FICORA and Kaiten Botnets Exploit Old DThe Hacker News·Dec 27, 07:11 UTC · Dec 27, 2024MalwareCVE-2015-2051CVE-2019-10891CVE-2022-37056+1 CVEs47
Key Group uses leaked builders of ransomware and wipersKaspersky Securelist·Oct 1, 10:00 UTC · Oct 1, 2024Ransomware57
HZ Rat backdoor for macOS harvests data from WeChat and DingTalkKaspersky Securelist·Aug 27, 10:01 UTC · Aug 27, 2024Malware42
Multiple vulnerabilities in TP-Link Omada system could lead to root accessCisco Talos·Jun 26, 16:00 UTC · Jun 26, 2024VulnerabilityCVE-2023-49906CVE-2023-49913CVE-2023-48724+11 CVEs47
Attackers Conducting Cryptojacking Operation Against U.S. Education OrganizationsPalo Alto Unit 42·Jun 6, 13:25 UTC · Jun 6, 2024Vulnerability42
Talos IR trends: BEC attacks surge, while weaknesses in MFA persistCisco Talos·Apr 25, 12:00 UTC · Apr 25, 2024Phishing & fraudCVE-2021-27876CVE-2023-27532147
Chinese Groups Deploy New TTPs to Exploit Ivanti VulnerabilitiesInfosecurity Magazine·Apr 5, 15:00 UTC · Apr 5, 2024VulnerabilityCVE-2023-46805CVE-2024-21887CVE-2024-2189347
Hugging Face, the GitHub of AI, hosted code that backdoored user devicesArs Technica · Security·Mar 1, 18:02 UTC · Mar 1, 2024Malware42
TinyTurla-NG in-depth tooling and command and control analysisCisco Talos·Feb 22, 13:00 UTC · Feb 22, 2024Threat actor57
SSH protects the world’s most sensitive networks. It just got a lot weakerArs Technica · Security·Dec 19, 17:35 UTC · Dec 19, 2023VulnerabilityCVE-2023-48795CVE-2023-46445CVE-2023-4644647
Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocolKaspersky Securelist·Dec 14, 13:00 UTC · Dec 14, 2023Exploit / PoCCVE-2017-563860
Qubitstrike Targets Jupyter Notebooks with Crypto Mining and Rootkit CampaignThe Hacker News·Oct 18, 11:42 UTC · Oct 18, 2023Malware42
Stayin' Alive campaign targets high-profile Asian government and telecom entities. Is it linked to ToddyCat APT?Security Affairs·Oct 13, 17:50 UTC · Oct 13, 2023Threat actor57
Trigona Ransomware targets Microsoft SQL serversSecurity Affairs·Apr 20, 07:03 UTC · Apr 20, 2023Ransomware57
An Early Interview With The Dark Overlord: The Hacking Group That Forever Changed Cyber ExtortionThe Record·Nov 17, 01:18 UTC · Nov 17, 2022Ransomware57
News URSNIF variant doesn't support banking featuresSecurity Affairs·Oct 21, 07:50 UTC · Oct 21, 2022Ransomware57
Three flaws allow attackers to bypass UEFI Secure Boot featureSecurity Affairs·Aug 13, 09:39 UTC · Aug 13, 2022Exploit / PoCCVE-2022-34301CVE-2022-34302CVE-2022-3430360
Experts uncovered a new wave of attacks conducted by Mustang PandaSecurity Affairs·May 9, 07:25 UTC · May 9, 2022Threat actor57
Threat Roundup for February 18 to February 25Cisco Talos·Feb 24, 11:00 UTC · Feb 24, 2022Ransomware157
Threat Roundup for February 11 to February 18Cisco Talos·Feb 18, 22:33 UTC · Feb 18, 2022Ransomware57
Conti ransomware gang targets Microsoft Exchange servers with ProxyShell exploitsSecurity Affairs·Sep 3, 17:00 UTC · Sep 3, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Necro Python bot adds new exploits and Tezos mining to its bag of tricksCisco Talos·Jun 3, 12:00 UTC · Jun 3, 2021VulnerabilityCVE-2021-3129CVE-2020-14882CVE-2017-014447
New Mirai Variant and ZHtrap Botnet Malware Emerge in the WildThe Hacker News·Mar 18, 03:14 UTC · Mar 18, 2021MalwareCVE-2020-25506CVE-2021-27561CVE-2021-27562+4 CVEs47
SUPERNOVA backdoor that emerged after SolarWinds hack is likely linked to Chinese actorsSecurity Affairs·Mar 9, 08:48 UTC · Mar 9, 2021MalwareCVE-2020-1014847
Hackers Exploit IT Monitoring Tool Centreon to Target Several French EntitiesThe Hacker News·Feb 17, 05:47 UTC · Feb 17, 2021Ransomware57
Sudo vulnerability allows attackers to gain root privileges on Linux systems (CVE-2021-3156)Help Net Security·Feb 10, 09:09 UTC · Feb 10, 2021VulnerabilityCVE-2021-315647
Malicious npm library removed from the repo due to backdoor capabilitiesSecurity Affairs·Nov 3, 10:04 UTC · Nov 3, 2020Malware42
Your best defense against ransomware: Find the early warning signsHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2020Ransomware57
A flaw in Concrete5 CMS could have allowed website takeoverSecurity Affairs·Aug 19, 06:35 UTC · Aug 19, 2020Vulnerability42