Latest Cybersecurity News and Articles
08 March 2023
The app was found to send the contents of the clipboard to a remote server if a particular pattern was present, though it is not clear whether there was any malicious intent behind the behaviour.
08 March 2023
The North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year.
While the first attack in May 2022 entailed the use of a vulnerable version of a certificate software that's widely used by public institutions and universities, the re-infiltration in October 2022 involved the
08 March 2023
A cryptojacking operation was found using an authentic, open-source command-line file transfer service to carry out its attack against misconfigured Redis database servers. Although the objective of the campaign is to mine cryptocurrencies, the script performs several additional tasks to ensure the effective utilization of resources. It is imperative that administrators actively monitor any misconfigurations in Redis servers and fix them.
08 March 2023
Using AI-generated polymorphic malware, a threat actor can combine a series of typically highly detectable behaviors in an unusual combination and evade detection by exploiting the model’s inability to recognize it as a malicious pattern.
08 March 2023
As part of an ongoing social engineering campaign, the China-aligned Mustang Panda threat group has been seen using a previously unknown custom backdoor dubbed MQsTTang. It’s unclear who the cybercriminals are targeting. A rare observation in the implant is the use of MQTT, an IoT messaging protocol, for C2 communications.
08 March 2023
This is according to Victor Zhora, deputy chairman and chief digital transformation officer of the SSSCIP of Ukraine, who explained the strategic change from disruptive attacks to cyber espionage to Infosecurity.
08 March 2023
The Emotet malware operation is again sending malicious spam emails as of Tuesday morning after a three-month break, rebuilding its network and infecting devices worldwide.
08 March 2023
Cybersecurity analysts at Cybel reported on R3NIN, an online skimmer, that pilfers payment card data and PII from unsuspecting individuals while they checkout from online shops. This toolkit has capabilities for creating unique JavaScript injection codes, managing exfiltrated data, managing compromised payment card info (across different browsers), checking BINs, parsing data, and generating statistics.
08 March 2023
Deep Instinct, the first company to apply deep learning to cybersecurity, today announced an investment from PayPal Ventures. The funding will help further accelerate Deep Instinct's growth, driven by its disruptive threat prevention technology.
08 March 2023
The most critical of the three is CVE-2022-35914, which concerns a remote code execution vulnerability in the third-party library htmlawed present in Teclib GLPI, an open-source asset and IT management software package.
08 March 2023
BlackLotus bootkit has been discovered interfering with UEFI Secure Boot, a crucial platform security feature, that can run even on fully up-to-date Windows 11 systems. The robust, persistent 80 KB toolkit was created in Assembly and C language. To prevent infecting computers in Armenia, Belarus, Kazakhstan, Moldova, Romania, Russia, and Ukraine, it also has geofencing capabilities.
08 March 2023
In December 2022, a private loader named “AresLoader” was advertised for sale on the top-tier Russian-language hacking forum XSS by a threat actor going by the name “DarkBLUP”.
08 March 2023
High-profile government entities in Southeast Asia are the target of a cyber espionage campaign undertaken by a Chinese threat actor known as Sharp Panda since late last year.
The intrusions are characterized by the use of a new version of the Soul modular framework, marking a departure from the group's attack chains observed in 2021.
Israeli cybersecurity company Check Point said the "
08 March 2023
Iron Tiger, an APT organization, has updated its SysUpdate RAT by incorporating additional functionality and support for malware infection to target the Linux OS. Experts suspect APT27 used the chat app Youdu to send malicious links to the employees, luring them into downloading the initial infection payloads. Organizations are suggested to tighten up the vigilance of all entry points, including emails and IM with ant-malware and anti-phishing solutions.
08 March 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The list of vulnerabilities is below -
CVE-2022-35914 (CVSS score: 9.8) - Teclib GLPI Remote Code Execution Vulnerability
CVE-2022-33891 (CVSS score: 8.8) - Apache Spark Command Injection Vulnerability
08 March 2023
Uptycs researchers spotted a new malware campaign targeting cryptocurrency companies with Parallax RAT. It can collect system metadata and data stored in the clipboard. Once the malware has been successfully injected, attackers interact with the victims by asking questions and sharing their Telegram ID via Notepad for further communication.
08 March 2023
According to VulnCheck, the KEV Catalog comprises 868 bugs, including 557 added in the past year. Among these, 241 have been abused by APT actors, 122 by ransomware gangs, and 69 by botnets. Another report by Tenable categorized significant vulnerability data to identify the most significant risks and disrupt attack paths, thereby reducing the overall exposure to cyberattacks.
08 March 2023
Experts at Lumen Black Lotus Labs stumbled across a campaign dubbed Hiatus dropping a pair of payloads to infect business routers. The payloads include HiatusRAT and a variant of tcpdump (which enables packet capture on the target device). With HiatusRAT, criminals can turn a compromised machine into a secret proxy system. Researchers identified at least 100 infected systems, with most of the infections in Europe and Latin America.
08 March 2023
Two recently released reports highlight the increasing challenges faced by security practitioners, particularly those who have larger and more integrated systems between their IT and OT environments.
07 March 2023
Researchers at Quarkslab unveiled two bugs in the Trusted Platform Module (TPM) 2.0 reference library specification. The attacks could potentially lead to information disclosure or privilege escalation. The first bug, CVE-2023-1017, concerns an out-of-bounds write while the other bug, CVE-2023-1018, is an out-of-bounds read issue. Billions of internet-connected devices across different organizations are vulnerable to the threat.