The RaaS group that distributes Hive ransomware delivers new malware impersonating as validly signed network-administration software to gain initial access and persistence on targeted networks
Автор: Elizabeth Montalbano, Contributing Writer
China’s Evasive Panda Attacks ISP to Send Malicious Software Updates
The APT used DNS poisoning to install the Macma backdoor on targeted networks and then deliver malware to steal data via post-exploitation activity.
Black Basta Develops Custom Malware in Wake of Qakbot Takedown
The prolific ransomware group has shifted away from phishing as the method of entry into corporate networks, and is now using initial access brokers as well as its own tools to optimize its most recent attacks.
Attackers Hijack Facebook Pages, Promote Malicious AI Photo Editor
A malvertising campaign uses phishing to steal legitimate account pages, with the endgame of delivering the Lumma stealer.
Dynamically Evolving SMS Stealer Threatens Global Android Users
A network of more than 2,600 Telegram bots has helped exfiltrate one-time passwords and data from devices for more than two years.
OAuth+XSS Attack Threatens Millions of Web Users With Account Takeover
An attack flow that combines API flaws within "log in with" implementations and Web injection bugs could affect millions of websites.
OAuth+XSS Attack Threatens Millions of Web Users With Account Takeover
An attack flow that combines API flaws within "log in with" implementations and Web injection bugs could affect millions of websites.
Security Firm Accidentally Hires North Korean Hacker, Did Not KnowBe4
A software engineer hired for an internal IT AI team immediately became an insider threat by loading malware onto his workstation.
CrowdStrike Blames Crash on Buggy Security Content Update
CrowdStrike vows to provide customers with greater control over the delivery of future content updates by allowing granular selection of when and where these updates are deployed.
Attackers Exploit ‘EvilVideo’ Telegram Zero-Day to Hide Malware
An exploit sold on an underground forum requires user action to download an unspecified malicious payload.