π¨ ALERT: @Mandiant's #AdvancedPractices team has recently received a video message from a State nexus actor. Sharing this for general visibility. Be safe out there.
cc:@ryankaz42 π¨
https://t.co/0B18D6hxiL
Spanberger just signed the βassault firearmβ ban bill into law. She also signed the hospital gun ban bill into law. So VCDLβs analysis that was released over the last couple days is correct as written.
π¨ UNC6692 is targeting enterprise environments with a sophisticated "SNOW" malware suite.
Posing as IT helpdesk staff, the actor uses high-pressure social engineering to deploy custom backdoors like SNOWBASIN and SNOWGLAZE.
Breakdown and IOCs: https://t.co/VClbcnnCDA
π¨ SECURITY ALERT π¨
The popular NPM package axios (>100M weekly downloads) was hit by a DPRK-nexus supply chain attack.
The attack deploys a cross-platform RAT (WAVESHAPER.V2).
Full IoCs & breakdown from @GoogleCloud:https://t.co/YspPRQYV4e #CyberSecurity#NPM#Axios
UNC6040 uses vishing to steal data from Salesforce environments and move laterally into Okta and M365.
Defend against their tactics with our guide that covers identity, SaaS application hardening, and detection.
Read now: https://t.co/w7hpLnsTqm