baseVISION TI – Game Over: Build Trust, Deploy Malware

In our latest Threat Intelligence report, baseVISION investigates a malware campaign that spreads through malicious game mods to compromise gamers and potentially corporate environments. The campaign leverages social engineering and the Stealit credential stealer to harvest sensitive data, showing how attackers exploit trusted communities and human behavior rather than technical Weiterlesen…

baseVISION TI – Hijacking Microsoft company accounts via TikTok open redirection abuse is still a thing

In our latest TI report, baseVISION uncovers a phishing campaign that abuses TikTok’s open redirect feature to hijack Microsoft credentials. The attackers use multi-stage redirect chains, IP-based cloaking, and Adversary-in-the-Middle (AiTM) phishing pages to bypass MFA and steal session tokens. We break down the full attack chain, indicators of compromise, Weiterlesen…

baseVISION TI – Click, Paste and Compromise: When User’s Trust Becomes Your Greatest Vulnerability

In a world where cyber threats evolve faster than ever, one thing remains constant: attackers are still betting on human error. Our latest report, “Click, Paste and Compromise: When User Trust Becomes Your Greatest Vulnerability,” dives deep into the rise of ClickFix—a social engineering technique that tricks users into executing malicious commands through Weiterlesen…

baseVISION TI – Patch, Exploit, Repeat: A Never-Ending Cycle for Windows Common Log File System Driver Vulnerabilities

Since 2024, multiple zero-day vulnerabilities in the Windows Common Log File System (CLFS) driver have been exploited by ransomware groups like RansomEXX and Play (Balloonfly). These Elevation of Privilege (EoP) flaws enabled SYSTEM-level access and were used in real-world attacks before patches were released. Microsoft issued fixes across several Patch Weiterlesen…

baseVISION TI – A Looming Menace and Escalating Threat to macOS users

Cybercriminals are increasingly targeting macOS with infostealers, exploiting the growing adoption of Mac devices in corporate environments. Our latest TI-Report uncovers: A 101% increase in macOS infostealer activity in 2024 How Atomic (AMOS) and Poseidon are spreading in Switzerland The tactics behind phishing, malicious downloads, and malvertising Key mitigations to Weiterlesen…

baseVISION TI – How threat actors are abusing Microsoft Teams to trick your employees, and what you can do about that

Cybercriminals are increasingly using Microsoft Teams to bypass security controls and target employees. Our first TI-Report uncovers: How groups like Black Basta use Teams as an attack vector The tactics behind phishing, vishing, and email bombing Key mitigations to protect your organization Get the full insights and Indicators of Compromise Weiterlesen…