Outpost24’s KrakenLabs has exposed EncryptHub’s sophisticated malware operation and hinted at their operational errors. The cybercriminal group’s tactics range from using multi-layered PowerShell scripts to devise remote tools and employing trojanized versions of common apps, which sometimes use stolen credentials. EncryptHub’s use of third-party services for rapid malware deployment has also been identified. Their potential move towards commercialization necessitates multi-layered security strategies and continuous monitoring.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered