Christoffer S.<p>Targeted attacks against MSP:s, NATO and Ukraine. Two stories from Sophos and Microsoft published today.</p><p>The MSP-attack involved abusing vulnerabilities in SimpleHelp chaining a number of vulnerabilities. A little bit of a more advanced attack IMHO.</p><p>Then you have the NATO and Ukraine attacks as detailed by Microsoft, involving password spraying and likely bought credentials from criminal ecosystems.</p><p>Funny. Ransomware attackers are more advanced than APTs 🙂 </p><p>References:<br><a href="https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.sophos.com/en-us/2025/05/</span><span class="invisible">27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/</span></a></p><p><a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">microsoft.com/en-us/security/b</span><span class="invisible">log/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThreatIntel</span></a> <a href="https://swecyb.com/tags/PasswordSpray" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PasswordSpray</span></a> <a href="https://swecyb.com/tags/Password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Password</span></a> <a href="https://swecyb.com/tags/StolenCredentials" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StolenCredentials</span></a> <a href="https://swecyb.com/tags/APT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APT</span></a> <a href="https://swecyb.com/tags/LAUNDRYBEAR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LAUNDRYBEAR</span></a> <a href="https://swecyb.com/tags/VoidBlizzard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VoidBlizzard</span></a> <a href="https://swecyb.com/tags/Russia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Russia</span></a> <a href="https://swecyb.com/tags/NATO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NATO</span></a> <a href="https://swecyb.com/tags/Ukraine" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ukraine</span></a> <a href="https://swecyb.com/tags/SimpleHelp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SimpleHelp</span></a> <a href="https://swecyb.com/tags/Vulnerabilities" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vulnerabilities</span></a> <a href="https://swecyb.com/tags/Vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vulnerability</span></a></p>