Simply Cyber Newsletter #190

Crush Your Week Like a Cyber Pro with Simply Cyber!

Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.

FOR END USERS

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT. Researchers have identified Operation DragonReturn, a phishing campaign targeting Indian taxpayers, tax professionals, and finance teams during tax filing season. The attackers impersonate the country’s tax authority to deliver malware through fake tax filing utilities, ultimately installing remote access trojans designed to steal sensitive information and maintain long-term access to compromised systems.

What you need to know: Attackers don’t always invent believable stories. Often, they wait for moments when people already expect important messages. Operation DragonReturn coincided with India’s tax filing season, using realistic tax violation notices, legal references, and urgent deadlines to convince recipients to download what appeared to be a legitimate filing utility. The malware wasn’t the attacker’s advantage. The timing was.

The lesson extends well beyond tax season. Payroll updates, benefits enrollment, compliance deadlines, invoices, and HR notifications all create similar moments where people feel pressure to act quickly. Remind employees that urgency is often part of the attack. When an unexpected message claims immediate action is required, especially if it involves downloading software or opening attachments, pause and verify the request through an independently trusted source before taking action.

FOR PEERS

New Helix vishing group emerges in SharePoint data theft attacks. A new data-extortion group called Helix is using vishing, device-code phishing, and MFA abuse to compromise Microsoft 365 accounts. After gaining access, operators register a new authenticator, enumerate SharePoint, and exfiltrate files for extortion or resale.

What you need to know: Helix is a reminder that identity attacks increasingly rely on legitimate authentication workflows instead of exploiting software vulnerabilities. The campaign begins with voice phishing, but the compromise succeeds because the victim is convinced to complete a real Microsoft device-code authentication flow. From there, the attackers register a new authenticator to maintain access and steal data from SharePoint. The lesson isn’t that Microsoft authentication is broken. It’s that legitimate identity features become attack paths when they aren’t governed as tightly as passwords or MFA.

This is a good opportunity to revisit the identity controls that often receive less attention than traditional sign-ins. Determine whether device-code authentication is required in your environment, verify that Conditional Access policies apply to that flow, and review how new authenticator registrations are monitored. ReliaQuest also observed consistent SharePoint enumeration and bulk download activity, giving defenders practical hunting opportunities if an account is compromised. Identity attacks don’t always begin with malware. Sometimes they begin with legitimate authentication followed by legitimate access.

FOR EXECUTIVES

France to stop certifying products without quantum-safe encryption. France’s cybersecurity agency, ANSSI, announced it will stop certifying security products that lack quantum-resistant encryption beginning in 2027 and expects organizations to purchase only quantum-safe products by 2030. Because ANSSI certification is required for French government agencies and critical infrastructure, the policy effectively begins phasing out older encryption technologies.

What you need to know: This is less about quantum computing than it is about procurement. France has attached dates to what has largely been a long-term security discussion, signaling that organizations selling to government or critical infrastructure will soon need to demonstrate quantum-safe capabilities as part of product selection and certification. Whether quantum computers arrive sooner or later, purchasing decisions are beginning to account for systems that may remain in service for the next decade.

If your organization has long technology refresh cycles, government customers, or critical infrastructure partners, this is the type of development worth raising with senior leadership before it becomes a procurement requirement. It provides early visibility into where regulatory and customer expectations may be heading, giving leaders more time to factor future cryptographic requirements into technology roadmaps, vendor evaluations, and capital planning rather than reacting when similar expectations become mandatory.

Stop typing what you could say in 10 seconds.

Wispr Flow turns your voice into clean, professional text inside any app. Emails, Slack, client updates — speak once, send without editing. 4x faster than typing.

JOIN US EVERY WEEKDAY DAILY CYBER THREAT BRIEF

Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io

Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.

SC WOMEN IN CYBER - MONTHLY MEETING

Get ready for the monthly SC Women in Cyber Discord meeting! It’s happening this Wednesday, July 15th at 1 PM EDT.

Learn more and connect with other #womenincyber on Simply Cyber’s Discord: https://discord.com/events/829733892981522453/1488267599857844246

SIMPLY CYBER FIRESIDES

As AI is incorporated into more products, platforms, and business processes, organizations are asking a new question: how do you test the security of an AI system before someone else does?

In this episode of Simply Cyber Firesides, host Gerald Auger, Ph.D. welcomes John V. for a conversation on the growing field of AI red teaming and the role it plays in evaluating the resilience of modern AI systems.

John's work focuses on offensive AI security, adversarial testing, and AI risk assessment. He has led AI red team operations, advised on AI security and strategic policy initiatives, contributed to industry standards, and worked alongside researchers developing practical approaches for evaluating emerging AI technologies.

Learn what AI red teaming is, why organizations are investing in it, and how it differs from traditional penetration testing and adversary emulation. As AI continues to reshape cybersecurity, understanding how these systems are evaluated has become increasingly important for practitioners across the industry.

As always, the Firesides livestream includes audience Q&A, giving you the opportunity to engage directly with John and Gerald throughout the discussion.

Register now and join us Thursday at 4:30 PM EDT: https://luma.com/5u3mh6zd 

Register now and get notified: https://luma.com/5u3mh6zd

SC MEDIA GROUP WEEKLY EVENTS SCHEDULE

Learning and networking happening every day of the work week on Simply Cyber:

SIMPLY CYBER MONTHLY EVENTS LINEUP

Want to know what’s happening at Simply Cyber at any given time?

Head over to the SC Monthly Events Calendar to register for new and upcoming events for the month - don’t forget to subscribe! lu.ma/simplycyber 

SC ACADEMY THE PLACE FOR CYBER CAREERS

At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.

The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.

Check out the NEW FREE courses available in the academy!

SIMPLY CYBER ACADEMY BLOG HIGHLIGHT

Check out the highlighted blog on Simply Cyber Academy:  

LET’S CONNECT

Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.

As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.

Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Thank you and see you again next week, #TeamSC!

Gerry