Silver Bullet Security

Silver Bullet Security Our managed security service is comprised of governance, engineering and training backed up by systems and data risk monitoring and management.

✨🌐There are preliminary reports that a threat actor known as TheHatman is selling data allegedly stolen from the Azure a...
19/08/2026

✨🌐There are preliminary reports that a threat actor known as TheHatman is selling data allegedly stolen from the Azure and Microsoft Entra ID environments of several Fortune 500-level organizations, including McDonald’s, Tata Consultancy Services (TCS), Vodafone, HCL Technologies, and InterContinental Hotels Group (IHG). The datasets reportedly contain millions of employee directory records, including names, corporate email addresses, phone numbers, employee IDs, job titles, service accounts, and privileged administrator information. The largest dataset reportedly belongs to McDonald’s, with more than 1.7 million records.
According to Hudson Rock, the attacker allegedly obtained the data using previously leaked credentials, potentially linked to targeted infostealer malware campaigns. Exposure of internal organizational structures and privileged accounts could facilitate social engineering, spear-phishing, and Business Email Compromise (BEC) attacks.
Organizations using Azure and Microsoft Entra ID should review logs for suspicious data access, enforce MFA, reset credentials for high-risk accounts, particularly administrators, and raise employee awareness of suspicious emails and communications.




👑Read more : https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/

✨💎🌐Threat actors are reportedly using Email Addresses leaked from previous Data Breaches and exposed by the Extortion gr...
31/07/2026

✨💎🌐Threat actors are reportedly using Email Addresses leaked from previous Data Breaches and exposed by the Extortion group ShinyHunters to conduct Sextortion email scams. The emails impersonate ShinyHunters, demand USD 2,000 in Bitcoin, and falsely claim that attackers have accessed victims’ devices and recorded private activities.
Investigations indicate that these emails were not sent by ShinyHunters directly but are instead using previously leaked data to make the threats appear credible. There is no evidence that attackers actually accessed devices, installed Malware, or captured personal information.
Users should not pay, reply, click links, or open attachments from such emails. They should delete the messages and report them to the Security team if using a corporate account.

Read more : https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/

🔴🌐⚠️The new version of RedHook Android malware spreads by masquerading as government agencies and banks to trick victims...
14/07/2026

🔴🌐⚠️The new version of RedHook Android malware spreads by masquerading as government agencies and banks to trick victims into downloading apps from fake Google Play sites. Once installed, it abuses Accessibility permissions to automatically enable Wireless ADB in the settings, allowing the malware to gain high-level Shell privileges without requiring a rooted device. This connection enables attackers to silently stream screens, intercept credentials, and gain full remote control over the compromised smartphone without the victim's knowledge.



🔰Read more : https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/

✨🌐OpenAI has announced a limited preview of its new GPT-5.6 model lineup, introducing three tier-based systems named Sol...
30/06/2026

✨🌐OpenAI has announced a limited preview of its new GPT-5.6 model lineup, introducing three tier-based systems named Sol, Terra, and Luna, with GPT-5.6 Sol being the premier flagship model optimized for high-intensity reasoning and advanced cybersecurity. Developed under strict consultation with the U.S. government, Sol is specifically engineered to favor defensive security tasks, such as automated vulnerability identification and patch development, rather than executing end-to-end cyberattacks. Benchmark tests on ExploitBench show that Sol matches the performance of top competing systems like Anthropic's Mythos Preview while utilizing only about one-third of the output tokens, representing a major leap in processing efficiency. To prevent dual-use risks and malicious exploitation, OpenAI integrated a multi-layered security architecture into the core system, featuring automated real-time classifiers that scan and block unsafe requests instantaneously. While currently restricted to approved partners and government-vetted institutions, OpenAI aims to deploy the GPT-5.6 family to ChatGPT and the broader public API in the near future.

Read more || https://www.securityweek.com/openai-unveils-gpt-5-6-sol-as-its-most-advanced-cybersecurity-ai/

🌐Due to the detection of the global 'FortiBleed' cyber campaign targeting over a hundred thousand Fortinet VPN and Sopho...
23/06/2026

🌐Due to the detection of the global 'FortiBleed' cyber campaign targeting over a hundred thousand Fortinet VPN and Sophos systems through credential spraying

🌐attackers have launched over a billion password-guessing attempts to intercept data and compromise enterprise networks

🌐therefore, system administrators must immediately update firmware, enforce a company-wide password reset, and enable multi-factor authentication (MFA) to block further intrusion

✨Read more : https://securityaffairs.com/193931/hacking/fortibleed-exposes-global-credential-spraying-operation.html

💎🛡️A Romanian hacker has been sentenced to nearly five years (57 months) in a U.S. federal prison after being extradited...
31/05/2026

💎🛡️A Romanian hacker has been sentenced to nearly five years (57 months) in a U.S. federal prison after being extradited to face charges for unauthorized access to the computer networks of various U.S. companies and organizations. The hacker was found guilty of compromising these systems to steal sensitive data and deploy malicious software. This successful prosecution highlights the effective collaboration between the U.S. Department of Justice and Romanian law enforcement, underscoring the U.S. government’s unwavering commitment to prosecuting international cybercriminals and demonstrating that global boundaries provide no sanctuary from the reach of the law. 🏛️

Read more: https://securityaffairs.com/192770/cyber-crime/romanian-hacker-gets-nearly-5-years-in-us-prison-over-network-intrusion.html

🎊🎁The Interchange 21 management team visited the office and give a gift basket to express our gratitude for your trust i...
19/05/2026

🎊🎁The Interchange 21 management team visited the office and give a gift basket to express our gratitude for your trust in our office rental services.✨💐

Google is set to significantly upgrade security on Android 17, focusing on blocking scams and preventing data theft. A k...
15/05/2026

Google is set to significantly upgrade security on Android 17, focusing on blocking scams and preventing data theft. A key highlight is a partnership with banking apps to automatically detect and disconnect spoofed calls pretending to be financial institutions-a feature that will retroactively support devices down to Android 11.
Additionally, enhanced AI will monitor malicious apps attempting to intercept SMS messages, while a new "Mark as Lost" mode enforces biometric authentication, preventing thieves from unlocking or untracking the device even if they know the PIN. Other notable protections include hiding OTP codes from third-party apps for three hours and allowing users to disable outdated 2G networks to block potential eavesdropping.

Read More : https://www.bleepingcomputer.com/news/security/android-17-to-expand-banking-scam-call-and-privacy-protections/

🌐The threat actor UNC6692 utilizes Email Bombing to overwhelm inboxes and create a false sense of urgency. Attackers the...
28/04/2026

🌐The threat actor UNC6692 utilizes Email Bombing to overwhelm inboxes and create a false sense of urgency. Attackers then impersonate IT personnel via Microsoft Teams to trick victims into installing malware, disguised as a "patch" to resolve the spam issue.
🌐 Capabilities of the “Snow” Malware Suite
The Snow malware family operates as a coordinated ecosystem: SnowBelt ensures persistence through browser integration, SnowGlaze establishes communication with Command-and-Control (C2) servers, and SnowBasin acts as a backdoor for remote command ex*****on, data theft, and screen capturing.
🌐 Network Intrusion and Data Exfiltration
After gaining initial access, the attackers move laterally through the network to compromise the Domain Controller. They employ memory dumping techniques to steal credentials and use FTK Imager to extract critical organizational databases. Finally, the stolen data is exfiltrated via LimeWire to maximize impact and facilitate further attacks.
🌐 Read more https://www.bleepingcomputer.com/news/security/threat-actor-uses-microsoft-teams-to-deploy-new-snow-malware/%0A

Security researchers from CloudSEK have identified a critical vulnerability in over 22 popular Android applications (tot...
13/04/2026

Security researchers from CloudSEK have identified a critical vulnerability in over 22 popular Android applications (totaling over 500 million downloads). These apps were found to have hardcoded Google API Keys within their source code. Because of how Google Cloud handles permissions, these keys—originally intended for basic services—can be exploited to gain unauthorized access to Google’s Gemini AI services.

The Shift in API Key Status: Historically, Google suggested that API keys for public services (like Google Maps) did not necessarily need to be kept secret. However, if a developer enables the Gemini API (Generative Language API) within that same Google Cloud project, the "public" key automatically gains the power to access Gemini.
Access to Sensitive Data: Attackers can extract these keys by decompiling the Android app. Once obtained, they can access files uploaded to Gemini, retrieve cached content, and execute AI models under the project owner’s identity.
Financial Impact: Attackers can exhaust AI quotas or rack up massive bills. Some reports indicate victims being charged as much as $15,400 (approx. 500,000 THB) within just a few hours of an exploit.
Read more : https://www.securityweek.com/google-api-keys-in-android-apps-expose-gemini-endpoints-to-unauthorized-access/

ที่อยู่

Exchange Tower
Bangkok
10110

เบอร์โทรศัพท์

+6621049251

แจ้งเตือน

รับทราบข่าวสารและโปรโมชั่นของ Silver Bullet Securityผ่านทางอีเมล์ของคุณ เราจะเก็บข้อมูลของคุณเป็นความลับ คุณสามารถกดยกเลิกการติดตามได้ตลอดเวลา

ทางลัด

แชร์