Latest Cybersecurity News and Articles


GuardZoo Malware Targets Over 450 Middle Eastern Military Personnel

09 July 2024
Military personnel from Middle East countries are the target of an ongoing surveillanceware operation that delivers an Android data-gathering tool called GuardZoo. The campaign, believed to have commenced as early as October 2019, has been attributed to a Houthi-aligned threat actor based on the application lures, command-and-control (C2) server logs, targeting footprint, and the attack

New Mallox Ransomware Variant Targets Linux Systems

09 July 2024
A new variant of Mallox ransomware has been discovered by cybersecurity researchers at Uptycs, targeting Linux systems with custom encryption and a builder web panel. A custom Python script called web_server.py is used to deliver the ransomware.

Splunk Addresses Critical Vulnerabilities in Enterprise and Cloud Platforms

09 July 2024
Splunk has released a set of security updates to address 16 vulnerabilities in Splunk Enterprise and Cloud Platform, including high-severity issues. CVE-2024-36985 allows remote code execution via External Lookup in Splunk Enterprise.

Update: Network Segmentation Hobbled Midnight Blizzard's Attack on TeamViewer

09 July 2024
The company revealed that their corporate IT network, production environment, and TeamViewer connectivity platform are segmented to prevent unauthorized access. Immediate remediation measures were effective in blocking suspicious activity.

Increase in the Exploitation of Microsoft SmartScreen Vulnerability

09 July 2024
Cyble Research and Intelligence Labs (CRIL) has identified an increase in the exploitation of the Microsoft SmartScreen vulnerability (CVE-2024-21412) through an active campaign targeting regions like Spain, the US, and Australia.

Critical Infrastructure Providers Seek Guardrails on Scope, Timeline for CIRCIA Rules

09 July 2024
Critical infrastructure providers are urging federal officials for more flexibility in reporting cyber incidents within the first 72 hours under the Cyber Incident Reporting for Critical Infrastructure Act.

The NCSC and partners issue alert about evolving techniques used by China state-sponsored cyber attacks

09 July 2024
APT40 is one of the cyber actors that has embraced the trend of using SoHo devices to launch attacks

Turning Jenkins Into a Cryptomining Machine From an Attacker's Perspective

09 July 2024
Attackers can leverage the Jenkins Script Console to execute malicious Groovy scripts, leading to cybercriminal activities such as the deployment of cryptocurrency miners.

As Cyber Command Evolves, Its Novel Malware Alert System Fades Away

09 July 2024
The shift away from public disclosure on Twitter is part of an evolution in how the CNMF communicates cyber threat information. The command now focuses on working closely with industry partners to share information effectively and efficiently.

CISA adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalog

09 July 2024
The flaw allows an attacker to execute arbitrary commands as root on the affected device's operating system. Only attackers with administrator credentials can successfully exploit this vulnerability.

Cybersecurity Agencies Warn of China-linked APT40's Rapid Exploit Adaptation

09 July 2024
Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. have released a joint advisory about a China-linked cyber espionage group called APT40, warning about its ability to co-opt exploits for newly disclosed security flaws within hours or days of public release. "APT 40 has previously targeted organizations in various countries, including

Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories

09 July 2024
Unknown threat actors have been found propagating trojanized versions of jQuery on npm, GitHub, and jsDelivr in what appears to be an instance of a "complex and persistent" supply chain attack. "This attack stands out due to the high variability across packages," Phylum said in an analysis published last week. "The attacker has cleverly hidden the malware in the seldom-used 'end' function of

New APT Group "CloudSorcerer" Targets Russian Government Entities

08 July 2024
A previously undocumented advanced persistent threat (APT) group dubbed CloudSorcerer has been observed targeting Russian government entities by leveraging cloud services for command-and-control (C2) and data exfiltration. Cybersecurity firm Kaspersky, which discovered the activity in May 2024, the tradecraft adopted by the threat actor bears similarities with that of CloudWizard, but pointed

Patelco announces ransomware attack

08 July 2024
Patelco Credit Union announced that on June 29, 2024, the company faced a ransomware attack. Hackers gained access to its systems and blocked access.

Dark Web Malware Logs Expose 3,300 Users Linked to Child Abuse Sites

08 July 2024
An analysis of information-stealing malware logs published on the dark web has led to the discovery of thousands of consumers of child sexual abuse material (CSAM), indicating how such information could be used to combat serious crimes. "Approximately 3,300 unique users were found with accounts on known CSAM sources," Recorded Future said in a proof-of-concept (PoC) report published last week. "

Indian Government Issues Serious Warning on Phishing Scams Alleging Sexual Offenses

08 July 2024
The emails falsely accuse recipients of sexual offences, using names and seals of authorities to appear authentic. Citizens are advised not to respond to such emails and report them to authorities.

New Ransomware-as-a-Service 'Eldorado' Targets Windows and Linux Systems

08 July 2024
An emerging ransomware-as-a-service (RaaS) operation called Eldorado comes with locker variants to encrypt files on Windows and Linux systems. Eldorado first appeared on March 16, 2024, when an advertisement for the affiliate program was posted on the ransomware forum RAMP, Singapore-headquartered Group-IB said. The cybersecurity firm, which infiltrated the ransomware group, noted that its

Decryptor for DoNex, Muse, DarkRace, (fake) LockBit 3.0 Ransomware Released

08 July 2024
Avast researchers have identified a cryptographic weakness in the DoNex ransomware and its previous versions, enabling them to create a decryptor for files encrypted by these variants.

Nearly 800,000 affected by children’s hospital ransomware attack

08 July 2024
Ann & Robert H. Lurie Children’s Hospital of Chicago was impacted by a ransomware attack. 

New Variation of WordFence Evasion Malware Discovered

08 July 2024
A new variation of WordFence evasion malware has been discovered, concealing backdoors in infected WordPress environments. A suspicious plugin named "wp-engine-fast-action" was found tampering with the popular WordFence security plugin.