Threat Intelligence Bulletin – Follina, Stolen VPN Credentials, and Telegram Phishing

Microsoft Office zero-day ‘Follina’ (CVE-2022-30190) exploiting Support Diagnostic Tools


FBI warns hackers selling VPN credentials from educational institutions


Chinese hackers infecting victims using man-on-the-side attacks by monitoring network tracking


Windows Search zero-day can be used to open search window with remotely-hosted malware by launching a word doc


Telegraph blogging platform being used for credential harvesting pages of phishing campaigns


Zero-day in unpatched Atlassian Confluence being exploited