Simply Cyber Newsletter #184

Crush Your Week Like a Cyber Pro with Simply Cyber!

Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.

FOR END USERS

Chinese Threat Actors Ditch Static Phishing Pages for Live Credential Interception. Real-time phishing attacks are moving beyond simple password theft. In these scams, attackers can capture usernames, passwords, and one-time passcodes as victims enter them, allowing them to bypass MFA and take over accounts. This matters at work and at home because trusted-looking login pages are getting harder to spot.

What you need to know: The old model was static. Attackers stood up a fake login page, harvested whatever credentials victims typed, and came back later to use them. Multi Factor authentication broke that model, because a stolen password alone was no longer enough. The new model is live. Attackers now run an administration panel beside the phishing page, so the moment a victim enters credentials, the data surfaces on the attacker's screen in real time. They trigger the OTP prompt on their own device, capture the code in the seconds before it expires, and walk straight through MFA. From there they can load the victim's card into a digital wallet and spend it in person. The lures are also arriving over iMessage and RCS now, not plain SMS, so they look legitimate.


Educate your end users on this shift with the following guidance: Be cautious with unexpected messages asking you to log in, verify an account, fix a payment, or confirm a delivery. Do not click the link. Open the official app or type the address yourself. If something feels off, slow down and report it before entering your credentials. Entering your one-time passcode on a page someone sent you is now just as risky as handing over your password.

FOR PEERS

CrowdStrike, Google shatter Glassworm botnet. A coordinated effort by CrowdStrike, Google, and the Shadowserver Foundation disrupted the Glassworm botnet, a self-propagating malware campaign that targeted developers through poisoned software packages, compromised repositories, and malicious extensions. The campaign highlights how threat actors are increasingly targeting software development ecosystems to steal credentials, spread malware, and gain access to downstream organizations.

What you need to know: Share this story and start a conversation about what your organization is doing to secure the software supply chain, monitor third-party dependencies, and protect developer environments. Glassworm shows that threat actors are going after the people who build and maintain software, not just end users and infrastructure. Developers are users too, and they are often the least trained, so make sure they receive the same security awareness as the rest of the workforce.

On the technical side, review how your organization validates new packages, extensions, and repositories before adoption, and talk through credential protection, secret management, dependency monitoring, and anomaly detection in development environments. One concrete step you can take today: infected machines now beacon to a benign CrowdStrike-operated address, and the company is urging organizations to check network logs and endpoint telemetry for connections to 164.92.88.210, which indicates a Glassworm infection.

FOR EXECUTIVES

AI-Assisted Exploit Development Outpaces Scanner Detection. Researchers found that attackers are using AI to dramatically reduce the time required to develop working exploits for newly disclosed vulnerabilities. In some cases, exploit development has dropped from months to hours, creating a growing gap between when vulnerabilities are disclosed and when organizations can identify and respond to them.

What you need to know: Share this story with your leadership team and have a conversation about whether your organization can quickly identify where newly disclosed vulnerabilities exist across your environment. As AI accelerates exploit development, the assumption that you have weeks or months to assess risk and respond is no longer realistic, and researchers expect today's speeds to compress further over the next year, not level off.

Leaders should also understand where the real gap is. The research found that it is not mainly that organizations scan too slowly, it is that the major scanning vendors often ship detection late or not at all, with most critical vulnerabilities never receiving coverage. Buying a faster scanner does not solve this. What does is the ability to answer ""are we running affected software?"" within minutes of a disclosure, using your own asset inventory rather than waiting on a vendor signature. Review how your organization prioritizes new vulnerabilities, measures exposure, and validates remediation. The organizations best positioned will be the ones that can identify affected assets and make informed risk decisions on their own timeline, independent of when their scanner catches up.

Your ads ran overnight. Nobody was watching. Except Viktor.

One brand built 30+ landing pages through Viktor without a single developer.

Each page mapped to a specific ad group. All deployed within hours. Viktor wrote the code and shipped every one from a Slack message.

That same team has Viktor monitoring ad accounts across the portfolio and posting performance briefs before the day starts. One colleague. Always on. Across every account.

JOIN US EVERY WEEKDAY DAILY CYBER THREAT BRIEF

Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io

Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.

NEW VIDEO: GRC ENGINEERING

GRC Analysts Will Get Left Behind Without This Skill

GRC engineering keeps coming up in job postings and conversations, but nobody tells you where to actually start.

In this video I walk through the GRC Playground, a free, browser-based, mission-based platform that lets you get hands-on with policy as code, Open Policy Agent (OPA), and Rego. No account, no credit card, no developer background needed. If you're a GRC analyst who wants to stay relevant as the discipline gets more technical, this is a great first step.

Shoutout to Ashley Pearce for building and sharing this with the community. 🙌

Watch now on Simply Cyber Media Group: https://youtu.be/Bnf_6BKlnFU 

2 CYBER CHICKS: AI WON’T SAVE CYBERSECURITY

AI Won’t Save Cybersecurity

In this episode of 2 Cyber Chicks, Jax sits down with Kathleen Moriarty, technology strategist, former CTO and CISO, Georgetown University adjunct professor, and one of the few people who has helped shape how internet security actually works.

This is not a hype episode.

Kathleen challenges the dominant narrative that AI will “fix” cybersecurity and explains why that belief may be creating more risk than it removes—especially for organizations with limited resources. Drawing on decades of experience influencing global standards, teaching cyber threat intelligence, and advising boards, she breaks down where automation helps, where it hurts, and where we’ve completely lost the plot.

If you’re tired of buzzwords, vendor promises, and magical thinking around AI—this episode brings the clarity the industry desperately needs.

Watch this Wednesday at 9:30 AM EDT on Simply Cyber Media Group:  https://youtu.be/luUAMoS6rF8 

Register to attend and get reminders! https://luma.com/imcpho58 

NEXT WEEK: SC SKILLS STREAM WITH ALETHE DENIS

Pretexts That Hold Up Under Pressure

What happens when your pretext falls apart the moment someone challenges your story?

In this Simply Cyber Skills Stream, Alethe Denis, Senior Security Consultant II at Bishop Fox and DEF CON Black Badge-winning social engineer, shares how to build pretexts that can withstand real-world pressure during physical red team engagements.

Most social engineering discussions focus on what to say. This session focuses on how to create believable stories that hold up when faced with skeptical employees, unexpected questions, or situations that do not go according to plan.

Drawing from her experience in social engineering, physical security assessments, and offensive security operations, Alethe will discuss the mindset and preparation behind creating stronger, more resilient pretexts for real-world engagements.

This Skills Stream is designed for red teamers, social engineers, OSINT practitioners, physical security professionals, and anyone interested in the human side of offensive security.

Join us next Tuesday at 1:00 PM EDT: https://youtube.com/live/mG-jRlyiW8k 

Register to attend and get an email reminder: https://luma.com/2q0zvwc1 

SC MEDIA GROUP WEEKLY EVENTS SCHEDULE

Join us for learning and networking every day of the work week on YouTube: youtube.com/@simplycyber 

Connect with the SC Discord community: simplycyber.io/discord

SIMPLY CYBER MONTHLY EVENTS LINEUP

Want to know what’s happening at Simply Cyber at any given time?

Head over to the SC Monthly Events Calendar to register for new and upcoming events for the month - don’t forget to subscribe! lu.ma/simplycyber 

SC ACADEMY THE PLACE FOR CYBER CAREERS

At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.

The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.

Check out the NEW FREE courses available in the academy!

SIMPLY CYBER ACADEMY BLOG HIGHLIGHT

Check out the highlighted blog on Simply Cyber Academy:  

LET’S CONNECT

Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.

As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.

Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Thank you and see you again next week, #TeamSC!

Gerry