-
May 5, 2023
Researchers from the Technical University of Berlin have discovered an exploit called faultTPM that can bypass security protections like BitLocker by exploiting a hardware bug in the firmware TPM (fTPM) of AMD Ryzen processors based on Zen 2 and 3… read more »
-
May 4, 2023
Check Point Research has discovered a new strain of malware, FluHorse, that is highly effective in infiltrating Android apps. The campaign is currently active in East Asia and has affected over 100,000 users. FluHorse is designed to steal sensitive information… read more »
-
May 4, 2023
According to a research by cybersecurity from Sophos, the APT group Dragon Breath (also known as Golden Eye Dog) is using complex variations of the classic DLL sideloading technique to evade detection. The group uses trojanized versions of Telegram, LetsVPN,… read more »
-
May 2, 2023
A new malware called LOBSHOT is being distributed through Google Ads by impersonating a legitimate remote management software, AnyDesk. The malware, analyzed by cybersecurity experts from Elastic Security Labs. is a remote access trojan that allows threat actors to take… read more »
-
Apr 29, 2023
In March and April 2023, cybersecurity firm TrendMicro discovered a new type of ransomware called Rapture that targets its victims using a minimalistic approach with tools that leave only a minimal footprint behind. This malware was found to have similarities… read more »
-
Apr 29, 2023
A new information stealer for Apple macOS, called Atomic macOS Stealer (AMOS), is being advertised on Telegram for $1,000 per month. According to a recent research from Cyble, the malware can steal various types of information from the victim’s machine,… read more »
-
Apr 26, 2023
Alloy Taurus, a Chinese nation-state group known for attacking telecom companies since at least 2012, has been found to be using a Linux variant of the PingPull backdoor and a new tool called Sword2033, according to cybersecurity company Palo Alto… read more »
-
Apr 25, 2023
North Korea-linked BlueNoroff APT group has been observed by security firm Jamf using a new macOS malware called RustBucket in recent attacks. The RustBucket malware allows operators to download and execute various payloads. The first-stage was contained within an unsigned… read more »
-
Apr 24, 2023
Several years ago, during a SANS course, I discovered TiddlyWiki for the first time. Since then, I have never stopped using it, despite its somewhat dated UI. TiddlyWiki is a highly versatile and customizable personal wiki that allows me to… read more »
-
Apr 21, 2023
Cybercriminals are using a new method called RBAC Buster to create persistent backdoor accounts on Kubernetes clusters and use their resources for Monero crypto-mining. The RBAC (Role-Based Access Control) system is used by admins to define which users or service… read more »
-
Apr 21, 2023
Google has fixed a security flaw called GhostToken that allowed attackers to backdoor Google Cloud Platform (GCP) users’ accounts using malicious OAuth applications installed from the Google Marketplace or third-party providers. According to a research by Astrix Security, after being… read more »
-
Apr 20, 2023
The Lazarus Group, a North Korea-aligned state-sponsored actor, has been attributed to a new campaign called Operation Dream Job that targets Linux users. In a report recently published, analists from cybersecurity firm ESET revealed that this social engineering scheme involves… read more »
-
Apr 19, 2023
AuKill is a new hacking tool used by threat actors to disable Endpoint Detection & Response (EDR) software on victims’ systems before deploying backdoors and ransomware in Bring Your Own Vulnerable Driver (BYOVD) attacks. The malware, first spotted by Sophos… read more »
-
Apr 18, 2023
The China-linked APT41 cyberespionage group (also known as HOODOO) used the open-source red teaming tool GC2 in an attack against an unnamed Taiwanese media organization in October 2022, using as payload an open source red teaming tool called “Google Command… read more »
-
Apr 17, 2023
QBot, a dangerous Windows banking Trojan, is being used in a new series of attacks against corporate targets. Cybercriminals are using new techniques to distribute the malware, including email phishing scams: infiltrating email conversations and tricking users into downloading a… read more »
-
Apr 16, 2023
According to some twitter threads published by cybersecurity researchers vx-underground and MalwareHunterTeam, the major ransomware operation LockBit has created encryptors specifically targeting MacOS for the first time. "locker_Apple_M1_64": 3e4bbd21756ae30c24ff7d6942656be024139f8180b7bddd4e5c62a9dfbd8c79As much as I can tell, this is the first Apple's Mac… read more »
-
Apr 16, 2023
A new Android malware called ‘Goldoson’ has been distributed via Google Play through 60 legitimate apps with 100 million downloads. The malware is part of a third-party library that developers have unwittingly added to their apps. According to a research… read more »
-
Apr 14, 2023
The Vice Society ransomware gang has developed a new PowerShell script to automate data theft from compromised networks, which is fully automated and uses “living off the land” binaries and scripts to remain undetected. The script uses multiple functions to… read more »
-
Apr 13, 2023
A cybercriminal gang called Read The Manual (RTM) Locker has been described in detail by cybersecurity researchers of Trellix . RTM is a private ransomware-as-a-service (RaaS) provider that conducts opportunistic attacks to generate illicit profits. The group operates through affiliates,… read more »
-
Apr 13, 2023
Legion is a new Python-based tool being sold on Telegram by cybercriminals that targets online email services for phishing and spam attacks. According to a reserch from cybersecurity firm Cado, Legion is a modular malware likely based on the AndroxGhOst… read more »