惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
腾讯CDC
aimingoo的专栏
aimingoo的专栏
月光博客
月光博客
Engineering at Meta
Engineering at Meta
C
Check Point Blog
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
GbyAI
GbyAI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
B
Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
WordPress大学
WordPress大学
博客园 - 司徒正美

News Archives - Heimdal Security Blog

Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It AI Will Absorb 99.98% of SOC Triage Within a Year, as 79% of IT teams brace for AI-driven workload shift Heimdal Achieves OPSWAT Gold Certification for Anti-Malware Digital Warfare and the New Geopolitical Frontline Nearly 40% of 2024 Ransomware Payouts May Have Gone to Russia, China & North Korea Is Your Tech Stack Killing Profitability? The Silent Bug Crippling MSP Growth Where Ransomware Profits Go and How to Cut Them Off Heimdal 5.0.0 RC: RDP Protection, Ransomware Detection, and OS Deployment Digital doppelgängers: How sophisticated impersonation scams target content creators and audiences Heimdal Joins the Tidal Cyber Registry with Its Extended Detection & Response (XDR) Solution Heimdal Investigation: European Organizations Hit by PDF Editor Malware Campaign Colt Technology Services Breached – Warlock Gang Claims Attack Attack Surface Management: Why MSPs Don’t Need Another Tool Should MSPs Stop Chasing Leads and Start Solving Problems? Agent Fatigue Crisis Hits 89% of MSPs as Security Tools Backfire Your Protection Guide For Cybersecurity in Manufacturing
Fortinet VPNs Under Coordinated Attack
Livia Gyongyoși · 2025-08-14 · via News Archives - Heimdal Security Blog

Time for your Weekly Cyber Snapshot with Adam Pilton, former Cybercrime Investigator, currently Cybersecurity Advisor.
The five major cyber stories this week go from North Korea’s cyber playbook getting leaked to the silent burnout creeping up on MSPs. Let’s go.

North Korean Cyber Ops Get Hacked

Hackers using the names Saber and Cyborg claim to have successfully breached a North Korean cyber operator connected to the infamous Kimsuki Group. Their breach? A goldmine-internal tools, training manuals, credentials, and email addresses.
What’s been exposed paints a detailed picture of espionage tactics and crypto theft campaigns. All of this reportedly came from a single compromised workstation. That’s right—one machine opened the doors to uncovering broader North Korean cyber operations.

How to Stay Safe

• Understand that espionage campaigns rely on human and technical weaknesses.
• Don’t assume your workstation isn’t a target, it can be the gateway.
• Practice strong endpoint security hygiene always.

Fortinet VPNs Under Attack

We’ve seen a spike in brute force attacks on Fortinet SSL VPNs kicking off early this month. And it didn’t stop there. Threat actors are now also probing FortiManager services in a coordinated second wave.
This strategy suggests a clear pattern: breach the edge, then move laterally into your management systems. Remote access threats are on the rise—and VPNs are squarely in the crosshairs.

How to Stay Safe

  • Lock down your VPNs immediately.
  • Restrict access to FortiManager.
  • Enforce multi-factor authentication (MFA).
  • Rate-limit login attempts.
  • Monitor for unusual traffic toward management ports.

ShinyHunters + Scattered Spider: A Dangerous Duo

Two cybercrime gangs—ShinyHunters and Scattered Spider—are now joining forces. They’re blending social engineering and extortion tactics to devastating effect.
Their toolkit includes:

  • Phone-based phishing
  • Fake IT support calls
  • Phishing emails
  • Bogus single sign-on portals

Their goal? Trick users, breach systems, and then pressure organizations by threatening data leaks. And they’re targeting big name retail, aviation, tech, financial services, and more.

How to Stay Safe

  • Train staff to spot vishing. Voice phishing is just as dangerous as email.
  • Check all suspicious requests out-of-band.
  • Just because someone sounds helpful on the phone doesn’t mean they are.

Lenovo Webcams Reprogrammed for Attacks

Researchers have discovered that certain Lenovo webcams can be reflashed to behave like malicious USB devices. We’re talking about turning a webcam into a fake keyboard or network adapter to inject keystrokes or maintain stealthy access.

Even wiping the OS won’t help if the firmware has been compromised. The root cause? Weak or missing firmware verification in specific models.
This isn’t the first time webcams have been abused—and it won’t be the last.

How to Stay Safe

  • Update your webcam firmware, don’t wait.
  • Audit and limit USB access across systems.
  • Disable unnecessary USB device classes to reduce the attack surface.

MSPs Are Drowning in Alerts

A joint survey by Heimdal and FutureSafe reveals a sobering stat: 89% of MSPs are suffering from alert fatigue.
Many are juggling five or more tools that don’t integrate. The result? Analysts are overwhelmed with false positives while real threats slip through the cracks.
As Jason Whitehurst, CEO at FutureSafe, puts it: “Agent fatigue isn’t just a tech issue—it’s a business risk.”

How to Stay Safe

  • Stop adding new tools just to tick boxes.
  • Consolidate your platforms – less is more.
  • Automate triage workflows.
  • Tune your alerts so your analysts see only what truly matters.

That’s a wrap for this week’s Cyber Snapshot. Stay sharp. Stay secure. We’ll be back next week with the latest in cyber news.

If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube.

Author Profile

Communications and PR Officer

Livia Gyongyoși is a Communications and PR Officer within Heimdal®, passionate about cybersecurity. Always interested in being up to date with the latest news regarding this domain, Livia's goal is to keep others informed about best practices and solutions that help avoid cyberattacks.