CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Weekly Cybersecurity Briefing (24 November – 30 November 2025)

Published: Loading…

This briefing covers 189 reports published from 24 November to 30 November 2025.

At a Glance

  • A wave of supply-chain attacks saw Shai-Hulud malware expand through npm and Maven packages.
  • ClickFix and Matrix Push C2 campaigns used steganography and browser notifications for malware delivery.
  • Breaches at Harvard, Dartmouth, and Gainsight exposed personal data.
  • Ransomware disrupted US emergency alerts and local councils.

Summary

The week saw a significant rise in supply-chain threats, ransomware disruptions, and breaches at major institutions.

  • Shai-Hulud campaign expanded across both npm and Maven Central repositories, infecting thousands of packages to steal credentials and compromise multi-cloud environments.
  • ClickFix campaign utilised steganographic PNG files and fake Windows Update screens to deliver infostealer malware, marking a new trend in browser-based attacks.
  • Matrix Push C2 abused browser push notifications for phishing and malware delivery, taking advantage of notification permissions to track and redirect users.
  • Harvard University and Dartmouth College disclosed breaches, with attackers exploiting Oracle E-Business Suite zero-days to access sensitive data.
  • Ransomware attack on OnSolve CodeRED led to nationwide emergency alert system disruptions in the US, highlighting growing vulnerabilities in critical infrastructure.
  • Gainsight breach revealed unauthorised access to Salesforce-linked applications, affecting multiple clients and prompting integration suspensions.

Highlights of the Week

Shai-Hulud Campaign Expands Through Trojanised npm Packages

The Shai-Hulud supply-chain attack expanded its reach by injecting credential-stealing malware into npm packages, impacting thousands of repositories and cloud environments. Attackers used compromised maintainer accounts to propagate the attack.

Sources: Wiz

Matrix Push C2 Uses Browser Alerts for Phishing and Malware

The Matrix Push C2 platform leveraged browser notifications to deceive users into visiting phishing pages and downloading malware. The attack exploits notification permissions for real-time user tracking and data theft.

Sources: Malwarebytes

Gainsight Reports Larger Set of Affected Customers

Gainsight expanded its list of impacted clients following a breach involving unauthorised access to Salesforce-linked applications. The ShinyHunters group claimed responsibility, leading to integration suspensions for some third-party platforms.

Sources: The Hacker News

FBI Reports Rising Losses from Account Takeover Fraud

The FBI reported more than 5,100 cases of account takeover fraud this year, leading to over $262 million in losses. Social engineering and phishing were the primary methods for accessing financial, payroll, and health accounts.

Sources: IC3

Ransomware Hits US Emergency Alert System

OnSolve's CodeRED emergency notification system suffered a ransomware attack, disrupting services across multiple US states. The incident exposed user data and prompted an investigation into the breach.

Sources: SecurityWeek

Threats

Dartmouth Confirms Data Theft After Clop Exploits Oracle Zero-Day

Clop ransomware exploited a zero-day in Oracle E-Business Suite, leading to data theft at Dartmouth College. Personal and financial records were exposed, and the stolen data was later published online.

ShadowV2 Botnet Targets IoT Devices Worldwide

The ShadowV2 botnet targeted vulnerabilities in Internet of Things devices during a significant AWS outage. The Mirai-derived malware infected devices globally, supporting distributed attacks.

Sources: Fortinet

Infrastructure & Exploits

Fluent Bit Flaws Enable File Manipulation and Remote Code Execution

Five vulnerabilities in the Fluent Bit telemetry agent exposed cloud environments to remote code execution and log manipulation. The flaws affected widely used cloud platforms and Kubernetes environments.

Sources: Oligo Security

Tor Introduces Counter Galois Onion Encryption

The Tor Project introduced Counter Galois Onion encryption, replacing the older tor1 algorithm. This upgrade improves forward secrecy and prevents tagging attacks, enhancing user security on the Tor network.

Sources: The Tor Project

Tools & Techniques

RomCom Deploys Mythic Agent Through SocGholish Infection Chain

The RomCom malware used the SocGholish framework to deliver its Mythic Agent loader to a US engineering firm, following the fake-update attack chain commonly associated with SocGholish.

North Korean Operation Expands npm Supply-Chain Intrusions

The North Korean-linked Contagious Interview campaign added nearly 200 malicious npm packages, distributing updated OtterCookie malware. These packages targeted blockchain and Web3 developers through typosquatted utilities.

Sources: Socket

Policy & Legal

WA Man Jailed for Airport ‘Evil Twin’ WiFi Attacks

A West Australian man was sentenced to seven years for operating an 'evil twin' WiFi network at airports to steal traveller credentials, accessing personal online accounts.

French Football Federation Reports Major Data Breach

The French Football Federation reported a data breach due to a compromised account, exposing personal details of millions of players. The breach prompted system remediation and notifications to authorities.

Weekly Coverage

Weekly Hot Topics:
Ransomware Shai-Hulud Gainsight Salesforce Dartmouth Injection Npm-Packages Fluent-Bit Repository Federation
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.