Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Here's Why eSIM Became a Trap for Mobile Users

  eSIM technology was heralded as the future of mobile connectivity, promising to eliminate the hassle of physical SIM cards and make switch...

All the recent news you need to know

Third-Party Cloud Breach Exposes Patient Data at Amgen


 

The global biotechnology company Amgen has disclosed a significant data breach resulting from unauthorized access to cloud environments operated by third-party service providers, leading to the theft of sensitive patient and corporate information. According to a filing with the Securities and Exchange Commission (SEC), the pharmaceutical company, based in California, discovered the incident in July 2026 and initiated its cybersecurity incident response process immediately. 

Several containment measures were implemented by the company and independent forensic experts were engaged in an investigation into the breach. As a result of assessing the volume of files that appeared affected and determining that the compromised data could contain sensitive information, Amgen formally classified the incident as material on July 29, 2017. 

As part of the legal requirement to inform investors of significant cybersecurity incidents, the company made the disclosure in a regulatory filing with the Securities and Exchange Commission. Upon preliminary investigation, it was determined that hackers successfully exfiltrated data from a number of cloud-based systems. 

In addition to proprietary corporate data, protected health information (PHI) belonging to patients, and other sensitive records, this information has been compromised. Despite not identifying the vendors involved or revealing how the attackers gained access to the stolen data, Amgen claims that the stolen data originated from cloud storage environments managed by third-party service providers. Additionally, Amgen is assessing whether confidential business information, intellectual property, research and development data, and additional patient information was compromised. 

During the ongoing forensic investigation, the company is continuing to determine if patient records, confidential business information, intellectual property, research and development data, or other sensitive information was accessed or stolen during the incident. 

Upon completion of the forensic investigation, the full scope of the compromise is anticipated. There has been no disclosure by the company as to identification of the third-party cloud providers, attack vectors used by threat actors, or number of individuals affected. No known cybercriminal organization has been attributed to the incident.

Following an evaluation of the number of potentially affected files and the likelihood that they contained highly sensitive information, Amgen determined that the breach was material on July 29. Even though the breach is serious, the company stated that it does not anticipate that the breach will adversely affect its financial condition or operating results in the near future. 

In addition to the assistance of external cybersecurity experts, the investigation is currently ongoing. Considering its legal and regulatory obligations, Amgen stated that it would notify affected patients where required under applicable data protection laws. According to Amgen's current assessment, the cybersecurity incident has not adversely affected its products, manufacturing operations, financial reporting systems, or its ability to continue supplying medicines and meeting the needs of patients. 

There has been an increase in cyberattacks targeting healthcare and pharmaceutical organizations, whose cloud-hosted patient records and valuable research data have made these organizations attractive targets for cybercriminals. In addition to highlighting the increasing cybersecurity risks associated with third-party cloud infrastructure, the incident highlights the importance of securing sensitive healthcare data throughout the supply chain as a whole. 

Amgen stated its response was to activate its cybersecurity incident response plan immediately after detecting the unauthorized activity, implement containment measures in order to limit exposure, and continue to work with independent forensic experts to determine the extent and impact of the incident. There has been an increase in cybersecurity incidents impacting the healthcare and pharmaceutical sectors in recent months. 

The breach is another in a string of recent cybersecurity incidents. The industry has also experienced numerous cyber incidents, including Abbott Laboratories, Clover Health, Stryker, Medtronic, Novo Nordisk, and West Pharmaceutical Services, which illustrates the increasing vulnerability of medical and corporate data to cyberattacks. 

Amgen has not yet disclosed whether it has received any extortion demands or whether the attackers have attempted to take advantage of the stolen data for ransom or another malicious purpose. It is anticipated that additional details will be released once the forensic investigation has been completed. 

Privacy-preserving technologies are reshaping digital identity verification as governments enforce age verification requirements. It is anticipated that solutions that minimize biometric data collection while maintaining security and regulatory compliance will play an important role in the future of online security.

Apps Targeting U.S. Military Personnel Found to Contain Chinese and Russian Software Components, Study Finds

 


A study led by researchers from Purdue University has found that a notable number of Android applications marketed toward U.S. military personnel include software components developed by companies based in China, Russia, and other countries identified by the U.S. Department of Defense as adversarial nations.

The research, conducted in collaboration with the U.S. Military Academy at West Point and Florida International University, examined more than 220 Android applications obtained from Google Play and online military communities. According to the researchers, over one in every eight apps analyzed contained code associated with organizations headquartered in countries regarded as strategic competitors of the United States. The Pentagon declined to comment on the study's findings.

Rather than identifying malicious applications outright, the study highlights a growing software supply chain challenge created by third-party Software Development Kits (SDKs), which developers routinely integrate into applications to support features such as advertising, analytics, authentication, and push notifications. While these components simplify development, they can also introduce external code that developers may not fully inspect or even realize has been included.

Researchers found SDKs in approximately 64% of the analyzed applications. Among them, twelve apps contained Huawei's HMS Core framework, including applications developed for state National Guard organizations. In one instance, Huawei's software was not intentionally added by the application's developer. Instead, it was introduced indirectly through a commercial notification service that bundled Huawei's SDK as a dependency.

The researchers noted that this type of indirect integration presents an important security concern because SDKs can receive remote updates over time. Even if no sensitive information is transmitted today, future updates could potentially alter an application's behavior without users being aware. Although the study did not observe any data being sent to Huawei-controlled servers during testing, the researchers cautioned that the presence of such software should not automatically be considered harmless.

Beyond Huawei, the analysis also identified software associated with Russian technology companies. SDKs linked to Yandex advertising services were found in applications used by military-affiliated users. The study also referenced Pushwoosh, a Russian software company that previously presented itself as a U.S.-based business. Reuters reported in 2022 that Pushwoosh code had been embedded in official mobile applications operated by the U.S. Army and the U.S. Centers for Disease Control and Prevention (CDC). Both organizations subsequently removed the software following public disclosure.

The researchers also discovered discrepancies between application behavior and the privacy information disclosed through Google Play. Approximately 40% of the applications examined either collected or shared more user data than indicated by their app store privacy labels. Overall, around 7% of the analyzed applications contained software linked to companies headquartered in countries designated by the Pentagon as adversarial nations.

Lead author Joshua Shinkle of Purdue University said the team hopes the findings encourage stronger awareness among military personnel, application developers, platform providers, and policymakers. According to Shinkle, the research is intended to support more informed privacy decisions while encouraging discussions about improving transparency and addressing existing security gaps.

The study argues that the implications extend beyond software development practices. Researchers pointed to the commercial mobile advertising ecosystem, where applications routinely collect location and device information that can later be shared through data brokers. Such information has the potential to expose sensitive operational patterns, including troop movements, deployment routines, and activity around military installations.

The report references an April letter in which U.S. Central Command (CENTCOM) informed Senator Ron Wyden that it had received multiple threat reports indicating that adversaries were exploiting commercially available location data to monitor U.S. military personnel operating near Iran and the Strait of Hormuz. Lawmakers described the disclosure as the first official acknowledgement that commercially traded mobile data had been used to track troops deployed in an active conflict zone.

Researchers also surveyed 103 military-affiliated Americans to better understand attitudes toward mobile application privacy. More than 83% of respondents reported using at least one application whose data collection practices made them uncomfortable. Between 76% and 83% indicated they would be extremely uncomfortable using applications containing software developed by companies from adversarial nations.

Despite these concerns, participants expressed greater trust in applications carrying military branding, suggesting that official appearance can influence perceptions of security even when underlying software components remain largely invisible to users. Nearly two-thirds of respondents also reported receiving little or no institutional guidance regarding the security risks associated with personal mobile applications.

When asked about potential solutions, respondents strongly supported greater transparency regarding third-party software embedded within applications. The most widely supported recommendation involved providing users with in-device notifications identifying foreign-developed SDKs before installation or use.

Participants also backed stronger federal restrictions on the commercial trading of military-affiliated location data, independent security audits of applications, and tighter controls on the inclusion of foreign-developed SDKs in apps marketed toward service members.

While the U.S. Marine Corps already prohibits several categories of applications, including gambling, dating, and cryptocurrency apps, from government-issued devices and has warned personnel against using platforms such as TikTok and WeChat, the researchers argue that personal smartphones remain a largely unaddressed area of risk because they frequently fall outside existing policy controls.

According to the researchers, improving software transparency will require greater visibility into third-party components that operate behind the scenes. They recommend clearer country-of-origin labeling for embedded SDKs within application marketplaces and encourage developers to regularly audit their software dependency chains to better understand which external components are included in their applications.

The study concludes that branding alone should not be viewed as an indicator of application security. As modern mobile apps increasingly rely on extensive networks of third-party software, researchers argue that stronger transparency, routine dependency auditing, and more robust privacy safeguards will be necessary to reduce hidden supply chain risks facing military personnel and other users handling sensitive information.

HollowGraph Malware Abuses Microsoft 365 Calendars for Covert Command-and-Control

 

The malware component HollowGraph is using Microsoft 365 mailbox calendars to hide its C2 channels and traffic, enabling the bad actors to communicate with the malware and exfiltrate the data. Group-IB researchers note that HollowGraph is a part of the Cavern command-and-control framework used by the Iranian nation-state actor previously observed targeting Israeli organizations. Researchers note that at least 12 Microsoft 365 mailboxes were compromised using HollowGraph, and three of them established communication with the attackers’ C2 servers between June 3 and July 9. 

Additionally, based on the infrastructure and victims’ location, Group-IB experts suggest that Israel is the likely target of this malware. The HollowGraph malware component is designed to self-register in the Microsoft Graph API using the credentials stolen from the Microsoft 365 mailbox. It stores the configuration data in the logAzure.txt file, which contains the Microsoft Entra ID information, client credentials, mailbox addresses of the victims, domains controlled by the attackers, and keys required to communicate with the C2 infrastructure. 

The attackers have taken measures to ensure that this file is not suspicious; specifically, it is placed in the known location used by Microsoft Entra ID and has the standard log file name. The malware communicates with its C2 server using the Microsoft 365 calendars. Specifically, HollowGraph creates events scheduled on May 13, 2050, and uses their titles and attachments to exchange data with the attackers. There are two types of such events: GET and SEND. The first one is used to retrieve the encrypted commands by extracting the contents of the event’s title. 

In turn, the SEND type of events is used to exfiltrate the stolen data by adding it as an attachment. Researchers note that the mailbox calendars are used as a “dead drop” to store the data; hence, HollowGraph does not use traditional C2 servers to avoid detection. It implements a strong encryption scheme to protect the command and data exfiltration channels and uses a combination of RSA and AES_256_GCM encryption algorithms. The RSA public key is embedded into the calendar event, whereas the HollowGraph malware uses the AES key to encrypt the data. 

Besides the Microsoft Graph API, HollowGraph also uses the Domain Name System (DNS) to communicate with its C2 servers. Specifically, the malware resolves the domains controlled by the attackers to extract the IPv6 AAAA records, which contains the updated Microsoft Entra ID credentials required to maintain persistence on the compromised mailboxes. Similar to the information stored in the logAzure.txt file, these credentials include the Microsoft Entra ID tenant, client ID and secret, and the mailbox information. 

All of these credentials are extracted from the DNS responses and stored in the malware configuration. Group-IB researchers conclude that HollowGraph is a sophisticated backdoor that utilizes various cybersecurity technologies to compromise targeted Microsoft 365 mailboxes and remain undetected for as long as possible. While the technical capabilities of this malware component overlaps with the ones attributed to the Lyceum Iranian nation-state actor, the researchers are not certain about its origin. 

Nevertheless, Group-IB experts note that there is a high likelihood that HollowGraph belongs to the Cavern framework used by Lyceum. To detect and prevent similar attacks, the cybersecurity experts recommend that organizations monitor the Microsoft Graph API activity and Microsoft 365 audit logs for any suspicious activities related to the creation of the calendar events. Specifically, defenders should pay attention to the events created by applications using the Microsoft Graph API scheduled far in the future, with the suspicious subjects and attachments. 

The researchers also recommend that organizations add the cloudlanecdn[.]com domain to their threat intelligence platforms and continuously monitor their Microsoft 365 environments for any unauthorized OAuth client credential applications. In addition, Group-IB experts note that Microsoft Entra ID Conditional Access policies and outbound DNS traffic should be reviewed to detect and block similar恶意 activities, such as DNS tunneling. This report highlights the importance of the growing threat landscape in cloud environments caused by the increasing reliance on the collaborative software in enterprise networks. 

Malware components like HollowGraph demonstrate that the attackers do not limit themselves to traditional network security tools and can use the trusted infrastructure to launch attacks against various organizations. In particular, the attackers utilize the cloud infrastructure as a part of their mitigation strategy. In turn, the defenders should shift their focus from traditional network perimeter security to inspecting individual hosts and applications for detecting malicious activities.

HollowFrame Loader and Matryoshka Malware Used in Spear-Phishing Attack

Experts discovered a recently undocumented Go-based loader framework termed HollowFrame and a Rust-based malware strain called Matryoshka.

Spear-phishing for attacks

Blackpoint Cyber said that the hack starts with a spear-phishing message consisting of a link to an encoded archive, which contains a Windows Shortcut (LNK). Running a file prompts a multi-level strain that consists of privilege escalation, compromising Microsoft Defender protections, while downloading extra payloads.

About Matryoshka

Matryoshka is available in two versions: one that supports HTTP-based communication and command execution, and another that uses GitHub for command-and-control (C2), including beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery. HollowFrame is launched via a DLL side-loading pair consisting of the legitimate Python binary ("python.exe") and a rogue DLL ("python311.dll").

"Together, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling. These capabilities could support credential theft, lateral movement, and broader domain compromise through additional tools delivered after initial access,” Blackpoint experts Nevan Beal and Sam Decker said.

Attack tactic

The multi-stage hack attacks two endpoints at an unknown law firm. The LNK file mimicked to be Case Documents to lure the victim into opening and triggering a command sequence that deploys PowerShell to get next-stage components from a remote server.

Hollowframe works as a modular loader and persistent framework that assists multiple tactics to deploy auxiliary components, while performing anti-analysis diagnosis to escape running inside sandboxed environments. This is decided based on installed memory, cursor movement, file count in the user profile, and system uptime. Persistence is gained by setting up a scheduled task.

Matryoshka ("version.dll"), a Rust-based backdoor that talks with its C2 server ("45.158.196[.]184:8888") over HTTP to spawn a shell and provide additional tooling, is deployed by unpacking the encrypted container that the Go loader comes with.

Another DLL gained in association with the same activity has been labeled as a version of Matryoshka that uses a private GitHub repository for polling target-specific commands, submitting results, and fetching payloads.

"The repository functioned as a collection of per-host mailboxes, with each victim assigned a dedicated <computer>_<username> directory. These directories contained beacon.json, cmd.json, result.json, and, in some cases, an upload/ tree for file delivery,” Blackpoint said.  

Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability

 

Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed to steal personal data of some of the company’s employees. The company confirmed that some of the information on the intranet belonged to third parties who were not authorized to access it. 

According to the company’s statement, Estee Lauder learned about the breach following an internal investigation into the cybersecurity incident. Specifically, investigators discovered on June 19, 2026, that unauthorized users accessed the Oracle EBS system on or around August 9, 2025. The data exfiltrated by the hackers varied depending on the individual’s details but generally included names, addresses, and email, birth dates, social security numbers, passport numbers, bank information, medical data, and records of payroll and performance reviews. 

Since the breach involved PII, financial information, and employment data, there is a risk of identity theft and financial fraud for the affected employees. After detecting the anomaly, Estee Lauder contracted cybersecurity experts to conduct a forensic audit, report the pertinent information to the relevant law enforcement agencies, and take additional measures to secure the site. The company is offering 24 months of identity and restoration services through Kroll to all the affected parties free of charge, and the services will be available until October 31, 2026. All the affected employees should remain on the lookout for possible suspicious activities, including monitoring financial accounts, credit reports, and other relevant personal information. 

Even though Estee Lauder did not disclose the identity of the perpetrators, in the context of the discovered timeline, it is plausible to assume that the threat actors who targeted the company are part of the Cl0p extortion group. According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. 

The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14. Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited. The latest breach serves as a reminder of the potential risks associated with the use of enterprise resource planning software that has the capability to store PII and other sensitive information about employees. 

It is strongly advised that organizations that use similar systems remain wary of the threats and make sure that all the relevant software has been updated with the latest security patches while also configuring the tools in a manner that minimizes the attack surface. In addition, enterprise systems should be constantly monitored for any suspicious activities that could indicate possible threats to data security.

Suspected Chinese-Speaking Threat Actor Targets Central Asian Governments With New OctLurk and SilkLurk Malware

 



Government organizations across Central Asia are facing a cyber espionage campaign that employs two newly identified malware families, OctLurk and SilkLurk, in attacks aimed at establishing long-term access to sensitive networks. Kaspersky said the activity has been ongoing since at least January 2025 and has affected organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and the Syrian Arab Republic. Victims span government ministries, foreign affairs departments, law enforcement agencies, healthcare organizations, research institutions, logistics providers, urban planning and facilities management offices, and public educational establishments. Although the campaign has not been tied to any known threat group, investigators believe a Chinese-speaking actor is behind the operation.

At the core of the campaign is a modular malware framework supported by LurkProxy, a custom utility that routes network traffic through compromised systems. The initial access method remains unknown, but investigators found that OctLurk is delivered through a lightweight loader that injects the backdoor directly into memory, checks internet connectivity, launches LurkProxy, and establishes communication with attacker-controlled command-and-control (C2) servers. The malware then gathers information about the infected device, encrypts the collected data, and retrieves plugins that are executed entirely in memory. This design allows the attackers to add capabilities as needed, including command execution, file manipulation, screenshot capture, clipboard monitoring, keyboard and mouse simulation, network scanning, email collection, keylogging, credential dumping, browser password theft, and remote access, while leaving very little evidence on disk.

Analysis of the intrusions shows the operators moving quickly from reconnaissance to credential theft and lateral movement. The attackers exported Windows logon events to identify user activity, extracted password hashes from Active Directory domain controllers using Impacket's secretsdump.py, deployed a keylogger disguised as AnyDesk, recovered saved credentials from Google Chrome and Mozilla Firefox, and established remote access with Pandora RC. They also scanned internal and external networks with Fscan to identify services such as SSH and MySQL before attempting authentication with credentials stored in a password file. The campaign also involved connecting to email servers, accessing shared network resources with administrative credentials, collecting confidential documents, and compressing the staged data with WinRAR and 7-Zip before possible exfiltration.

SilkLurk expands the framework through DLL side-loading, creating a TCP connection with its configured C2 server before collecting victim information, receiving updated instructions, and loading additional plugins directly into memory. Investigators also found the malware deploying PlugX, a backdoor that has repeatedly appeared in Chinese cyber espionage operations. Kaspersky identified infrastructure overlaps with an earlier campaign involving the SilentRaid implant, also tracked as MystRodX and TrustFall, but said the available evidence is insufficient to confirm the same operators were responsible. Both OctLurk and SilkLurk rely on victim-specific decoding mechanisms derived from a system's drive serial number or computer name, making forensic analysis more difficult and allowing the malware to remain concealed while maintaining access to compromised government networks.

Featured