ThreatCluster
About Blog Help Contact
Login
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication

Threat Score:
82
The Hacker News
6 hours ago
Part of cluster #2296

Overview

Amazon on Friday said it flagged and disrupted what it described as an opportunistic watering hole campaign orchestrated by the Russia-linked APT29 actors as part of their intelligence gathering efforts. The campaign used "compromised websites to redirect visitors to malicious infrastructure designed to trick users into authorizing attacker-controlled devices through Microsoft's device code authentication flow," Amazon's Chief Information Security Officer CJ Mosessaid. APT29, also tracked as Blu...

Continue Reading on Original Site

Related Articles

5 articles
1

TransUnion Data Breach Impacts 4.4 Million

SecurityWeek • 7 hours ago

The credit reporting firm did not name the third-party application involved in the incident, only noting that it was used for its US consumer support operations.

Score
86
Read more
2

WhatsApp 0-Day Vulnerability Exploited to Hack Mac and iOS Users

Cybersecurity News • 2 hours ago

A sophisticated attack campaign has leveraged a previously unknown zero-day vulnerability in WhatsApp on Apple devices to target specific users, the company has confirmed. The vulnerability, now identified as CVE-2025-55177, was combined with a separate vulnerability in Apple’s operating systems to compromise devices and access user data. WhatsApp has since patched the vulnerability and has […]

Score
84
Read more
3
Deception in depth: Defending against sophisticated and evolving PRC-nexus espionage campaigns

Deception in depth: Defending against sophisticated and evolving PRC-nexus espionage campaigns

Brighttalk • 5 hours ago

Presented by Patrick Whitsell, Security Engineer, Google Threat Intelligence Group and Austin Larsen, Principal Threat Analyst, Google Threat Intelligence Group

Score
83
Read more
4

Google Confirms Workspace Accounts Also Hit in Salesforce–Salesloft Drift Data Theft Campaign

SecurityWeek • 7 hours ago

Google says the same OAuth token compromise that enabled Salesforce data theft also let hackers access a small number of Workspace accounts via the Salesloft Drift integration.

Score
83
Read more
5
Sweden scrambles after ransomware attack puts sensitive worker data at risk

Sweden scrambles after ransomware attack puts sensitive worker data at risk

Graham Cluley • 3 hours ago

Municipal government organisations across Sweden have found themselves impacted after a ransomware attack at a third-party software service supplier. Software firm Miljödata, which provides a significant proportion of Sweden's municipalities with "smart systems for a healthy work environment" handling such things as long-term sick leave and work-related injuries, is at the heart of the incident which has left around 200 of the country's organisations scrambling. Karlstad University, for instance

Score
82
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

ATTACK TYPES
Credential Harvesting
Phishing
Watering Hole Attack
COUNTRIES
Russia
COMPANIES
Amazon
Cloudflare
Google
Microsoft
AGENCIES
Foreign Intelligence Service
SVR
SECURITY VENDORS
Cloudflare
PLATFORMS
AWS
Microsoft 365
APT GROUPS
APT29
UNC2452
RANSOMWARE
Desktop
Evolution
MITRE ATT&CK
Phishing
T1003
T1053
T1059
T1190
MALWARE
Mispadu
ARTICLE INFORMATION
Article #15560
Published 6 hours ago
The Hacker News

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration