September 5, 2022 Luca Stealer Malware Targets Cryptocurrency Wallets and Password Managers A new malware variant dubbed Luca Stealer is growing in popularity following the release of its source code for free in July. At present, it ... Read more
August 29, 2022 More than 130 Companies Fall Victim to SMS Phishing Campaign Targeting Okta Credentials A highly successful phishing campaign has been identified that targets Okta credentials. Okta is an American identity and access management company that provides cloud-based software ... Read more
August 19, 2022 2 ‘Actively Exploited’ RCE Vulnerabilities Patched in iPhones, iPads, iPods, and Macs Two critical zero-day vulnerabilities have been patched by Apple that may have been actively exploited in the wild. Exploitation of the flaws allows threat actors ... Read more
August 19, 2022 IBM X-Force Provides Insights into the Rapidly Changing OT Threat Landscape IBM X-Force has analyzed data from its incident response and managed security services (MSS) and has provided valuable insights into the rapidly expanding operational technology ... Read more
August 16, 2022 Microsoft Disrupts Ongoing Russia-Linked Phishing Campaign Microsoft has announced it has taken steps to disrupt phishing campaigns conducted by a Russia-linked threat actor tracked as SEABORGIUM. The threat actor originates from ... Read more
August 10, 2022 Microsoft Patches 121 Vulnerabilities Including an Actively Exploited 0-Day Bug Microsoft released updates to fix 121 CVEs on August 2022 Patch Tuesday, including two zero-day flaws, one of which is being actively exploited in the ... Read more
July 25, 2022 Amadey Bot Malware Distributed via SmokeLoader using Software Cracking Software A malware distribution campaign has been detected by researchers at AhnLab that ultimately delivers Amadey Bot malware. Amadey Bot malware can steal information from infected ... Read more
July 21, 2022 Flaws in Vehicle GPS Tracker Could be Exploited Remotely to Track and Disable Vehicles A popular GPS tracking device – MiCODUS MV720 GPS tracker – that is installed in vehicles to protect against theft and for vehicle fleet management ... Read more
July 19, 2022 ICS Systems Infected with Sality Malware via Password Recovery Tool A threat actor is gaining access to industrial control systems (ICS) using a Trojan horse password recovery tool that claims to recover passwords for programmable ... Read more
July 14, 2022 Security Vendors Impersonated in Callback Phishing Campaign The cybersecurity vendor CrowdStrike has issued a warning about a callback phishing campaign that attempts to trick employees at businesses into visiting a malicious website. ... Read more
July 8, 2022 Threat Groups Observed Substituting Cobalt Strike for Stealthier Post-Exploitation Framework Cyber threat actors are frequently observed deploying a legitimate penetration testing and post-exploitation framework known as Cobalt Strike on victims’ systems. Cobalt Strike is used ... Read more
June 24, 2022 Police in Europe Dismantle Multi-Million-Euro Phishing Operation An organized criminal gang that was operating a multi-million-Euro phishing operation has been dismantled by police forces in Belgium and the Netherlands, according to Europol. ... Read more
June 13, 2022 Emotet Malware Infections Increased by 2,700% from Q4, 2021 to Q1, 2022 Security researchers have identified new variants of Emotet malware that are capable of collecting and using stolen credentials, which are then weaponized and used to ... Read more
June 10, 2022 Researchers Uncover Massive Facebook and Messenger Phishing Campaign Security researchers at the cybersecurity firm PIXM have identified a massive phishing campaign being conducted through Facebook and Messenger, which has driven millions of individuals ... Read more
June 7, 2022 Local Governments Targeted in Phishing Campaign Exploiting Windows Follina Vulnerability The critical Windows ‘Follina’ zero-day vulnerability is being exploited in phishing attacks on local governments in the United States and government entities throughout Europe, according ... Read more
June 3, 2022 Zero-day Atlassian Confluence Vulnerability Being Actively Exploited by Multiple Threat Actors A critical Atlassian Confluence zero-day vulnerability is being actively exploited by multiple threat actors. At present, there is no patch available to fix the flaw. The ... Read more
June 1, 2022 Zero-Day Vulnerability Affecting Microsoft Office Being Actively Exploited A zero-day remote code execution vulnerability has been identified in the Microsoft Windows Support Diagnostic Tool (MSDT) which is being actively exploited in the wild. ... Read more
May 25, 2022 CISA Adds 41 Vulnerabilities to the Known Exploited Vulnerability Catalog On May 23 and May 24, 2022, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a further 41 vulnerabilities to its Known Exploited Vulnerability ... Read more
May 11, 2022 Critical F5 BIG-IP Flaw is Being Widely Exploited A critical flaw in F5 BIG-IP systems is being actively exploited by threat actors. BIG-IP systems are software/hardware solutions that are used for access control, ... Read more
May 10, 2022 Phishing Campaign Pushing Jester Malware Targets Ukrainian Citizens Warning of Chemical Attacks A phishing campaign has been identified that warns of chemical weapon attacks on Ukrainian citizens in an attempt to infect devices with Jester malware. The ... Read more
May 5, 2022 Campaign Identified Delivering Fileless Malware using Shellcode in Windows Event Logs A new technique has been observed in the wild for delivering fileless malware on targeted devices and evading detection. According to researchers at Kaspersky, the ... Read more
May 3, 2022 Man Convicted for Phishing Scam Resulting in Theft of $23.5 Million from DoD The losses to phishing scams can be considerable. What starts with a single phishing email can easily result in a costly data breach, malware infection, ... Read more
April 30, 2022 How Password Managers Mitigate the Threat from Phishing The best way to mitigate the threat from phishing is to train employees to be more resilient to phishing attacks, introduce processes to report suspicious ... Read more
April 29, 2022 Bumblebee is the Malware Loader of Choice for Delivering Malicious Payloads A new malware loader dubbed Bumblebee is being used by multiple threat actors to deliver malicious payloads to victims’ devices. According to cybersecurity firm Proofpoint, ... Read more
April 26, 2022 Emotet is Once Again the Biggest Malware Threat In January 2021, the infamous Emotet botnet was shut down following an international law enforcement operation coordinated by Europol and Eurojust. Emotet started life as ... Read more
April 15, 2022 Microsoft Takes Control of ZLoader Botnet Infrastructure Microsoft’s Digital Crimes Unit (DCU) has taken control of 65 domains that were being used as the command-and-control mechanism for the ZLoader botnet. The botnet ... Read more
April 7, 2022 FBI Disrupts the Russia-Linked Cyclops Blink Botnet The massive Cyclops Blink botnet that was being used to target firewall appliances and SOHO networking devices has been neutralized by the U.S. Federal Bureau ... Read more
April 5, 2022 WhatsApp Voicemail Phishing Campaign Distributes Information Stealing Malware A new WhatsApp phishing campaign has been identified by researchers at Armorblox that has been sent to at least 27,655 email addresses. The emails impersonate ... Read more
March 28, 2022 Over 5 Dozen Software Flaws Added to CISA’s Known Exploited Vulnerabilities List The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 66 vulnerabilities to its Known Exploited Vulnerabilities Catalog that should be given priority when patching, ... Read more
March 22, 2022 Malware Infection at Dental Clinic Operator Affects More Than 1 Million Texans JDC Healthcare Management, which operates more than 70 dental clinics in Texas as Jefferson Dental & Orthodontics, has recently notified the Texas Attorney General about ... Read more