Danny Palmer
Cybersecurity writer.
A surge in phishing attacks which exploit email routing settings and misconfigured domain spoofing protections to spoof domains and make malicious emails appear as if they were sent from within the organization are targeting Microsoft 365 accounts.
Microsoft Threat Intelligence has warned that the attacks are themed around phoney messages from HR departments and IT security teams and are being deployed in attempts to steal login credentials.
While the attack vector isn’t new, Microsoft said there’s been a significant rise in attacks deploying these techniques since May 2025 and they’re commonly used in conjunction with phishing-as-a-service kits like Typhoon2FA.
(By me for Infosecurity Mag)
https://www.infosecurity-magazine.com/news/phishing-exploits-misconfigured/
Meet the Spy
The Microsoft Digital Crimes Unit has just announced the take down and seizure of infrastructure used by RedVDS, which has been used to conduct phishing and BEC attacks which have cost victims millions.
One thing I find particularly interesting about this announcement is how Microsoft praises the victims of some of these campaigns for coming forward: therefore helping the investigation and disruption of the cybercriminal infrastructure.
“Their cooperation made this action possible and will help protect future victims. Falling victim to a scam should never carry stigma... Every report helps dismantle networks like RedVDS and brings us closer to stopping cybercrime at scale."
Some of the most well-received features I've ever written have been interviews with CISOs at organisations which have fallen victim to cybercrime. I understand why people don't want to talk about it: but talking about those lessons learns can really help others!
https://www.infosecurity-magazine.com/news/criminal-subscription-service/
The National Cyber Security Centre has issued an alert to critical national infrastructure providers, urging them to act now to protect against “severe” cyber threats.
The alert comes following coordinated cyber-attacks which targeted Poland’s energy infrastructure with malware in December.
Jonathon Ellison OBE has urged CNI operators that they must act now to ensure they can respond to any similar campaigns targeting the UK.
“Cyber-attacks disrupting everyday essential services may sound far-fetched, but we know it’s not,” he said.
https://www.infosecurity-magazine.com/news/ncsc-warning-severe-cyberattacks/
Well, I suppose it's time for one of those posts looking back at the working year, isn't it? Put simply, did I expect 2025 to be the year I went freelance? In all honesty, probably not, but circumstances pushed me down that path.
(I got laid off by the company I worked for not long after they were bought by a private equity firm...)
But, I think even though I'm really still making my first tentative steps at making things work for myself and as my own, for want of a better phrase, 'brand', it can count as successful so far, I think?
At a fundamental level, working for myself is doing more than enough to keep a roof over my head and pay the bills, so that's good!
On a more professional level, I'm so pleased with all the new publications and podcasts I've been able to work with this year - while it's also been satisfying to provide editorial consultation for companies and agencies behind the scenes.
(Turns out you don't spent 15 years working as a journalist without learning a thing or two on what makes good writing and narrative storytelling, huh?)
But it hasn't been easy. I didn't anticipate how quiet opportunities would get in the summer which caused a bit of a panic, but I know now for next year to organise the budgeting so that the August lull doesn't have me worrying about paying the bills. (Or maybe I should just go away on holiday? Or figure out a way of getting to that big cybersecurity conference in the US that month without destroying my bank balance...)
But overall, despite the challenging start to the year, I'm pleased with how things have gone. And not to be all vague and mysterious, but I've got a very interesting opportunity on the horizon, but that can wait until 2026.
Thank you to everyone who has commissioned me, read my articles, shared my posts and just generally supported me this year, it's really, really, appreciated. Have a good Christmas break!
A new Cyber Unit to coordinate responses to cyber threats across the public sector and an ambassador scheme to help encourage secure software development have been announced as part of the UK government’s new Cyber Action plan.
While the plan has broadly been welcomed by cybersecurity leaders – although there concerns that the budget of £210m isn’t enough to have a significant impact.
(Also, I'm Deputy Editor of Infosecurity Magazine now...)
https://www.infosecurity-magazine.com/news/uk-launches-new-cyber-unit/
Well chuffed that @gcluley@mastodon.green invited me back to guest on Smashing Security.
Come for our discussion about research from Black Hat Europe, stay for me yammering on about playing Tomb Raider Remastered and what makes it different to the original I played as a kid back in the 90s - most important for me being, that unlike the original, this version didn't just crash to a black screen of death in the middle. Very serious business.
https://open.spotify.com/episode/3JQ4Ul21LNU2W9kzxQN4xp?si=ef9bebcef155429b
Are cybercriminals shifting towards cutting out the middle-man in ransomware attacks? That is, why bother encrypting a whole network when you can just steal the data and demand payment from that alone?
An increasing number of cybercriminals are relying on data theft alone to extort ransom payments out of victims, a new research paper by Symantec has warned.
Analysis of data leak sites suggests that there were almost 1500 incidents that relied on data theft alone for extortion attacks in 2025. The figure for 2024 was only 28.
“While attacks involving encrypting ransomware remain as prevalent as ever and still pose a threat, the advent of new types of encryptionless attacks adds another degree of risk."
https://www.infosecurity-magazine.com/news/hackers-shun-encryption-in-favour/
Analysis by Symantec and Carbon Black Threat Hunter Team has concluded that the cybercriminals behind PureRAT are using AI tools to write scripts and code. One of the reasons for this conclusion is that sections of the code powering PureRAT contain emojis.
“Many AIs have a tendency to insert emojis in code comments because they’ve been trained using data from social platforms such as Reddit,” researchers said.
(Write-up by me for Infosecurity Magazine)
https://www.infosecurity-magazine.com/news/emojis-in-purerats-code/
So, about VoidLink, the sophisticated Linux malware which came to light last week. Researchers have spent more time examining it and they've concluded that rather than being developed by a crack team of cyber criminals... it was developed largely by AI.
(Helped along with prompts from one person.)
"VoidLink demonstrates that the long-awaited era of sophisticated AI-generated malware has likely begun,” said the Check Point Software Research.
“In the hands of individual experienced threat actors or malware developers, AI can build sophisticated, stealthy and stable malware frameworks that resemble those created by sophisticated and experienced threat groups.”
Write-up by me for Infosecurity Magazine.
(I only had to self-edit myself twice after I typed VoidLink as Voidsent - a type of monster from Final Fantasy XIV...)
https://www.infosecurity-magazine.com/news/voidlink-linux-malware-built-using/
A quick one from me on what Trellix describes as surge in browser-in-the-browser attacks to steal Facebook passwords.
No, I'm not quite sure why one of the phishing lures claims that YOU have infringed copyright by sharing the music of *checks paper* Lewis Capaldi either.
https://www.infosecurity-magazine.com/news/phishing-scams-exploit-browser/
Phishing attacks and cyber fraud have overtaken ransomware as the top cybersecurity concern of business leaders, according to the World Economic Forum’s Global Cybersecurity Outlook for 2026. 👀
“As cyber risks become more interconnected and consequential, cyber-enabled fraud has emerged as one of the most disruptive forces in the digital economy, undermining trust, distorting markets and directly affecting people’s lives,” said Jeremy Jurgens, managing director, World Economic Forum.
(Write-up by me)
https://www.infosecurity-magazine.com/news/fraud-overtakes-ransomware-as-top/
The rising use of generative AI tools like LLMs in the workplace is increasing the risk of cyber-security violations as organizations struggle to keep tabs on how employees are using them - especially if they're using their personal accounts. (By me)
https://www.infosecurity-magazine.com/news/personal-llm-accounts-drive-shadow/
This data breach is from before 2021, but I can't help but wonder what happens the next time there's inevitably some sort of breach and it involves people's identifiable information because government legislation means you need to verify your identity to access these sites now...
Big thanks to SDxCentral for commissioning two features from me for their new Cybersecurity Supplement!
In the first piece - 𝗭𝗲𝗿𝗼 𝗧𝗿𝘂𝘀𝘁: 𝗙𝗿𝗼𝗺 𝗕𝘂𝘇𝘇𝘄𝗼𝗿𝗱 𝘁𝗼 𝗕𝗮𝘀𝗲𝗹𝗶𝗻𝗲 - I examine the current status of Zero Trust and why even many of those organizations which are implementing it are yet to roll it out across their entire network.
In the second piece - 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗮𝘁 𝗠𝗮𝗰𝗵𝗶𝗻𝗲 𝗦𝗽𝗲𝗲𝗱 - I take a look at the advantages and challenges around using agentic AI in the SOC to defend networks against ever-evolving cyber threats.
You can check out the full SDxCentral Cybersecurity Supplement here. 👇
It's behind a reg wall, but I'd say it's worth signing up to read my work, if I do say so myself.😅
https://www.sdxcentral.com/resources/the-cybersecurity-supplement/
