PCSDF

PCSDF "Protect your digital world with PCSDF! Get expert cyber security services & online courses. Learn how to stay safe online & defend against threats.

Explore our services & courses now! https://pcsdf.com/
đź”— All links in About section"

PCSDF CYBER WATCH | WEEKLY CYBERSECURITY BULLETINMassive Microsoft Patch Tuesday. Active FortiGate Exploitation. Critica...
14/09/2026

PCSDF CYBER WATCH | WEEKLY CYBERSECURITY BULLETIN

Massive Microsoft Patch Tuesday. Active FortiGate Exploitation. Critical RCEs. Zero-Days. AI-Driven Threats.

Cybersecurity is moving fast and this week’s threat landscape makes one thing clear:

Patch late. Get exposed.

Patch. Protect. Monitor. Respond.

Don't wait for an attack to discover that your systems were vulnerable.

Read the full weekly bulletin in the PCSDF Cyber Watch.

Pakistan Cyber Security & Digital Forensics (PCSDF)
Cyber Awareness | Digital Awareness | Safe Users | Secure Future

Cybersecurity | Cyber Security Pakistan | PCSDF | PCSDF Cyber Watch | Microsoft Patch Tuesday | September 2026 Patch Tuesday | Microsoft Security Updates | Zero Day Vulnerability | Zero Day Exploit | CVE 2026 | Microsoft Vulnerabilities | FortiGate Security | Fortinet Vulnerability | FortiOS Security | Firewall Security | RCE Vulnerability | Remote Code Ex*****on | Cyber Threats | Cyber Attack | Active Exploitation | Vulnerability Management | Patch Management | Network Security | Enterprise Security | Information Security | Cyber Threat Intelligence | AI Cybersecurity | AI Security | Data Security | Cloud Security | Digital Security Pakistan | Cyber Awareness Pakistan | Cybersecurity Awareness | Pakistan Cybersecurity | Digital Forensics | Cyber Resilience | SOC | CISO | IT Security | Security OperationsPakistan Cybersecurity | Cybersecurity Pakistan | Digital Security Pakistan | Cyber Awareness Pakistan | Pakistan Cyber Security | Cyber Crime Pakistan | IT Security Pakistan | Information Security Pakistan | Digital Forensics Pakistan | Cyber Resilience Pakistan

PASSKEY PHISHING: MFA CAN’T SAVE YOU IF YOU APPROVE THE ATTACKHackers are targeting Microsoft 365 users with fake passke...
11/09/2026

PASSKEY PHISHING: MFA CAN’T SAVE YOU IF YOU APPROVE THE ATTACK

Hackers are targeting Microsoft 365 users with fake passkey, MFA and SSO support scams and a simple approval can hand over access to your cloud account.

Attackers use Microsoft Graph to discover users, groups, applications, permissions, SharePoint sites, OneDrive files and mailboxes before downloading valuable data.

A password reset alone may not remove an attacker if active sessions, refresh tokens or unauthorized authentication methods remain.

Attackers may also register their own:
Authenticator app
Phone number
Software OTP method

Remember: MFA protects you only when you know what you're approving.

PCSDF | Cyber Awareness • Digital Safety • Safe Users • Secure Future

Microsoft 365 Security | Passkey Phishing | MFA Bypass | Microsoft Entra Security | Cloud Security | Identity Security | Device Code Phishing | Account Takeover | Session Hijacking | Microsoft Graph | SharePoint Security | OneDrive Security | Exchange Online Security | Phishing Awareness | Cybersecurity | Digital Safety | PCSDF

FAKE LINKEDIN JOBS ARE INFECTING DEVELOPERS WITH RATSCybercriminals are turning fake developer job interviews into malwa...
10/09/2026

FAKE LINKEDIN JOBS ARE INFECTING DEVELOPERS WITH RATS

Cybercriminals are turning fake developer job interviews into malware delivery systems. Recruiters on LinkedIn and employment platforms are reportedly sending “coding challenges” that secretly install NodeRabbit and PollCat—cross-platform Remote Access Trojans (RATs).

Developers in fintech, aviation & aerospace are among the reported victims.

📩 Fake recruiter → 🧑‍💻 Coding test → 📦 Malicious ZIP/project → 🦠 Hidden dependency → 🔓 RAT infection

A job offer can be a malware delivery channel.

Don't trust the recruiter. Verify the code.

PCSDF | Pakistan Cyber Security & Digital Forensics
Cyber Awareness • Digital Safety • Safe Users • Secure Future

Fake Job Scam | LinkedIn Security | Developer Security | Malware | RAT | Remote Access Trojan | NodeRabbit | PollCat | Supply Chain Security | npm Security | Node.js Security | Git Security | VS Code Security | Phishing | Social Engineering | Cybersecurity | Cyber Awareness | PCSDF

WEWORM: A 0-CLICK WORM THAT COULD SPREAD THROUGH WECHAT CALLSA security research demonstration called “WeWorm” reportedl...
09/09/2026

WEWORM: A 0-CLICK WORM THAT COULD SPREAD THROUGH WECHAT CALLS

A security research demonstration called “WeWorm” reportedly shows how a memory-corruption flaw in WeChat’s VoIP stack could allow an attacker to compromise accounts through an incoming call without the victim answering or tapping anything.

A messaging vulnerability can potentially become wormable turning trusted contacts into the next stage of propagation.

The research demonstrated cross-platform behavior involving iOS and Android, but the report describes this as a proof of concept, not evidence of a widespread active worm outbreak.

In a 0-click attack, there may be nothing for the victim to click — so patching becomes your first line of defense.

PCSDF | Pakistan Cyber Security & Digital Forensics
Cyber Awareness • Digital Safety • Secure Future

WeWorm | WeChat Security | Zero Click Attack | 0 Click Exploit | Mobile Security | iOS Security | Android Security | VoIP Security | Memory Corruption | Messaging App Security | Account Takeover | Cybersecurity | Cyber Awareness | Mobile Privacy | PCSDF

BIMBO BAKERIES DATA BREACH: ORACLE EBS ZERO-DAY EXPLOITEDBimbo Bakeries USA has confirmed that employee data was stolen ...
08/09/2026

BIMBO BAKERIES DATA BREACH: ORACLE EBS ZERO-DAY EXPLOITED

Bimbo Bakeries USA has confirmed that employee data was stolen after attackers exploited a zero-day vulnerability in Oracle E-Business Suite (EBS).

Attackers exploited a third-party vendor’s Oracle EBS environment and accessed files stored within the platform. The investigation later confirmed that one stolen file contained:

The incident is linked by its timeline and vendor details to CVE-2025-61882, a critical Oracle EBS vulnerability rated CVSS 9.8, which allowed unauthenticated remote code ex*****on on vulnerable systems.

Monitor your credit reports, consider fraud alerts, and be especially cautious of phishing messages using breach-related information.

Patch your systems. Audit your vendors. Protect the data they can access.

PCSDF | Pakistan Cyber Security & Digital Forensics
Cyber Awareness • Digital Safety • Secure Future

Bimbo Bakeries Data Breach | Oracle EBS Security | Oracle E Business Suite | CVE-2025-61882 | Zero Day Vulnerability | Data Breach | Clop Ransomware | Third Party Risk | Enterprise Security | Vulnerability Management | Patch Management | Data Protection | Cybersecurity | Cyber Awareness | PCSDF

AI AGENTS BREACH ENTERPRISE NETWORK IN UNDER 10 HOURSAI-powered cyberattacks are getting faster. A Unit 42 incident resp...
07/09/2026

AI AGENTS BREACH ENTERPRISE NETWORK IN UNDER 10 HOURS

AI-powered cyberattacks are getting faster. A Unit 42 incident response report describes an intrusion where a human attacker used frontier AI models + agentic AI frameworks to breach an enterprise network and obtain root-level credentials in under 10 hours a process that might take human red teams around two weeks.

The agents reportedly automated 50+ MITRE ATT&CK techniques through a continuous loop of monitor → evaluate → act → re-plan.

THE BIG LESSON
This wasn't about a zero-day.

AI simply made conventional attack techniques dramatically faster and more scalable.

That means organizations may no longer have hours or days to respond to an active intrusion.

PCSDF DEFENSE
Instantly revoke compromised credentials
Monitor unusual AI/API activity
Secure secrets and eliminate hard-coded credentials
Protect CI/CD pipelines with strong controls
Require multi-person review for infrastructure-as-code changes
Treat AI models and API keys as critical infrastructure
Prepare automated containment playbooks

When attackers operate at machine speed, defense must be ready to respond at machine speed.

PCSDF | Pakistan Cyber Security & Digital Forensics
Cyber Awareness • Digital Safety • Secure Future

AI Cybersecurity | AI Agents | Agentic AI | AI Powered Cyber Attack | Enterprise Security | Root Credentials | Cloud Security | CI/CD Security | DevSecOps | MITRE ATT&CK | Secrets Management | Terraform Security | Cyber Threats | Cyber Awareness | PCSDF

MICROSOFT 365 PHISHING: THE “EMPTY SENDER” TRICKAttackers have discovered a clever way to abuse Microsoft 365 Direct Sen...
05/09/2026

MICROSOFT 365 PHISHING: THE “EMPTY SENDER” TRICK

Attackers have discovered a clever way to abuse Microsoft 365 Direct Send: leaving the SMTP envelope sender empty while displaying a convincing internal From address.

Microsoft 365’s RejectDirectSend control checks the envelope sender domain. With MAIL FROM:, there is no domain to compare potentially allowing an unauthenticated message past that specific safeguard.

PCSDF DEFENSE
For organizations:
âś… Restrict Direct Send to approved IP addresses/devices
âś… Review allowed senders, domains & mail-flow exceptions
âś… Monitor empty envelope sender + internal-looking From combinations
âś… Investigate messages failing SPF, DKIM or DMARC that still reach users
âś… Don't rely on RejectDirectSend alone

For employees:
Unexpected payment or document request? Verify it through a known channel before clicking, replying, or paying.

The address you SEE isn't always the address that SENT the email.

PCSDF | Pakistan Cyber Security & Digital Forensics
Cyber Awareness • Digital Safety • Secure Future

Microsoft 365 Security | Email Security | Phishing Attack | Email Spoofing | Direct Send | Exchange Online | Business Email Compromise | SPF DKIM DMARC | Cyber Awareness | Microsoft Security | Email Fraud | Digital Safety | PCSDF

SCREENCONNECT ABUSE: HACKERS TURN REMOTE SUPPORT INTO A WORMHackers are abusing ScreenConnect remote-access software to ...
04/09/2026

SCREENCONNECT ABUSE: HACKERS TURN REMOTE SUPPORT INTO A WORM

Hackers are abusing ScreenConnect remote-access software to spread malware from one compromised Windows computer to other connected systems — without needing a new phishing lure for every victim.

How the attack starts?
Fake tech-support calls, phishing, or refund scams
Victim installs or allows an unauthorized remote-support client
Attackers gain remote access
Malicious clients use ScreenConnect file transfer to push staged scripts to connected systems
The infection can spread when systems reconnect

Organizations should:
âś… Restrict remote-management software installation
âś… Monitor unusual PowerShell & Windows Script Host activity
âś… Investigate unauthorized ScreenConnect clients
âś… Isolate suspected endpoints immediately
âś… Reimage compromised systems from trusted media

The danger isn't always the software — it's who controls it.

PCSDF | Pakistan Cyber Security & Digital Forensics
Cyber Awareness • Digital Safety • Secure Future

Tags:
ScreenConnect Security | Remote Access Malware | Windows Security | Cyber Attack | Malware | Remote Support Scam | Phishing | PowerShell Security | VBScript Malware | Cyber Awareness | Endpoint Security | Digital Safety | PCSDF

WhatsApp Android Lock-Screen BypassA WhatsApp video-call flaw could let someone with physical access to a locked Android...
03/09/2026

WhatsApp Android Lock-Screen Bypass

A WhatsApp video-call flaw could let someone with physical access to a locked Android phone open the device’s photo gallery without a PIN, password, or fingerprint.

Reported vulnerable: Google Pixel 6 Pro, Oppo K13
Reported protected: Samsung Galaxy S25 Ultra
iPhone: Not affected in the described attack

The flaw could be abused for privacy invasion or covert surveillance, especially when someone has temporary physical access to an unattended phone.

Until an official fix is available, restrict WhatsApp's Photos & Videos permission to limited/selected access rather than your entire gallery, and keep WhatsApp and Android updated.

Your phone may be locked — but your apps can still expose what’s inside.

PCSDF — Protect. Secure. Educate.

WhatsApp Security | Android Security | Mobile Privacy | Cybersecurity | Digital Safety | Cyber Awareness | Lock Screen Security | PCSDF

ATM JACKPOTTING: WHEN MALWARE MAKES ATMs SPIT OUT CASHFive Venezuelan nationals have pleaded guilty in the U.S. over att...
02/09/2026

ATM JACKPOTTING: WHEN MALWARE MAKES ATMs SPIT OUT CASH

Five Venezuelan nationals have pleaded guilty in the U.S. over attempted ATM jackpotting attacks.

Instead of stealing card details, attackers attempted to install malware inside ATMs and remotely force them to dispense cash.

How Jackpotting Works
Malware targets the ATM’s internal systems
Attackers gain remote control
The machine is instructed to release cash
Security alarms & surveillance can expose the attack

The FBI reported 700+ jackpotting incidents in 2025, with losses exceeding $20 million.

ATM security isn't just about the card — it's about protecting the machine itself.

PCSDF — Cyber Awareness | Digital Awareness | Safe Users | Secure Future

Address

Karachi
05444

Alerts

Be the first to know and let us send you an email when PCSDF posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share