Blog

Storm-0501 Campaign Exploits Microsoft Entra ID: Why Identity Has Become the New Cybersecurity Battlefield

Storm-0501 Campaign Exploits Microsoft Entra ID: Why Identity Has Become the New Cybersecurity Battlefield

In today’s hyper-connected world, identity is no longer just an administrative concern—it is the new perimeter of cybersecurity. The recent discovery of Storm-0501, a sophisticated phishing campaign targeting Microsoft Entra ID (formerly Azure Active Directory), has highlighted just how vulnerable organizations can be when attackers bypass traditional defenses and focus directly on identity systems.

New Pre-Auth Exploit Chains Discovered in Popular Platforms – Is Your Organization at Risk?

New Pre-Auth Exploit Chains Discovered in Popular Platforms – Is Your Organization at Risk?

In the ever-evolving world of cybersecurity, every year introduces new attack methods, more sophisticated adversaries, and more critical vulnerabilities. But among the most concerning trends emerging today are pre-authentication exploit chains—a class of attacks that can allow cybercriminals to completely bypass login mechanisms and gain unauthorized access to critical systems.

New UNC6384 Campaign Deploys PlugX via Captive Portal Attacks – Is Your Network Secure?

New UNC6384 Campaign Deploys PlugX via Captive Portal Attacks – Is Your Network Secure?

When you connect to a public Wi-Fi network, what’s the first thing you see?
Usually, a captive portal that login or “Agree to Terms & Conditions” page you click before getting access. For most people, it’s a routine step. But what if that portal wasn’t a harmless gateway, but instead a weaponized tool used by cybercriminals to infect your device?
That’s exactly what’s happening in a sophisticated cyber campaign launched by UNC6384, a threat actor now under global watch. By exploiting captive portals, UNC6384 is distributing the notorious PlugX malware, a remote access trojan capable of data theft, persistence, and further compromise.

DOM-Based Extension Clickjacking: The Silent Threat in Your Browser

DOM-Based Extension Clickjacking: The Silent Threat in Your Browser

Did you know that over 4.95 billion people worldwide—about 62.3% of the global population—actively use internet browsers every day? Browsers have become the entry point to nearly every digital interaction we perform—whether it’s accessing work tools, online banking, or managing personal accounts. Yet, despite their importance, a large percentage of users remain unaware of the silent threats lurking within browser extensions.

Malicious Go Module Discovered Posing as SSH Brute-Forcer – Why Supply Chain Attacks Demand Urgent Attention

Malicious Go Module Discovered Posing as SSH Brute-Forcer – Why Supply Chain Attacks Demand Urgent Attention

In today’s fast-moving digital world, software supply chains have become both a cornerstone of innovation and a prime target for attackers. A recent discovery reported by The Hacker News highlights a particularly troubling case: a malicious Go module named “golang.org/x/ssh” was found imitating the legitimate SSH library to deliver backdoor access.

New Apache ActiveMQ Exploit Unleashes Godzilla Malware – What Security Leaders Need to Know

New Apache ActiveMQ Exploit Unleashes Godzilla Malware – What Security Leaders Need to Know

In cybersecurity, time is the ultimate weapon. Threat actors have mastered the art of exploiting vulnerabilities faster than organizations can patch them, turning every unpatched system into a potential breach point. The latest high-profile example is the critical flaw in Apache ActiveMQ (CVE-2023-46604), which has been weaponized to deliver the notorious Godzilla malware.
This vulnerability carries a CVSS score of 10.0, the highest possible rating, meaning it allows unauthenticated remote code execution (RCE). In practical terms, an attacker can gain complete control of a vulnerable server without needing valid credentials.

Information

digiALERT is a rapidly growing new-age premium cyber security services firm. We are also the trusted cyber security partner for more than 500+ enterprises across the globe. We are headquartered in India, with offices in Santa Clara, Sacremento , Colombo , Kathmandu, etc. We firmly believe as a company, you focus on your core area, while we focus on our core area which is to take care of your cyber security needs.