Cyble Chronicles: Jan 18 Cybersecurity Findings & Tips
ID: 92ce402e-fa37-50d3-bc70-b1bf9a0dbf36
STIX ID: report--92ce402e-fa37-50d3-bc70-b1bf9a0dbf36
Feed Name: Cyble Blog
This bulletin reports multiple concurrent threats: a memory-resident Azorult info-stealer campaign distributed via obfuscated shortcuts and PowerShell loaders; a Go-based stealer variant targeting the Indian Air Force via lnk/ISO delivery and exfiltrating credentials (using Slack); a critical GitLab vulnerability (CVE-2023-7028) that can redirect password resets and enable account takeover; and claims by the 'dawnofdevil' actor of massive breaches and sale of PII affecting millions—collectively indicating active, high-impact malicious activity against both civilian and defense targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
