Guardicore extends microsegmentation and zero trust security to protect legacy infrastructure and IT
Threats Making WAVs - Incident Response to a Cryptomining Attack
Guardicore researchers dissect a cryptomining attack that hid a cryptominer inside WAV files, mapping the full infection chain and response steps.
Guardicore security researchers present a full analysis of a cryptomining attack that concealed a cryptominer inside WAV audio files. The report documents the complete attack chain from detection through infection, network propagation, and malware analysis. It also includes recommendations for optimizing incident response processes in data centers.
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers the PLEASE_READ_ME ransomware campaign targeting MySQL servers, using double extortion and publishing stolen victim data.
Guardicore Labs at Akamai uncovered an opportunistic ransomware campaign dubbed PLEASE_READ_ME that targets MySQL servers. The attackers employ double extortion, publishing stolen data to pressure victims into paying. The campaign is devastating internet-facing MySQL deployments, making exposed database servers the primary at-risk population.
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
Guardicore researchers detail the Nansh0u campaign's growing arsenal, with three attacks traced to South African IPs hosted by VolumeDrive.
Guardicore security researchers analyzed three attacks detected in early April through the Guardicore Global Sensor Network (GGSN). All three attacks originated from source IP addresses in South Africa hosted by the VolumeDrive ISP. The write-up catalogs the expanding arsenal and tooling used by the Nansh0u campaign attackers and includes indicators of compromise.