December 6, 2018 Adobe Patches Actively Exploited 0-Day Vulnerability in Flash Player On Wednesday, December 5, 2018, Adobe issued an update to correct a vulnerability in Adobe Flash Player that is being leveraged by a threat group ... Read more
November 29, 2018 49% of All Phishing Sites Have SSL Certificates and Display Green Padlock Almost half of phishing sites now have SSL certificates, start with HTTPS, and display the green padlock to show the sites are secure, according to ... Read more
November 22, 2018 APT28 Group Uses New Cannon Trojan in Spear Phishing Campaign Targeting US and EU Government Agencies A new spear phishing campaign is being conducted by the AP28 (Sofacy Group/Fancy Bear/Sednit) on government organizations in the United States, Europe, and a former ... Read more
November 21, 2018 Gmail Flaw Allows Phishing Emails to Be Sent Anonymously A Gmail flaw has been discovered that allows emails to be sent anonymously with no information included in the sender field. The flaw could easily ... Read more
November 20, 2018 Critical AMP for WP Plugin Vulnerability Allows Any User to Gain Admin Rights A new critical WordPress plugin vulnerability has been identified that could allow site users to escalate privileges to admin level, giving them the ability to ... Read more
November 20, 2018 TA505 APT Group Spreading tRat Malware in New Spam Campaigns The prolific APT group TA505 is conducting spam email campaigns spreading a new, modular malware variant named tRAT. tRAT malware is a remote access Trojan ... Read more
November 7, 2018 Zero-Day VirtualBox Vulnerability and Exploit Published Details of a zero-day VirtualBox vulnerability have been published online along with a step by step exploit. The vulnerability in the Oracle open source hosted ... Read more
October 30, 2018 U.S. Treasury Investigating $700,000 Loss to Phishing Scam In July 2018, the Washington D.C. government fell for an email scam that resulted in wire transfers totaling nearly $700,000 being sent to a scammer’s ... Read more
October 25, 2018 Cloud-Based Threat Analytics Firm ZoneFox Acquired by Fortinet Fortinet has announced it has acquired the cloud-based threat analytics firm ZoneFox and will be using the company’s machine learning threat detection technology to enhance ... Read more
October 24, 2018 Zero-Day Windows Data Sharing Service Vulnerability Discovered A Windows zero-day vulnerability has been discovered that allows hackers to delete application dlls and cause a system to crash and potentially hijack systems. The ... Read more
October 22, 2018 Exploits Published for LibSSH Vulnerability: Immediate Patching Required A recently discovered LibSSH vulnerability, that has been described as ‘comically bad’ by the security researcher who discovered it, has been patched. The flaw is ... Read more
October 11, 2018 Sophisticated Phishing Attack Inserts Malware into Existing Email Conversation Threads A new sophisticated phishing tactic has been identified that involves a malicious actor gaining access to an email account, monitoring a conversation thread, and then ... Read more
October 10, 2018 Microsoft Addresses 49 Flaws Including One Actively Exploited Vulnerability Almost 50 vulnerabilities have been patched by Microsoft on October Patch Tuesday including one zero-day vulnerability that is being actively exploited in the wild by ... Read more
October 8, 2018 Phishers Using Azure Blog Storage to Host Phishing Forms with Valid Microsoft SSL Certificate Cybercriminals are using Microsoft Azure Blog storage to host phishing forms. The site hosting the malicious files has a genuine Microsoft SSL certificate which adds ... Read more
October 3, 2018 Danabot Banking Trojan Used in U.S. Campaign The DanaBot banking Trojan was first detected by security researchers at Proofpoint in May 2018. It was being used in a single campaign targeting customers ... Read more
September 26, 2018 Q2, 2018 Saw an 86% Rise in Cryptocurrency Mining Malware Detections 2018 has proven to be the year of cryptocurrency mining malware. Cybercriminals are increasingly abandoning other forms of malware and ransomware in favor of malware ... Read more
September 19, 2018 Pegasus Spyware Campaigns Gather Pace: Infections Detected in 45 Countries Pegasus spyware is a legitimate surveillance tool that has been attributed to the Israeli cyber-intelligence firm NSO Group. The spyware works on both Android smartphones ... Read more
September 18, 2018 New Python Ramsomware Threat Detected Security researchers at Trend Micro have identified a new Python ransomware threat that piggybacks on the success of Locky ransomware. The threat actors behind the ... Read more
September 10, 2018 New Brazilian Banking Trojan Hides in Plain Sight An innovative new Brazilian banking Trojan has been detected by security researchers at IBM X-Force. The Trojan has been named CamuBot due to its use ... Read more
September 6, 2018 Zero-Day Windows Task Scheduler Vulnerability Exploited by Threat Group On August 27, a security researcher with the online moniker SandboxEscaper discovered a zero-day vulnerability in Windows Task Scheduler (Windows 7-10) and published a proof-of-concept ... Read more
September 3, 2018 Micropatch Blocks Zero-Day Vulnerability in Windows Task Scheduler On August 29, 2018, a proof-of-concept exploit for a zero-day vulnerability in Windows Task Scheduler was published on GitHub by a security researcher. The vulnerability ... Read more
August 29, 2018 Exploit Published for Zero-Day Vulnerability Found in Windows Task Scheduler A zero-day vulnerability has been discovered in Windows Task Scheduler and an exploit for the flaw has been published on GitHub. The local privilege escalation ... Read more
August 24, 2018 New Critical Apache Struts Vulnerability Discovered A new Apache Struts vulnerability has been discovered in the core functionality of Apache Struts. This is a critical flaw that allows remote code execution ... Read more
August 21, 2018 Necurs Botnet Now Distributing Marap Malware The Necurs botnet is being used to send huge quantities of spam emails containing Marap malware. Marap malware is currently being used for reconnaissance and ... Read more
August 3, 2018 Massive Malvertising Operation Uncovered that Delivers Traffic to Rig Exploit Kit For many years cybercriminals have been sneaking malicious adverts onto legitimate websites through advertising networks. Publishers – website owners that sell space on their sites ... Read more
August 3, 2018 Businesses Turn Employee Safety Solution into Phishing Alert System Fast action is required when cybersecurity threats are detected to limit the harm caused. When phishing emails are received, or ransomware or malware threats are ... Read more
August 2, 2018 AI-Assisted Virtual Security Analyst Added to Ironscales’ Advanced Threat Protection Platform Ironscales, the Tel Aviv-based anti-phishing solution provider, has announced it has incorporated a new module into its advanced threat protection platform that helps security teams ... Read more
July 24, 2018 Most Clicked Phishing Emails in Q2, 2018 Security training and phishing email simulation platform provider KnowBe4 has released a report on the most clicked phishing emails in Q2, 2018. If businesses provide ... Read more
July 17, 2018 Convincing Phishing Campaign Targets Australian Businesses and Spreads DanaBot Trojan A new phishing campaign has been detected that is spreading the DanaBot Trojan. The campaign involves phishing emails which appear to contain invoices from the ... Read more
July 12, 2018 Code Stealing Certificates Stolen from D-Link and Used in Malware Campaign The Advanced Persistent Threat (APT) group BlackTech has stolen code-signing certificates from D-Link and Changing Information Technology Inc., and is using them to cryptographically sign ... Read more