XStore Documentation

May 21, 2025 – Cyber Briefing

👉 What’s trending in cybersecurity today?

Hazy Hawk exploits DNS misconfigs for scams, More_Eggs backdoor hits HR via fake job apps, and fake Kling AI sites spread crypto-stealing malware. Cellcom suffers voice/SMS outage, ransomware disrupts UK’s Peter Green Chilled, and Kettering Health cancels procedures after attack. Dutch expand cyber espionage law, NIST & CISA introduce LEV exploit metric, and teen admits PowerSchool breach affecting 70M records.

Listen to the full podcast


🚨 Cyber Alerts

1. Hazy Hawk Hijacks Cloud DNS For Web Scams

Threat actor Hazy Hawk hijacks abandoned cloud resources of major organizations using DNS CNAME misconfigurations. These reputable hijacked domains are then used for adtech scams and malware distribution not espionage. The attacks involve cloning sites luring users and funneling them via traffic distribution systems. Domain owners should remove old CNAME records while users must deny unknown website notification requests.

2. Venom Spiders More Eggs Malware Hits Hiring

The More_Eggs JavaScript backdoor by Venom Spider targets corporate HR departments via fake job application emails. Distributed as Malware-as-a-Service it uses malicious LNK files in ZIPs to deploy the backdoor. This polymorphic malware achieves persistence and uses living-off-the-land techniques abusing legitimate Windows files. Its final JavaScript payload employs advanced anti-analysis and server-side polymorphism to evade detection.ents. This update comes as Windows 10 nears its October 2025 end of support urging migration to Windows 11.

3. Fake Kling AI Sites Spread Malware To Users

A phishing campaign created fake Kling AI sites using Facebook ads to deliver malware to users. Victims were lured to spoofed pages and tricked into downloading malware disguised as AI generated media. The attackers used filename masquerading and anti analysis techniques deploying PureHVNC RAT as the payload. This RAT steals cryptocurrency wallet data with evidence suggesting possible links to Vietnamese threat actors.

For more alerts, click here!

💥 Cyber Incidents

For more incidents, click here!

Click to See Tools

📢 Cyber News

For more news, click here

📈Cyber Stocks

On May 20, 2025, Zscaler fell 0.25%, CrowdStrike Holdings dropped 0.47%, while Palo Alto Networks, Fortinet, and SentinelOne posted modest gains under 0.5%

💡 Cyber Tip

Click to Check Events

Copyright © 2025 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

SubstackLinkedInTwitterRedditInstagramFacebookYouTube, and Medium.

Get Help

Online Scam Prevention & Recovery

Schedule a free consultation

A free 15-min cybersecurity consultation