• Between August and October 2025, a sophisticated phishing campaign has emerged targeting Colombian and Spanish-speaking users through deceptive emails masquerading as official communications from Colombia’s Attorney General’s office.

    The campaign employs a carefully crafted social engineering strategy, luring victims with notifications about supposed lawsuits processed through labor courts.

    This marks a significant shift in attack tactics as threat actors expand PureHVNC deployment into regions previously untouched by this malware.

    Example email (Source – IBM)

    The attack chain begins when recipients encounter an email containing an SVG attachment that leads them through Google Drive, where clicking on the document triggers an automatic download of a password-protected ZIP archive.

    7 ZIP archive contents (Source – IBM)

    Inside this archive lies a renamed executable disguised with a judiciary-themed filename “02 BOLETA FISCAL.exe”, which is actually a legitimate javaw.exe file repurposed for malicious DLL side-loading.

    This initial stage deploys Hijackloader, an increasingly prevalent loader previously observed delivering RemcosRAT to CrowdStrike customers.

    IBM X-Force analysts identified this campaign as particularly noteworthy because it represents the first observed instance of PureHVNC being delivered to Spanish-speaking users through such coordinated efforts.

    The malware, typically sold on dark web forums and Telegram channels by PureCoder, demonstrates advanced evasion capabilities that separate it from standard remote access trojans.

    Infection Mechanism and Persistence

    The malware operates through a sophisticated multi-stage infection process designed to evade security detection.

    The attack exploits DLL side-loading, where the malicious JLI.dll hijacks Windows’ library loading procedures to inject the second-stage payload MSTH7EN.dll directly into memory using the LoadLibraryW() API function.

    This shellcode eventually loads into vssapi.dll through memory manipulation techniques involving VirtualProtect() calls that modify the .text section to PAGE_EXECUTE_READWRITE permissions.

    The third-stage payload contains encrypted configuration data including process name hashes that trigger execution delays when security software is detected.

    When activated, the malware queries running processes and uses NtDelayExecution() API calls to pause execution, demonstrating awareness of its operational environment.

    The complete infection chain ultimately establishes communication with the command server sofiavergara[.]duckdns[.]org, granting attackers complete remote access over compromised systems.

    This campaign highlights how judicial and legal themes continue serving as effective social engineering vectors, particularly against government and corporate employees in Latin America.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Threat Actors Weaponizes Judicial Documents to Deliver PureHVNC RAT appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity experts at ANY.RUN recently unveiled alarming trends in how attackers are exploiting everyday technologies to bypass security operations centers (SOCs).

    They dissected tactics like QR code phishing, ClickFix social engineering, and Living Off the Land Binaries (LOLBins), showing how these methods evade traditional defenses.

    As threats grow more sophisticated, SOC teams face mounting pressure to adapt, with low detection rates risking severe breaches. Drawing from analyses of real-world samples, the session emphasized interactive tools and real-time intelligence as vital countermeasures.

    ClickFix Attacks: Mastering Human Deception

    ClickFix attacks stand out for their reliance on user interaction, turning routine verifications into malware gateways. Attackers send phishing emails mimicking trusted sites, like booking platforms, complete with fake CAPTCHAs.

    Once a victim clicks, a malicious PowerShell script hijacks the clipboard unnoticed, prompting the user to paste and execute it via a system dialog.

    This multi-stage ploy thrives on deception: double spoofing creates convincing replicas, while manual steps foil automated scanners.

    Sandbox analyses reveal how execution deploys stealers like Lumma or AsyncRAT, plus ransomware, establishing persistence through startup files.

    Traditional tools falter at CAPTCHAs, but interactive sandboxes simulate human actions, exposing the full chain from initial click to payload delivery in seconds.

    Without such capabilities, SOCs miss threats that blend seamlessly into user workflows, leading to credential theft and system compromise.

    PhishKit Attacks: QR Codes as Stealth Vectors

    Phishing kits, or phishkits, have evolved into dark web staples, empowering novices to launch pro-level campaigns against giants like Microsoft and Google.

    The latest twist integrates QR codes into PDF attachments disguised as DocuSign docs, directing scans to mobile devices where phishing cues hide on small screens.

    These kits incorporate AI-generated lures, multi-stage checks, and CAPTCHAs like Cloudflare Turnstile, culminating in fake login pages for credential harvesting.

    ANY.RUN’s automated detonation extracts QR links, solves challenges, and traces the kill chain, revealing ties to groups like Storm-1747.

    Many defenses overlook QR content, allowing evasion, but advanced sandboxes handle this autonomously, cutting Tier 1 workloads by 20%. As phishkits proliferate, targeting regions via localized lures, SOCs must prioritize QR scanning to curb widespread campaigns.

    LOLBins: Weaponizing Trusted Tools

    LOLBins exploit Windows’ own utilities, PowerShell, mshta.exe, and cmd.exe to mask malice as routine operations. A phishing .lnk file might invoke mshta via PowerShell to fetch payloads from remote servers, downloading decoy PDFs to obscure the real stealer, like DeerStealer.

    This “living off the land” approach evades whitelists and antivirus software by mimicking admin tasks, leaving faint forensic traces.

    Behavioral analysis in sandboxes uncovers connections to C2 servers and persistence mechanisms, distinguishing abuse from legitimacy.

    Without context from global investigations, alerts trigger false positives. Threat intelligence feeds, pulling fresh IOCs from thousands of sessions, enable real-time blocking, slashing response times.

    The tactics employed by ClickFix, including interactivity, QR obfuscation, and LOLBin stealth, highlight the limitations of relying solely on automation.

    ANY.RUN’s solutions, which combine interactive analysis with shared intelligence, enhance detection rates by 88% in under a minute and reduce mean time to resolve (MTTR) by 21 minutes.

    Security Operations Centers (SOCs) that implement these solutions report a 30% decrease in escalations and a tripling of efficiency, thereby strengthening their defenses against an increasingly relentless adversary landscape.

    Enhance your SOC Performance With Interactive Sandbox Threat Intelligence Lookup and Feeds => Try Now

    The post Emerging Cyber Threats Featuring QR Codes ClickFix and LOLBins Challenging SOC Defenses appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly discovered ransomware-as-a-service platform called Gentlemen’s RaaS has recently emerged on underground hacking forums, offering threat actors a sophisticated cross-platform attack capability.

    The service, advertised by the threat actor known as zeta88, represents a significant expansion in ransomware delivery models, targeting critical infrastructure across multiple operating systems.

    This development signals an intensified threat landscape where organized cybercriminals are offering affiliate-based ransomware operations to lower-level attackers, democratizing access to enterprise-level encryption malware.

    The service leverages a compelling business model that allocates ninety percent of ransom proceeds to affiliates while retaining just ten percent for the operator.

    This generous revenue-sharing arrangement has proven highly attractive to potential partners within the cybercriminal ecosystem.

    By offering this financial incentive structure, the platform encourages widespread adoption and rapid deployment across global organizations.

    The architecture reflects a deliberate strategy to scale ransomware operations efficiently while maintaining operational control through centralized decryption infrastructure.

    KrakenLabs researchers identified the malware following detailed analysis of its promotional materials circulating across hacking forums.

    The platform exhibits sophisticated technical construction with separate lockers designed for specific platforms, indicating purpose-built infrastructure rather than generic variants.

    Lateral movement

    The most technically noteworthy aspect involves the malware’s persistence and lateral movement mechanisms.

    Gentlemen’s RaaS deploys a Go-based locker targeting Windows, Linux, NAS, and BSD systems, while employing a separate C-coded ESXi locker approximately thirty-two kilobytes in size.

    The encryption implementation utilizes XChaCha20 combined with Curve25519 cryptography, with per-file ephemeral keys providing granular encryption architecture.

    Particularly concerning is the self-propagation capability through WMI, WMIC, SCHTASKS, SC, and PowerShell Remoting commands, enabling rapid network traversal.

    The malware establishes persistence via schtasks registry modifications and run-on-boot routines, ensuring survival across system restarts and administrative interventions.

    Additionally, the platform supports network share discovery and automated encryption, allowing the ransomware to identify and compromise adjacent systems seamlessly.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Gentlemen’s RaaS Advertised on Hacking Forums Targeting Windows, Linux and ESXi Systems appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A massive 4TB SQL Server backup file belonging to global accounting giant Ernst & Young (EY) was discovered publicly accessible on Microsoft Azure.

    The exposure, uncovered by cybersecurity firm Neo Security during a routine asset mapping exercise, highlights how even well-resourced organizations can inadvertently leave sensitive data vulnerable to the internet’s automated scanners.

    Neo Security’s lead researcher discovered the file while examining passive network traffic with low-level tools.

    A simple HEAD request meant to fetch metadata without downloading content revealed the staggering size: 4 terabytes of data, equivalent to millions of documents or an entire library’s worth of information.

    The file’s naming convention screamed SQL Server backup (.BAK format), which typically contains full database dumps, including schemas, user data, and, crucially, embedded secrets such as API keys, credentials, and authentication tokens.

    Discovery and Verification Process

    Initial searches on the Azure Blob Storage yielded no immediate ownership clues, but deeper probes uncovered merger documents in a European language, translated with tools like DeepL, pointing to a 2020 acquisition.

    A pivotal DNS SOA record lookup tied the domain to ey.com, confirming EY’s involvement. To avoid any legal pitfalls, the team downloaded only the file’s first 1,000 bytes, revealing an unmistakable “magic bytes” signature for an unencrypted SQL Server backup, Neo Security learns.

    This was not a theoretical risk. Neo Security relied on real-world incident response experience, recalling a fintech breach that resulted from the brief exposure of a similar .BAK file for just five minutes.

    In that case, attackers exploited the brief window to exfiltrate personally identifiable information and credentials, leading to ransomware and the company’s collapse.

    With today’s botnets scanning the entire IPv4 address space in minutes, such exposures invite inevitable compromise. Neo Security halted further probing and pursued responsible disclosure over a weekend, eventually connecting with EY’s CSIRT via LinkedIn outreach after 15 attempts.

    EY responded swiftly and professionally, triaging and remediating the issue within a week, with no defensiveness, just effective action.

    The firm deserves credit for its mature handling, a rarity in an industry often marred by denial or delays. Yet the incident underscores systemic cloud vulnerabilities. Azure’s convenience in exporting databases can lead to ACL (Access Control List) errors, flipping private storage public with one misclick.

    For EY a Big Four firm auditing billion-dollar deals and holding market-moving financial data this lapse raises questions about oversight in fast-paced infrastructures.

    Experts warn that automated adversarial scanning means exposures aren’t “if” but “how many” actors notice.

    As cloud complexity grows, continuous mapping and visibility tools become essential to outpace threats, ensuring organizations discover their own leaks first.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post EY Data Leak – Massive 4TB SQL Server Backup Exposed Publicly on Microsoft Azure appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fraudulent investment platforms impersonating cryptocurrency and forex exchanges have emerged as the predominant method used by financially motivated cybercriminals to defraud victims across Asia and beyond.

    These sophisticated scam operations deploy advanced social engineering tactics to manipulate victims into transferring funds to attacker-controlled systems that masquerade as legitimate trading platforms.

    The threat landscape has evolved significantly from isolated cybercriminal activities to highly organized, cross-border operations with structured hierarchies and specialized roles.

    These schemes no longer target single geographic regions but instead operate internationally, utilizing complex infrastructure networks to sustain prolonged campaigns against unsuspecting investors.

    Recent law enforcement actions have highlighted the massive scale of these operations.

    In August 2025, Vietnamese authorities arrested 20 individuals connected to the billion-dollar Paynet Coin crypto scam, charging them with multi-level marketing violations and asset misappropriation.

    Victim manipulation flow from initial contact to fund extraction (Source – Group-IB)

    While this particular case represents just one facet of the broader threat landscape, it demonstrates the transnational reach and financial impact of modern investment fraud campaigns.

    Group-IB analysts identified a sophisticated victim manipulation framework that consistently appears across these fraudulent platforms.

    The research reveals that threat actors employ a multi-stage approach beginning with initial contact through social media platforms including Zalo, Facebook, TikTok, and messaging applications such as Telegram and WhatsApp.

    Scammers present themselves as successful investors or financial experts, using carefully crafted personas and forged credentials to establish trust with potential victims.

    The deception extends beyond simple impersonation tactics. When victims display hesitation or skepticism, operators introduce additional “bait” personas, including fake fellow investors, friends, or support staff who engage directly with targets to simulate genuine platform activity and reinforce the illusion of legitimacy.

    Advanced Infrastructure and Technical Sophistication

    These fraudulent platforms operate on shared backend infrastructure rather than isolated throwaway websites.

    The technical analysis reveals recurring API endpoints, SSL certificate reuse, and common administrative interfaces across multiple scam domains.

    Group-IB researchers noted cross-domain HTTP requests during controlled browsing sessions, with captured traffic showing requests to API subdomains using paths such as /user/info, /index/tickers, and /index/init.

    The infrastructure investigation uncovered exposed administrative panels accessible through subdomains following predictable naming patterns like adn.<domain> and api.<domain>.

    These control interfaces, often presented in Simplified Chinese, feature standard login fields and integration with popular Chinese platforms including Tencent QQ, WeChat, and Weibo.

    Source code analysis revealed the use of lightweight UI frameworks such as Layui, commonly employed in dashboard and administrative panel development.

    An organization chart depicting a Multi-Actor Fraud Network (Source – Group-IB)

    Chat-based onboarding systems represent another layer of technical sophistication. Instead of direct registration forms, many platforms load chatbot interfaces powered by third-party services like Meiqia.

    These chatbots serve multiple functions including access control, trust reinforcement, and payment instruction delivery.

    When victims select deposit functions, the platform redirects them to chatbot windows that provide specific bank account details or cryptocurrency wallet addresses.

    Backend payload analysis of these chatbot systems exposes configuration data, registered email addresses, and system-level parameters.

    HTTP request traces show API calls to external chatbot infrastructure, while payload inspection reveals Chinese-language system messages and queue notifications not visible in the frontend interface.

    The technical infrastructure also includes auxiliary components such as chat simulation tools designed to fabricate convincing conversation screenshots.

    These web-based messaging simulators mimic popular platforms and include configurable message metadata, timestamps, and delivery status indicators to create fabricated social proof for victim persuasion.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft experienced a widespread service outage on Wednesday, October 29, 2025, affecting its Azure cloud platform and Microsoft 365 suite, leaving thousands of users unable to access critical business services. The disruption, which began around 16:00 UTC (approximately 9:30 PM IST), was attributed to Domain Name System (DNS) configuration issues that crippled connectivity across Microsoft’s […]

    The post Microsoft DNS Outage Disrupts Azure and Microsoft 365 Services Worldwide appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft reported a DNS-related outage on October 29, 2025, affecting access to key services, including Microsoft Azure and Microsoft 365.

    The issue surfaced around 9:37 PM GMT+5:30, leaving users unable to reach the Microsoft 365 admin center and experiencing widespread delays in other applications.

    Businesses relying on these platforms for email, collaboration tools, and cloud computing faced operational hurdles, highlighting the fragility of global DNS infrastructure.

    The outage stemmed from connectivity problems in portions of Microsoft’s internal infrastructure. Initial reports indicated that DNS resolution failures prevented proper routing of traffic, impacting authentication and service endpoints.

    Administrators attempting to manage Office 365 tenants encountered error messages, while end-users saw sluggish performance in apps like Outlook, Teams, and SharePoint.

    Azure Virtual Machines and storage services also reported intermittent unavailability, potentially stalling development workflows and data processing tasks.

    Microsoft DNS Outage

    The disruption spanned multiple regions, with complaints flooding social media and tech forums from North America, Europe, and Asia. Small enterprises and large corporations alike voiced frustrations, as the outage coincided with end-of-month reporting deadlines for many.

    Cybersecurity experts noted that while no data breaches were reported, the event underscored vulnerabilities in dependency chains where a single DNS hiccup can cascade across interconnected services.

    Microsoft’s status page confirmed the scope included admin portals and core productivity tools, but spared some ancillary features like OneDrive file syncing in isolated cases.

    Microsoft’s engineering teams swiftly identified the root cause as unhealthy network and hosting infrastructure. By 9:51 PM GMT+5:30, they began unblocking affected systems and redistributing traffic to mitigate the issue.

    A subsequent update at 9:58 PM detailed a deeper review of infrastructure health, followed by rerouting to alternate healthy paths announced at 10:06 PM.

    As of 10:37 PM IST, recovery efforts continued, with Microsoft promising full restoration soon. The company emphasized that this was an isolated internal issue, not a cyberattack, and advised users to monitor the Azure status page for real-time updates.

    This incident adds to a string of cloud reliability challenges in 2025, prompting calls for enhanced redundancy in DNS systems. While downtime appears limited to under two hours so far, it serves as a reminder of the critical role DNS plays in modern cloud computing.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft DNS Outage Disrupts Azure and Microsoft 365 Services Worldwide appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A groundbreaking security vulnerability has emerged that fundamentally challenges the integrity of modern trusted execution environments across Intel and AMD server platforms.

    Researchers from Georgia Tech, Purdue University, and van Schaik LLC have unveiled TEE.fail, a sophisticated attack methodology that exploits weaknesses in DDR5 memory bus interposition to extract sensitive cryptographic keys from supposedly secure environments.

    This discovery represents the first successful demonstration of memory bus interposition attacks on DDR5-based systems, affecting Intel SGX, TDX, and AMD SEV-SNP implementations running on the latest server hardware.

    The attack leverages a critical shift in trusted execution environment design, where manufacturers moved from client-oriented hardware with robust integrity protections to server-grade implementations using deterministic AES-XTS memory encryption.

    Unlike earlier SGX implementations that utilized Merkle tree-based integrity verification and replay protections, current server TEEs prioritize performance and scalability over security guarantees.

    This trade-off enables support for terabytes of protected memory while reducing latency, but introduces vulnerabilities that TEE.fail exploits through physical memory bus monitoring.

    TEE.fail researchers noted that the attack can be executed for under $1,000 using readily available hobbyist equipment from secondhand markets.

    The research team demonstrated successful key extraction from machines maintaining Intel’s fully trusted “UpToDate” attestation status, highlighting that even systems meeting the highest security certifications remain vulnerable to this attack vector.

    Probe isolation networks, DDR5 RDIMM interposer and logic analyzer connecting pods (Source – Tee.fail)

    The implications extend beyond theoretical vulnerabilities, as the researchers successfully extracted provisioning certification keys (PCK) from production systems and used them to forge arbitrary SGX and TDX attestations.

    Memory Bus Interposition Technique

    The attack methodology centers on constructing a DDR5 memory interposition probe using components sourced from electronic equipment resellers.

    The researchers developed a custom interposer by modifying DDR5 RDIMM riser boards and incorporating probe isolation networks salvaged from decommissioned Keysight test equipment.

    The isolation network, consisting of carefully matched resistors, capacitors, and inductors, prevents electrical interference with the target system while enabling memory bus traffic observation.

    // Example of deterministic encryption verification
    void ecall_experiment() {
        memset(global_memory, 0x00, burst_size);
        uncached_read(global_memory);
        wait_for_logic_analyzer_collection();
    
        memset(global_memory, 0xFF, burst_size);
        uncached_read(global_memory);
        wait_for_logic_analyzer_collection();
    
        memset(global_memory, 0x00, burst_size);
        uncached_read(global_memory);
        wait_for_logic_analyzer_collection();
    }

    The attack exploits Intel’s use of deterministic AES-XTS encryption combined with precise control over enclave execution timing.

    By implementing controlled-channel attacks to pause enclave execution at specific points and utilizing cache thrashing techniques to force memory accesses, researchers achieved synchronized data collection with their logic analyzer setup.

    The deterministic nature of the encryption enables correlation between observed ciphertexts and known plaintext values, creating a direct pathway to cryptographic key recovery through ECDSA nonce extraction during signing operations performed by Intel’s Provisioning Certification Enclave.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New TEE.fail Attack Breaks Trusted Environments to Exfiltrate Secrets from Intel and AMD DDR5 Environments appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Tel Aviv, Israel, October 29th, 2025, CyberNewsWire

    Sweet Security Brings Runtime-CNAPP Power to Windows

    Sweet Security, a leader in Runtime Cloud and AI security solutions, today announced an extension of its Runtime CNAPP sensor to include Windows environments.

    With this launch, organizations can secure Windows workloads and applications in the cloud.

    The new capability brings the same deep visibility, real-time detection, risk prioritization, and automated investigation that power Sweet’s Runtime CNAPP for Linux to one of the most complex and widely used operating systems in the enterprise cloud.

    Protecting cloud workloads running on the Windows operating system has long been a challenge due to the complexity and the wide range of attack vectors that adversaries can exploit.

    Many existing solutions rely on an EDR agent that’s been repurposed for the cloud, but was ultimately designed for totally different attack scenarios than the ones present in the cloud. 

    Sweet’s Windows sensor was developed specifically for the cloud using Rust, which allows for minimal resource footprint.

    Sweet’s Windows sensor covers all the usual attack vectors, such as DLL injection, registry manipulation, PowerShell scripting, etc., in addition to covering application-level requests and responses (Layer 7 data), peering into applications’ behavior.

    Like all of Sweet’s runtime signals, the Windows sensor relies on Sweet’s renowned behavioral baselining technology, which allows it to detect not just known attack techniques or binary signatures, but also the abuse of legitimate tools for malicious purposes.

    The signals are also cross-correlated with cloud audit logs and cloud identities (CDR and ITDR) for maximum context and observability.

    In a recent customer evaluation, Sweet’s Windows sensor identified a credential-dumping attempt within seconds. The sensor correlated PowerShell execution, registry export, and file creation anomalies that traditional sensors failed to detect.

    From detection to full investigation, the entire process took under two minutes, demonstrating how Sweet’s behavioral and AI-powered detection capabilities accelerate response times and reduce investigation noise.

    With Sweet’s Windows runtime sensor, customers now have a clear view of activity across all workloads. They are now able to detect and address potential threats faster and with greater confidence, protecting critical workloads and maintaining business continuity.

    With the extension to Windows, Sweet Security now leverages its patented LLM-powered correlation and investigation, behavioral baseline, and L7 capabilities to provide full-stack protection for the cloud with its runtime CNAPP, including:

    • Cloud Application Detection and Response (CADR) 
    • Cloud Security Posture Management (CSPM)
    • Kubernetes Security Posture Management (KSPM)
    • Cloud Infrastructure Entitlements Management (CIEM) 
    • Compliance & Governance 
    • Vulnerability Management 
    • CI/CD Pipeline Hardening 
    • Identities Security (ITDR)
    • API Security 
    • Dynamic Application Security Testing (DAST)
    • Data Security (DSPM)

    “This launch marks a major step forward for the entire cloud security industry,” said Orel Ben Ishay, co-founder and VP of R&D, Sweet Security.

    “Windows has historically been a blind spot for runtime protection. By bringing the same depth of behavioral insight, AI-powered detection, and real-time investigation that we deliver for Linux to Windows environments, we are eliminating one of the most significant visibility gaps in cloud security. Detection and full investigation can now take less than two minutes, providing teams with actionable insights faster than ever. This is a foundational step toward our vision of universal runtime protection across all cloud workloads.”

    With this launch, Sweet Security continues to redefine runtime-native CNAPP, helping organizations detect and stop sophisticated attacks before they impact critical cloud workloads.

    For more information on Sweet’s Windows sensor or Runtime CNAPP, users can book a demo today or contact their customer support representative. 

    About Sweet Security

    Sweet Security is redefining enterprise cloud protection.

    As the leading provider of Runtime CNAPP solutions and a pioneer in AI Security, Sweet unifies runtime context with advanced AI intelligence to protect the modern enterprise across applications, workloads, and infrastructure.

    Its platform delivers real-time detection and response, vulnerability and posture management, identity threat protection, and API security—powered by patent-pending, LLM-driven detection, reducing alert noise to just 0.04%.

    By bridging cloud and AI security, Sweet enables organizations to accelerate innovation, reduce operational risk, and achieve industry-leading MTTR times.

    Privately funded, Sweet is backed by Evolution Equity Partners, Munich Re Ventures, Glilot Capital Partners, CyberArk Ventures, and an elite group of angel investors. For more information, users can visit sweet.security.

    Contact

    Chloe Amante

    Montner Tech PR

    camante@montner.com

    The post Sweet Security Brings Runtime-CNAPP Power to Windows appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Tel Aviv, Israel, October 29th, 2025, CyberNewsWire Sweet Security Brings Runtime-CNAPP Power to Windows Sweet Security, a leader in Runtime Cloud and AI security solutions, today announced an extension of its Runtime CNAPP sensor to include Windows environments. With this launch, organizations can secure Windows workloads and applications in the cloud. The new capability brings […]

    The post Sweet Security Brings Runtime-CNAPP Power to Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶