Enterprise management platforms and software supply chains continue to attract threat actor interest because they can provide privileged, centralised access to corporate systems and connected services.
This week’s Orpheus Weekly Intelligence Summary covers compromises involving N-able’s N-central platform, phishing campaigns abusing Microsoft Teams and targeted identity attacks by UNC6671 against financial organisations. It also highlights vulnerabilities affecting Veeam ONE, Apache Tomcat, OVSwrap and Jenkins, alongside the ChainDrop supply-chain worm, which compromised at least 444 packages.