• Cyber threats are evolving faster than ever. Attackers now combine social engineering, AI-driven manipulation, and cloud exploitation to breach targets once considered secure. From communication platforms to connected devices, every system that enhances convenience also expands the attack surface. This edition of ThreatsDay Bulletin explores these converging risks and the safeguards that help

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Azure, one of the world’s leading cloud computing platforms, experienced a significant service outage on Thursday, October 9, 2025, leaving customers across Europe and Africa unable to access their services.

    The disruption began at approximately 07:40 UTC, with the core issue identified as a major capacity loss within Azure Front Door (AFD), Microsoft’s cloud-native Content Delivery Network (CDN).

    Users reported periodic connectivity problems, which extended to an inability to access the Azure Portal itself, preventing administrators from managing their own cloud infrastructure.

    The incident highlights the critical dependency of global businesses on cloud service availability and the cascading impact of a failure in a core component like a CDN.

    According to Microsoft’s service health status page, internal monitoring systems detected a “significant capacity loss, of about 30% of Azure Front Door instances.” This degradation was predominantly concentrated across environments in Europe and Africa.

    Specific regions confirmed to be impacted include North Europe, West Europe, France Central, South Africa West, and South Africa North.

    Azure Front Door is designed to provide a secure and scalable entry point for web applications, accelerating content delivery and enhancing global performance.

    Its failure effectively cut off the “front door” for many services, rendering them inaccessible to end-users even if the backend infrastructure remained operational.

    Microsoft promptly acknowledged the incident through its official channels. The Azure Support team on X (formerly Twitter) confirmed an “ongoing outage” and stated that their engineering teams were actively working toward a resolution.

    In a more detailed impact statement, the company noted it was investigating the underlying factors that may have triggered the sudden capacity loss.

    As of 10:14 UTC, Microsoft had ruled out any recent deployments as a potential cause for the event, suggesting the root cause may be more complex.

    The company promised to provide further updates within 60 minutes or as the situation evolved, while also engaging with affected customers directly via direct messages to gather specific subscription details for better assistance.

    Users Express Frustration Online

    The outage triggered a swift reaction from the global developer and IT community, with many taking to social media to report the issues and express their frustration.

    The inability to access not just their public-facing services but also the Azure Portal itself was a significant point of concern, as it left administrators in the dark and unable to implement potential workarounds.

    The event serves as a centralized cloud infrastructure, where a single point of failure in a critical service like a CDN can lead to widespread and costly downtime for countless organizations that rely on it for their daily operations.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post Microsoft Azure Faces Global Outage Affecting Services Worldwide appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity landscape has been shaken by the emergence of Trinity of Chaos, a sophisticated ransomware collective that has launched a data leak site containing sensitive information from 39 major corporations.

    This formidable alliance, presumably comprising members from the notorious Lapsus$, Scattered Spider, and ShinyHunters groups, represents a significant evolution in cybercriminal organization and operational capability.

    The group has strategically positioned itself as a hybrid threat actor, combining traditional ransomware tactics with data extortion methodologies to maximize their impact and financial returns.

    The Trinity of Chaos collective has demonstrated remarkable operational sophistication by establishing a dedicated Data Leak Site (DLS) on the TOR network, following the established playbook of modern ransomware groups.

    Rather than announcing new attacks, the group has chosen to reveal previously undisclosed successful breaches, sharing samples of stolen data to validate their claims and pressure victims into compliance.

    This approach suggests a calculated strategy designed to maintain operational security while maximizing leverage over their targets through the threat of public data exposure.

    Following the group’s previous exploitation of Salesforce instances, they have issued ultimatums to affected companies, threatening massive data releases if negotiation demands are not met.

    Resecurity analysts identified the group’s polished marketing approach, with the collective describing themselves as specialists in “high-value corporate data acquisition and strategic breach operations” spanning multiple industries including automotive, financial, insurance, technological, and telecommunications sectors worldwide.

    The threat actors have indicated that their operations began as early as 2019, suggesting extensive experience and a well-established operational infrastructure.

    The scope of the Trinity of Chaos breach is unprecedented, with victims spanning Fortune 100 companies across diverse industries.

    Major technology giants Google and Cisco feature prominently among the compromised entities, alongside household names such as Toyota Motor Corporation, FedEx, Disney/Hulu, Home Depot, Marriott, McDonald’s, and numerous other high-profile organizations.

    The group has set October 10 as a negotiation deadline for most victims, employing psychological pressure tactics similar to traditional ransomware operations while threatening regulatory reporting that could result in criminal negligence charges against non-compliant organizations.

    Exploitation of Salesforce Infrastructure Through Advanced Social Engineering

    The Trinity of Chaos collective has demonstrated sophisticated attack methodologies centered around the exploitation of Salesforce instances through compromised Salesloft Drift AI chat integration.

    The majority of leaked data samples notably lack passwords but contain substantial amounts of personally identifiable information (PII), strongly indicating that the stolen records originate from targeted Salesforce environments.

    The attack vectors employed by the group involve vishing attacks combined with the theft of OAuth tokens specifically designed for Salesloft’s Drift AI chat integration, representing a highly targeted approach to cloud platform exploitation.

    This exploitation technique has proven so effective that it prompted the Federal Bureau of Investigation to issue a flash warning containing technical indicators that organizations should monitor to detect potential infiltration of their Salesforce environments.

    The group’s ability to maintain persistent access within victim networks for extended periods, as demonstrated in the Vietnam Airlines case where attackers remained undetected for nearly three years, highlights the sophistication of their operational security measures.

    SLSH 6.0 Part 3 (Source – Resecurity)

    The stolen data encompasses sensitive customer information, internal communications, loyalty program details, and comprehensive activity histories, providing the threat actors with extensive intelligence for future operations and social engineering campaigns.

    The Trinity of Chaos collective claims to possess over 1.5 billion records spanning 760 companies, with detailed breakdowns including 254 million account records, 579 million contact entries, and 458 million case files.

    This massive dataset originates from previous campaigns including UNC6395 and UNC6040 activities, demonstrating the group’s systematic approach to data aggregation and monetization across multiple attack campaigns.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Hacker Alliance Trinity of Chaos Leaked 39 Companies Data Including Google, CISCO and Others appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • VirusTotal, the collaborative malware analysis platform, has announced a major update to simplify access and reward contributors. The changes aim to make the platform easier to use for individual researchers while ensuring engine partners receive priority support and advanced features. VirusTotal will offer streamlined pricing tiers and a dedicated Contributor Tier to recognize and empower […]

    The post VirusTotal Introduces Simplified Platform Access and New Contributor Model appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Token theft is a leading cause of SaaS breaches. Discover why OAuth and API tokens are often overlooked and how security teams can strengthen token hygiene to prevent attacks. Most companies in 2025 rely on a whole range of software-as-a-service (SaaS) applications to run their operations. However, the security of these applications depends on small pieces of data called tokens. Tokens, like

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A proof-of-concept exploit has been published for a critical flaw in the secure boot process of the Nothing Phone (2a) and CMF Phone 1. This exploit can break the chain of trust and allow full code execution at the highest privilege level, posing a severe risk to device security. Vulnerability Overview A logic flaw in […]

    The post PoC Released for Nothing Phone Code-Execution Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A seemingly legitimate Zoom document share from “HR” redirected victims through a fake bot-protection gate into a Gmail login phish. User credentials are exfiltrated live via WebSocket and validated in real time. This report breaks down the social engineering, the malicious infrastructure, proof-of-concept exfiltration code, and indicators of compromise to watch for. Job seekers and […]

    The post Cybercriminals Impersonate HR Departments to Harvest Your Gmail Login Details appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A major service outage is affecting Microsoft 365, preventing users from accessing the admin center and other services that rely on Microsoft Entra ID for authentication.

    The disruption, which began on Thursday, October 9, 2025, is causing widespread access issues for organizations that depend on Microsoft’s cloud-based productivity suite.

    The scope of the impact is broad, affecting any user attempting to access the Microsoft 365 admin center or authenticate through Microsoft Entra ID.

    This core dependency means that numerous Microsoft 365 services, including Outlook, Teams, and SharePoint, may be inaccessible to end-users.

    Microsoft confirmed it is investigating reports from users who are unable to access these critical services. The initial phase of the investigation involved a review of dependent service pathways to identify the source of the failure and determine the first course of action.

    For IT administrators, the inability to access the admin center presents a significant challenge, as it prevents them from managing their environment or troubleshooting user-facing issues.

    Microsoft 365 Outage

    Microsoft’s investigation has identified an issue within the Azure Front Door (AFD) service as the primary cause of the outage.

    This service is responsible for managing and routing traffic to Microsoft’s global web applications, and its malfunction is leading to intermittent access problems for the Microsoft 365 admin portals.

    The failure within AFD is believed to be having a cascading effect, contributing to the wider impact on services that use Entra ID.

    In response, Microsoft’s engineering teams are reviewing recent changes made to the AFD environment that may have inadvertently triggered the disruption.

    The company is analyzing extensive diagnostic data to isolate the exact cause of the issue and understand the mechanics of the failure.

    As the investigation progresses, Microsoft’s efforts are now concentrated on the load-balancing infrastructure within its environment.

    Load balancers play a critical role in distributing incoming network traffic efficiently across multiple servers, and a fault in this system could explain the intermittent connectivity issues and access failures being reported.

    The company has stated that it is actively working on mitigation strategies to resolve the underlying problem and restore service as quickly as possible.

    Microsoft has committed to providing an update on the situation on Thursday, October 9, 2025, at 5:30 PM GMT+5:30, as engineers continue to work toward a resolution.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post Microsoft 365 Outage Disrupts Access to Admin Center, Services, and Entra ID appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A significant security flaw has been discovered within the Microsoft Events platform, which could have allowed attackers to access the personal information of users from two separate databases: the event registration list and the waitlist.

    The vulnerability, uncovered by a 15-year-old bug bounty hunter known as Faav, exposed sensitive user data, including full names, email addresses, phone numbers, and in some cases, physical addresses. The flaw was responsibly disclosed to Microsoft and has since been patched.

    The investigation began when the researcher started examining the events.microsoft.com subdomain, which led to the discovery of several API endpoints on the msevents.microsoft.com domain.

    Attack Chain
    Attack Chain

    Initial tests for vulnerabilities on various endpoints returned no sensitive data. The first breakthrough came when an OData injection flaw was identified in the /api/GetEvents endpoint.

    However, this initial entry point proved to be a dead end, as it only returned non-sensitive, public event information and threw errors when attempts were made to access other data tables like accounts or contacts.

    Database Match
    Database Match

    A similar injection vulnerability was found in another endpoint /api/GetEventCustomRegistrationFields, which allowed the enumeration of all Microsoft events but still did not leak any user data.

    Microsoft Events Vulnerability

    The crucial discovery was made within a POST endpoint named /api/CheckEventRegistration. This feature was designed to check if a user’s email was already registered for a specific event.

    The researcher found that by injecting malicious payloads into the email and eventId fields, it was possible to trick the system.

    A specific OData injection technique revealed that the endpoint was making two separate requests to two different databases. By carefully crafting the input, Faav was able to target each database individually.

    One injection allowed the enumeration of the entire Waitlist database, which contained fields such as fullname, telephone1, address1_line1, company, and email addresses, including many from government and corporate domains.

    Contact form
    Contact form

    By reversing the injection technique, the researcher was able to access the second database, the Event Registration list.

    This database contained personal details like first name, last name, phone number, company name, and country. Some events even included custom fields for Partner IDs and Tenant IDs.

    The researcher noted that there were no rate limits in place, meaning an attacker could have scripted the extraction of all data from both databases.

    After successfully demonstrating the ability to leak this information, Faav stopped further testing and reported the findings to the Microsoft Security Response Center (MSRC) on July 23, 2025.

    According to the timeline provided, Microsoft acknowledged the issue and completed a fix by August 26, 2025.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post Microsoft Events Vulnerability Exposes Users Personal Data From Registration And Waitlist Databases appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Shuyal Stealer has rapidly ascended as one of the most versatile credential theft tools observed in recent months.

    First detected in early August 2025, its modular architecture allows it to target an expansive range of web browsers, including Chromium-based, Gecko-based, and legacy engines alike.

    Initial indicators of compromise emerged as anomalous network traffic from compromised hosts, where users reported unexplained browser crashes followed by surges in outbound connections to unfamiliar command-and-control (C2) servers.

    Point Wild researchers noted that within days of its emergence, Shuyal Stealer had already compromised hundreds of endpoints across multiple industry sectors, including finance, healthcare, and manufacturing.

    The malware’s attack vectors are rooted in traditional social engineering techniques, primarily masquerading as software updates or utility installers.

    Delivered through phishing emails or malicious advertisements, the installer payload employs a self-extracting archive that unpacks and executes a legitimate system binary alongside an obfuscated DLL loader.

    Infection chain flow (Source – Point Wild)

    This side-loading mechanism allows Shuyal Stealer to evade common application whitelist solutions.

    As the loader executes, it injects the core stealer module into running browser processes, granting it full access to stored cookies, saved passwords, and form-autofill data.

    Point Wild analysts identified the use of encrypted strings and API hashing to conceal calls to key Windows functions such as LoadLibrary and GetProcAddress, complicating static analysis by security researchers.

    Upon successful injection, Shuyal Stealer begins its payload routines, harvesting credentials from browser SQLite databases and memory.

    It supports 19 different browsers, including Chrome, Edge, Firefox, Opera, Vivaldi, Brave, and several lesser-known forks popular in certain regions.

    The stealer can also extract banking session tokens and two-factor authentication approvals stored in local cache.

    Once collected, data is compressed using a custom ZIP implementation and encrypted with AES-256 in CBC mode before exfiltration.

    Traffic analysis shows the malware batching stolen credentials into 512 KB chunks, which are sent over HTTPS to a dynamically generated subdomain for each victim, complicating takedown efforts.

    Infection and Loader Mechanism

    Shuyal Stealer’s infection mechanism hinges on DLL side-loading and unhooked API calls to maintain stealth.

    After decompressing the archive, the loader writes a benign system executable (for example, svchost.exe) into the Windows directory and drops an accompanying malicious DLL in the same location.

    The executable is then launched with a crafted registry entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, ensuring persistence across reboots.

    Once the legitimate executable loads, Windows automatically resolves and loads the malicious DLL due to its naming convention match.

    Within the DLL’s DllMain, the loader invokes a staged unpacker:-

    // Simplified unpack routine
    void UnpackAndInject() {
        BYTE* encryptedPayload = LoadResource(MAKEINTRESOURCE(101));
        BYTE* payload = DecryptAES256(encryptedPayload, payloadSize, key, iv);
        HANDLE hProc = OpenProcess(PROCESS_ALL_ACCESS, FALSE, targetPid);
        LPVOID remoteMem = VirtualAllocEx(hProc, NULL, payloadSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
        WriteProcessMemory(hProc, remoteMem, payload, payloadSize, NULL);
        CreateRemoteThread(hProc, NULL, 0, (LPTHREAD_START_ROUTINE)remoteMem, NULL, 0, NULL);
    }

    This unpacker decrypts the core stealer module in memory and injects it into the target browser process.

    By avoiding writing the primary payload to disk and leveraging legitimate binaries, Shuyal Stealer bypasses many endpoint detection solutions.

    The use of API hashing further thwarts heuristic detection, as function names never appear in string tables.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Shuyal Stealer Attacking 19 Browsers to Steal Login Credentials appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶