransomware affiliates bypassing MFA on SonicWall VPN appliances. Here’s this week’s ransomware roundup covering both the cash-out and entry-point sides of the attack pipeline.

Read more

ShinyHunters-Linked Attackers Walked Into Salesforce Through Trust, Not Vulnerabilities

Microsoft mapped how ShinyHunters-linked attackers spent a year walking into corporate Salesforce environments through abused OAuth trust connections rather than any platform vulnerability. Combined with a ransomware attack on the Orleans Parish Sheriff’s Office and INC ransomware’s rise to 830 claimed victims, here’s this week’s ransomware landscape.

Read more

Microsoft’s Record 622-CVE Patch Tuesday Targets Two Critical Identity Flaws

Microsoft’s record 622-CVE Patch Tuesday includes two actively exploited zero-days in SharePoint Server and Active Directory Federation Services, identity infrastructure flaws that matter more than their severity scores suggest. Combined with EU-UK sanctions over a Russian hack of the Polish grid and an Oracle investor lawsuit over OpenAI cloud sales, here’s this week’s cybersecurity landscape.

Read more