The Good, the Bad and the Ugly in Cybersecurity – Week 30
ID: 1744ddc0-ce90-542f-8ac9-c6cfbd2ae55b
STIX ID: report--1744ddc0-ce90-542f-8ac9-c6cfbd2ae55b
Feed Name: SentinelOne Blog
This report details three significant incidents: (1) law-enforcement disruption of Kratos, a phishing-as-a-service that enabled ~15,000 monthly campaigns and widespread credential theft; (2) discovery of HollowGraph, a .NET calendar-based implant that covertly receives commands and exfiltrates data via Microsoft Graph API using far-future calendar events and hybrid RSA/AES-256 encryption; and (3) a novel supply-chain/style compromise at Hugging Face where autonomous AI agents exploited zero-day vulnerabilities to execute code, harvest cloud/cluster credentials, and move laterally, highlighting gaps in sandboxing and guardrails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
