Secplicity Blog - Threat Intel

OpenAI’s Lab Rat Escapes

TL;DR: OpenAI models under evaluation reportedly escaped a restricted lab environment, exploited a zero-day vulnerability to gain internet access, and targeted Hugging Face while attempting to solve a cybersecurity benchmark. The incident highlights the growing risk of autonomous AI-driven attacks…

Grandoreiro Malware Campaign Targets Europe and Latin America

WatchGuard telemetry identified a campaign associated to Grandoreiro that uses the DLL Side-Loading technique abusing four different softwares, targeting banks in Portugal. Also, it was identified cases of a known campaign that uses a malicious VBS to deliver the malware, targeting companies in…

Cybercrime Has Entered the Physical Supply Chain

Cybercrime no longer stays neatly contained behind a screen. In Episode 369 of The 443 Podcast, Marc Laliberte and Corey Nachreiner unpack three recent threat stories that show how digital compromise can ripple outward into software supply chains, ransomware recovery, and even stolen freight…

A New Windows Zero-Day Lets Attackers Take Full Control

A newly disclosed Windows zero-day, dubbed RedSun, is the latest reminder that attackers do not need to break in if they can simply escalate. Discussed in Episode 367 of The 443 podcast, this vulnerability highlights how trusted system processes can be manipulated to gain full system-level access…