XStore Documentation

May 30, 2025 – Cyber Briefing

👉 What are the latest cybersecurity alerts, incidents, and news?

OneDrive flaw risks full cloud exposure, fake AI apps spread ransomware, and EDDIESTEALER uses fake CAPTCHAs to steal data. State actor hits ScreenConnect, Ivanti breach impacts NHS, and Amalgamated Sugar leaks SSNs. Funnull tied to $200M crypto scams, Cerby raises $40M to secure identities, and EY says cybersecurity adds $36M in business value per project.

Listen to the full podcast


🚨 Cyber Alerts

1. OneDrive Flaw Gives Sites Full Data Access

Cybersecurity researchers have discovered a critical security flaw in Microsoft’s OneDrive File Picker that could allow websites to access a user’s entire cloud storage, not just selected files. The vulnerability stems from overly broad OAuth scopes and misleading consent prompts, with affected applications potentially including ChatGPT, Slack, Trello, and ClickUp. Compounding the risk, OAuth tokens are often stored insecurely in plaintext within browser session storage, and refresh tokens can grant ongoing data access. Microsoft has acknowledged the responsibly disclosed issue but has not yet released a fix, prompting interim recommendations like temporarily disabling the feature or enhancing token security.

2. Fake AI Apps Drop Ransomware And Malware

Cybercriminals are using counterfeit installers for popular AI tools like ChatGPT and InVideo AI to distribute various malicious threats, including the CyberLock and Lucky_Gh0$t ransomware families, as well as a new destructive malware named Numero. These campaigns often involve fake websites promoted through SEO poisoning, luring victims with deceptive offers before deploying ransomware that encrypts files and demands large payments, sometimes with false humanitarian claims. Other tactics include distributing the Yashma-based Lucky_Gh0$t ransomware via fake premium ChatGPT installers and using a counterfeit InVideo AI installer to continuously run the Numero malware, which renders Windows GUIs unusable.

3. EDDIESTEALER Uses Fake CAPTCHAs for Stealing

Cybersecurity researchers have uncovered a sophisticated malware campaign distributing a new Rust-based infostealer called EDDIESTEALER by using deceptive CAPTCHA verification pages as lures. This campaign tricks users into executing malicious code through a multi-stage delivery mechanism starting with compromised websites that copy a PowerShell command to the clipboard via fake reCAPTCHA interactions. EDDIESTEALER is designed to steal a wide range of sensitive data including credentials, cryptocurrency wallets, and browser information, even bypassing recent Chrome security features. The malware also employs advanced evasion techniques such as string and API obfuscation, sandbox detection, and self-deletion to avoid analysis and persist on victim systems.

For more alerts, click here!

💥 Cyber Incidents

For more incidents, click here!

Click to See Tools

📢 Cyber News

For more news, click here

📈Cyber Stocks

On May 29, 2025, Zscaler fell 1.00%, CrowdStrike Holdings dropped 2.14%, Palo Alto Networks declined 1.05%, Fortinet decreased 2.36%, and SentinelOne plunged 11.57%.

💡 Cyber Tip

📚 Cyber Book

Smart Home Hacking: Exploiting and Protecting IoT Environments by Zephyrion Stravos

Click to Check Events

Copyright © 2025 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

SubstackLinkedInTwitterRedditInstagramFacebookYouTube, and Medium.

Get Help

Online Scam Prevention & Recovery

Schedule a free consultation

A free 15-min cybersecurity consultation