Attackers abuse Node.js to execute malicious scripts and deploy payloads in attacks targeting governments, technology ...
Threat actors are abusing legitimate remote-management tools, including ConnectWise ScreenConnect and Microsoft Quick Assist, ...
The flaw that had gone unnoticed since 2014 could let attackers with low-privileged replication access execute code, gain ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Microsoft Threat Intelligence identified a “TerminalFix” social engineering campaign designed to deploy a custom Python-based ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.