Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato CTRL Insights: When Trust Becomes the Payload in a Fake Codex ClickFix Campaign

Attackers are using a fake Codex download experience to trick macOS users into pasting a malicious command into Terminal. This technique, known as ClickFix, relies on social engineering rather than a conventional malware download: the victim is persuaded to perform the execution step themselves. We analyzed sponsored search results leading to convincing Google Sites pages, a no-code website-building and hosting service provided by Google.

Shai-Hulud was the best thing to happen to supply chain security

npm launched Package Provenance in late 2022. For two years, adoption averaged 20-50 packages per week. Followed by Trusted Publishing in 2024. Blog posts were written. CISA advisories were issued. The line barely moved. Eventually Trusted Publishing with OIDC was made Generally Available in July 2025 Then Shai-Hulud hit. Weekly adoption jumped to 430 packages. In 18 months, cumulative adoption grew 3.4x.

PoshC2 Explained: Capabilities, Indicators, and Detection

PoshC2 version 6.0, an open-source command and control framework, is notable for its robust capabilities in managing compromised hosts. Accompanying its release, a comprehensive list of Indicators of Compromise (IoCs) and a dedicated GitHub repository have been provided. These resources are designed to assist cybersecurity teams in detecting PoshC2, especially when deployed with its default settings, which less sophisticated attackers often utilize.

Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business

Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.

They Paid Medusa's Ransom. A Second Medusa Actor Called and Demanded Half Again.

The FBI documented a Medusa ransomware victim who paid the ransom—and was then contacted by a second, separate Medusa actor, claiming the original negotiator had stolen the payment and demanding half the ransom again for the "true" decryptor. That's triple extortion, and it's the strongest argument in the whole CISA/FBI/MS-ISAC advisory (AA25-071A) against paying at all. There is no guarantee the extortion stops when the money moves.

Anatomy of an Agent Tesla BEC Attack: From Inbox to In-Memory Infostealer

Phishing is a form of social engineering that has evolved beyond simple lures into complex, multi-stage attacks exploiting trusted software, cloud identities and business platforms to bypass traditional security. Attackers leverage these campaigns to deliver trojans capable of stealing credentials and also establishing remote code execution, which might serve as a gateway for lateral movement.

Ransomware Has Changed and Your Defenses Need to Change With It

For years, ransomware was treated mostly as a malware problem. A user clicked something bad, files were encrypted, a ransom note appeared and everyone had a very bad week. That version still exists, of course, because cybercriminals love recycling old hits. But ransomware has changed significantly over the last year.

How to prevent ransomware damage: a 12-step checklist for IT teams and MSPs

No combination of controls guarantees that ransomware actors will never gain access or cause any impact. What the 12 controls below do is reduce the attacker's opportunities, accelerate containment and preserve the ability to restore operations without relying on ransom payment. Think of ransomware resilience as a continuous lifecycle rather than a fixed sequence: govern and identify, harden and prevent, detect and contain, roll back and recover, and improve and patch.

Ransomware protection for businesses and MSPs: the complete guide

Ransomware protection is a coordinated set of controls that reduces the likelihood of compromise, detects and contains malicious activity, protects recovery infrastructure and restores operations when an attack succeeds. It spans identity security, vulnerability and patch management, endpoint protection, EDR or XDR, incident response, targeted rollback, immutable backup and disaster recovery. No single control covers the complete ransomware lifecycle.