GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull ToolPalo Alto Unit 42·Jun 5, 20:24 UTC · Jun 5, 2024Malware42
Security Issue in JWT Secret Poisoning (Updated)Palo Alto Unit 42·Jun 5, 17:06 UTC · Jun 5, 2024VulnerabilityCVE-2022-2352947
Analysis of DuneQuixote APT campaign in the Middle EastKaspersky Securelist·Apr 18, 10:00 UTC · Apr 18, 2024Threat actor57
HTTP/2 CONTINUATION Flood technique can be exploited in DoS attacksSecurity Affairs·Apr 5, 02:41 UTC · Apr 5, 2024Vulnerability in the wildCVE-2024-27983CVE-2024-27919CVE-2024-2758+6 CVEs60
Telecom firms hit with novel backdoors disguised as security softwareHelp Net Security·Feb 15, 12:04 UTC · Feb 15, 2024Malware42
SystemBC Malware's C2 Server Analysis Exposes Payload Delivery TricksThe Hacker News·Jan 26, 04:30 UTC · Jan 26, 2024Malware42
Labyrinth Chollima behind PyPI supply chain attacksSecurity Affairs·Sep 1, 11:36 UTC · Sep 1, 2023Malware42
New Ongoing Campaign Targets npm Ecosystem with Unique Execution ChainThe Hacker News·Jun 28, 05:23 UTC · Jun 28, 2023Threat actor57
Lazarus APT uses fake cryptocurrency apps to spread AppleJeus MalwareSecurity Affairs·Dec 5, 06:40 UTC · Dec 5, 2022Malware42
New Air-Gap Attack Uses MEMS Gyroscope Ultrasonic Covert Channel to Leak DataThe Hacker News·Aug 23, 13:32 UTC · Aug 23, 2022Malware42
The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
Avos ransomware group expands with new attack arsenalCisco Talos·Jun 21, 11:58 UTC · Jun 21, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
ToddyCat: Unveiling an unknown APT actor attacking highKaspersky Securelist·Jun 21, 10:00 UTC · Jun 21, 2022Vulnerability42
New MyloBot Malware Variant Sends Sextortion Emails Demanding $2,732 in BitcoinThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2022Ransomware57
Sugar Ransomware, a new RaaS in the threat landscapeSecurity Affairs·Feb 2, 18:30 UTC · Feb 2, 2022Ransomware57
Hackers Using New Malware Packer DTPacker to Avoid Analysis, DetectionThe Hacker News·Jan 25, 06:47 UTC · Jan 25, 2022Malware42
New “Undetected” Backdoor Runs Across Three OS PlatformsInfosecurity Magazine·Jan 13, 11:20 UTC · Jan 13, 2022Malware42
Attack techniques observed by Kaspersky MDRKaspersky Securelist·Dec 15, 10:00 UTC · Dec 15, 2021Exploit / PoC in the wildCVE-2021-1675CVE-2021-3452760
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with BabukCisco Talos·Nov 3, 12:00 UTC · Nov 3, 2021RansomwareCVE-2021-3694260
REvil ransomware gang's servers are mysteriously online againSecurity Affairs·Oct 18, 07:21 UTC · Oct 18, 2021Ransomware57
GhostEmperor: From ProxyLogon to kernel modeKaspersky Securelist·Sep 30, 10:00 UTC · Sep 30, 2021Vulnerability42
Bitdefender released free REvil ransomware decryptorSecurity Affairs·Sep 16, 14:57 UTC · Sep 16, 2021Ransomware57
Revil ransomware operators are targeting new victimsSecurity Affairs·Sep 12, 05:29 UTC · Sep 12, 2021Ransomware57
Security research project: The easiest way to get "experience" and land a job in cybersecurityHelp Net Security·May 12, 05:31 UTC · May 12, 2021Malware in the wild57
Lazarus APT Hackers are now using BMP images to hide RAT malwareThe Hacker News·Apr 20, 05:33 UTC · Apr 20, 2021Malware42
Masslogger campaigns exfiltrates user credentialsCisco Talos·Feb 17, 13:00 UTC · Feb 17, 2021Threat actor57
Vulnerability Spotlight: Accusoft ImageGear vulnerabilities could lead to code executionCisco Talos·Feb 9, 17:00 UTC · Feb 9, 2021Vulnerability in the wildCVE-2020-13561CVE-2020-13571CVE-2020-13572+1 CVEs60
FireEye, GoDaddy,and Microsoft create kill switch for SolarWinds backdoorSecurity Affairs·Dec 17, 08:32 UTC · Dec 17, 2020Malware42
New Malware Jumps Air-Gapped Devices by Turning PowerThe Hacker News·Dec 16, 06:16 UTC · Dec 16, 2020Malware42
Malicious Domain in SolarWinds Hack Turned into ‘Killswitch’Krebs on Security·Dec 15, 00:00 UTC · Dec 15, 2020Malware42
What did DeathStalker hide between two ferns?Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2020Malware42
Lifting the veil on DeathStalker, a mercenary triumvirateKaspersky Securelist·Aug 24, 10:00 UTC · Aug 24, 2020Ransomware57
CISA warns of phishing attacks delivering KONNI RATSecurity Affairs·Aug 17, 16:31 UTC · Aug 17, 2020Malware42
Friday Squid Blogging: Vulnerabilities in Squid ServerSchneier on Security·Jun 22, 16:30 UTC · Jun 22, 2020Vulnerability42
Vulnerability Spotlight: Multiple vulnerabilities in Videolabs libmicrodnsCisco Talos·Mar 23, 15:21 UTC · Mar 23, 2020Vulnerability in the wildCVE-2020-6071CVE-2020-6072CVE-2020-6073+4 CVEs60
Vulnerability Spotlight: Denial-of-service, information leak bugs in MiniCisco Talos·Feb 3, 19:11 UTC · Feb 3, 2020Vulnerability in the wildCVE-2020-6058CVE-2020-6059CVE-2020-606060
Vulnerability Spotlight: Accusoft ImageGear PNG IHDR width code execution vulnerabilityCisco Talos·Dec 2, 18:38 UTC · Dec 2, 2019Vulnerability in the wildCVE-2019-5083CVE-2019-5076CVE-2019-5132+1 CVEs60
WAV files spotted delivering malicious codeHelp Net Security·Oct 18, 07:41 UTC · Oct 18, 2019Exploit / PoC57