Latest Attack Trends (vibes-based assessments only)

What kind of attack patterns have you all been seeing or focusing on lately? I don’t mean what did CrowdStrike or Microsoft report in their threat assessments, I mean what kind of attacks have been catching your eye in the day-to-day of your work?

Lately I’ve been seeing a TON of people installing browser and IDE extensions that claim to be AI tools but are actually data stealers.

A list of what you’ve found would be deeply helpful.

I’m seeing just a ton of RMM initial access, followed by .NET of every flavor imaginable.

Encountered this one directly last week as well:

If only we had some sort of threat intelligence sharing network where I could safely and clearly share this intel in an easily digestible way :smiley:

I’ll spend some time in the next couple of days coming up with some IOCs and details though.

1 Like