FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

BYOEDR: Weaponizing SentinelOne to Bypass Windows Protected Process Light PPL

The "Bring Your Own EDR" (BYOEDR) technique evolves the "Bring Your Own Vulnerable Driver" (BYOVD) vector by weaponizing legitimate, digitally signed components from trusted security vendors, specifically SentinelOne. Because EDR drivers possess high-level system privileges to monitor activity, they can be leveraged to manipulate kernel-mode process protection flags. By flipping PPL bits, attackers strip the "Protected" status from critical system processes such as lsass.exe. This bypasses Windows Protected Process Light (PPL) protections, facilitating unauthorized memory reads, credential dumping, and process injection, ultimately enabling full administrative takeover and lateral movement through stolen high-privileged credentials.

Midnight Blizzard and the 'CaptiveCrunch' Campaign Targeting Microsoft 365 via Hotel WiFi

The "CaptiveCrunch" campaign, attributed to the Russian state-sponsored actor Storm-2945 (a Midnight Blizzard sub-cluster), targets global travelers by compromising hospitality WiFi gateways. The attack utilizes DNS hijacking and poisoning to redirect users from legitimate captive portals to malicious, Microsoft-themed phishing sites. This redirection facilitates two primary objectives: the theft of Microsoft 365 credentials through OAuth token interception and the deployment of the CornFlake Remote Access Trojan (RAT). CornFlake enables persistent endpoint surveillance, including keystroke logging and audio/visual interception. This sophisticated operation, active since May 2026, represents a high-severity threat to enterprise users traveling internationally.

The CINEMAGOAL Evolution: From Piracy App to Credential Harvesting Engine

Italian law enforcement, including the Polizia Postale and Guardia di Finanza, has successfully disrupted the CINEMAGOAL ecosystem, a sophisticated mobile operation that evolved from a simple piracy application into a high-scale credential-harvesting platform. By leveraging malicious mobile binaries (APK/IPA) to perform session hijacking and Man-in-the-Middle (MitM) attacks, the app exfiltrated authentication tokens and session codes from legitimate users of major streaming services like Netflix, Disney+, and Spotify. This shift from content redistribution to active identity theft poses a significant threat to the streaming economy, necessitating enhanced scrutiny of mobile application behavior and session management protocols to prevent large-scale account takeovers.


LINK COPIED TO CLIPBOARD