Latest Cybersecurity News and Articles


China's Mustang Panda Hackers Exploit TP-Link Routers for Persistent Attacks

16 May 2023
The Chinese nation-state actor known as Mustang Panda has been linked to a new set of sophisticated and targeted attacks aimed at European foreign affairs entities since January 2023. An analysis of these intrusions, per Check Point researchers Itay Cohen and Radoslaw Madej, has revealed a custom firmware implant designed explicitly for TP-Link routers. "The implant features several malicious

Update: Dallas says it 'will likely take weeks to get back to full functionality' after ransomware attack

16 May 2023
For the last two weeks, the city has been engulfed in a massive recovery effort after the Royal ransomware gang caused significant damage to systems that manage the city’s police, fire department, courts, critical infrastructure, and more.

Industrial Cellular Routers at Risk: 11 New Vulnerabilities Expose OT Networks

16 May 2023
Several security vulnerabilities have been disclosed in cloud management platforms associated with three industrial cellular router vendors that could expose operational technology (OT) networks to external attacks.

Water Orthrus APT Re-Emerges with Two New Malware Families

16 May 2023
The threat actor known as Water Orthrus was spotted with two new campaigns in March and April 2023 that intended to deliver CopperStealth and CopperPhish payloads. The new malware have been upgraded for different purposes, such as injecting network advertisements, acquiring personal information, and stealing crypto assets. Organizations must leverage the updated IOCs associated with the malware families to better understand the attack campaign

Is human threat hunting a fool’s errand?

16 May 2023
As the rate of cyberattacks steadily increases, automated threat hunting processes are being integrated to help stem the tide by providing quicker security insights, more efficient operations, and human error reductions.

More Supply Chain Attacks Propagating Through Malicious Python Packages

16 May 2023
The FortiGuard Labs team discovered over 30 new zero-day attacks in PyPI packages (Python Package Index). These were found between late March and late April by monitoring an open-source ecosystem.

DangerousPassword Campaign: A Multi-Faceted Approach Exploiting Cryptocurrency Exchanges

16 May 2023
DangerousPassword initiated an attack campaign on cryptocurrency exchanges that infect their targets with malware, employing four distinct attack patterns. It distributes malicious CHM files from LinkedIn, uses OneNote and virtual hard disk files, and deploys an Applescript to target Mac users. Organizations must watch out for these threats and deploy the right security measures.

Geacon Brings Cobalt Strike Capabilities to macOS Threat Actors

16 May 2023
According to SentinelOne researchers, Geacon was a project that first surfaced on GitHub four years ago as a Go implementation of Cobalt Strike Beacon. Despite being widely forked, it was not being deployed against macOS targets until recently.

Western Digital cyberattack not expected to have material impact on future earnings

16 May 2023
The majority of Western Digital’s impacted systems and services are back online following a March cyberattack where hackers stole a database used in the company’s online store, the company said in a quarterly report filed with the SEC last week.

Re-Victimization from Police-Auctioned Cell Phones

16 May 2023
Countless smartphones seized in arrests and searches by police forces across the United States are being auctioned online without first having the data on them erased, a practice that can lead to crime victims being re-victimized, a new study found. In response, the largest online marketplace for items seized in U.S. law enforcement investigations says it now ensures that all phones sold through its platform will be data-wiped prior to auction.

Inside Qilin Ransomware: Affiliates Take Home 85% of Ransom Payouts

16 May 2023
Ransomware affiliates associated with the Qilin ransomware-as-a-service (RaaS) scheme earn anywhere between 80% to 85% of the ransom payments, according to new findings from Group-IB. The cybersecurity firm said it was able to infiltrate the group in March 2023, uncovering details about the affiliates' payment structure and the inner workings of the RaaS program following a private conversation

Cyolo Product Overview: Secure Remote Access to All Environments

16 May 2023
Operational technology (OT) cybersecurity is a challenging but critical aspect of protecting organizations' essential systems and resources. Cybercriminals no longer break into systems, but instead log in – making access security more complex and also more important to manage and control than ever before. In an effort to solve the access-related challenges facing OT and critical infrastructure

CopperStealer Malware Crew Resurfaces with New Rootkit and Phishing Kit Modules

16 May 2023
The threat actors behind the CopperStealer malware resurfaced with two new campaigns in March and April 2023 that are designed to deliver two novel payloads dubbed CopperStealth and CopperPhish. Trend Micro is tracking the financially motivated group under the name Water Orthrus. The adversary is also assessed to be behind another campaign known as Scranos, which was detailed by Bitdefender in

Lancefly APT Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors

16 May 2023
The custom backdoor called Merdoor is used very selectively, appearing on just a handful of networks and a small number of machines over the years, with its use appearing to be highly targeted.

Intel says its mystery microcode update isn't security fix

16 May 2023
Despite the patch notes suggesting otherwise, the mysterious blob of microcode released for many Intel microprocessors last week was not a security update, the x86 giant says.

Qilin's Dark Web Ransomware Targets Critical Sectors

16 May 2023
Employing Rust and Go programming languages, Qilin has been actively targeting companies in critical sectors with highly customized and evasive ransomware attacks, explained Nikolay Kichatov, threat intelligence analyst at Group-IB.

The new info-stealing malware operations to watch out for

16 May 2023
Although older strains like RedLine, Raccoon, and Vidar continue to have a significant presence, and newer families like Aurora, Mars, and Meta are still growing, new malware families are also trying to make a name for themselves this year.

Water Orthrus New Campaigns Deliver Rootkit and Phishing Modules

16 May 2023
According to Trend Micro researchers, they have been monitoring the activities of a threat actor referred to as Water Orthrus since 2021. The threat actor has been utilizing pay-per-install (PPI) networks to distribute CopperStealer malware.

Advantech’s industrial serial device servers open to attack

16 May 2023
Three vulnerabilities discovered by CyberDanube researchers in Advantech’s EKI series of serial device servers could be exploited to execute arbitrary commands at the operating system level.

Hackers Using Golang Variant of Cobalt Strike to Target Apple macOS Systems

16 May 2023
A Golang implementation of Cobalt Strike called Geacon is likely to garner the attention of threat actors looking to target Apple macOS systems. The findings come from SentinelOne, which observed an uptick in the number of Geacon payloads appearing on VirusTotal in recent months. "While some of these are likely red-team operations, others bear the characteristics of genuine malicious attacks,"