Latest Cybersecurity News and Articles


Boolka Group's Modular Trojan BMANAGER Exposed

25 June 2024
The Boolka group is responsible for deploying advanced malware and conducting web attacks. They have been exploiting vulnerabilities using SQL injection attacks since 2022, targeting websites in various countries.

New Attack Uses MSC Files and Windows XSS Flaw to Breach Networks

25 June 2024
A new command execution technique called "GrimResource" has been discovered that leverages a combination of specially crafted Microsoft Saved Console (MSC) files and an unpatched Windows XSS flaw.

New Attack Technique Exploits Microsoft Management Console Files

25 June 2024
Threat actors are exploiting a novel attack technique in the wild that leverages specially crafted management saved console (MSC) files to gain full code execution using Microsoft Management Console (MMC) and evade security defenses. Elastic Security Labs has codenamed the approach GrimResource after identifying an artifact ("sccm-updater.msc") that was uploaded to the VirusTotal malware

Manufacturing Cybersecurity at Heart of New White House Guidance

25 June 2024
The U.S. Department of Energy has released a new framework of best practices for securing clean energy cyber supply chains, focusing on key technologies used in managing electricity, oil, and natural gas systems.

How to Cut Costs with a Browser Security Platform

25 June 2024
Browser security is becoming increasingly popular, as organizations understand the need to protect at the point of risk - the browser. Network and endpoint solutions are limited in their ability to protect from web-borne threats like phishing websites or malicious browser extensions. They also do not protect from internal data exfiltration, like employees pasting sensitive data to ChatGPT. As it

Is the Cybersecurity Industry Ready for AI?

25 June 2024
AI is not new to cybersecurity, but generative AI is causing concern as it impacts organizations. A study found that AI-generated threats have already affected 75% of organizations, yet 60% are not prepared to handle AI-based attacks.

New Cyberthreat 'Boolka' Deploying BMANAGER Trojan via SQLi Attacks

25 June 2024
A previously undocumented threat actor dubbed Boolka has been observed compromising websites with malicious scripts to deliver a modular trojan codenamed BMANAGER. "The threat actor behind this campaign has been carrying out opportunistic SQL injection attacks against websites in various countries since at least 2022," Group-IB researchers Rustam Mirkasymov and Martijn van den Berk said in a

European Union Sanctions Russian State Hackers

25 June 2024
The European Union has imposed sanctions on four Russian hackers from the country's domestic intelligence agency, including two military officers. These individuals were involved in "hack and leak" operations against Western governments.

StealC and Vidar Malware Campaign Identified

25 June 2024
During an analysis of a malware sample containing StealC and Vidar, it was discovered that attackers were using Steam to hide their C2 location and disguise malicious activity as regular traffic.

Google Introduces Project Naptime for AI-Powered Vulnerability Research

25 June 2024
Google has developed a framework known as Project Naptime, which utilizes a large language model (LLM) for vulnerability research. The framework allows an AI agent to simulate the actions and workflow of a human security researcher.

Wikileaks' Julian Assange Released from U.K. Prison, Heads to Australia

25 June 2024
WikiLeaks founder Julian Assange has been freed in the U.K. and has departed the country after serving more than five years in a maximum security prison at Belmarsh for what was described by the U.S. government as the "largest compromises of classified information in the history" of the country. Capping off a 14-year legal saga, Assange, 52, pleaded guilty to one criminal count of conspiring to

4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree

24 June 2024
Four Vietnamese nationals with ties to the FIN9 cybercrime group have been indicted in the U.S. for their involvement in a series of computer intrusions that caused over $71 million in losses to companies. The defendants, Ta Van Tai (aka Quynh Hoa and Bich Thuy), Nguyen Viet Quoc (aka Tien Nguyen), Nguyen Trang Xuyen, and Nguyen Van Truong (aka Chung Nguyen), have been accused of conducting

Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

24 June 2024
Multiple WordPress plugins have been backdoored to inject malicious code that makes it possible to create rogue administrator accounts with the aim of performing arbitrary actions. "The injected malware attempts to create a new administrative user account and then sends those details back to the attacker-controlled server," Wordfence security researcher Chloe Chamberland said in a Monday alert.

5 underappreciated benefits of AI in cyber security

24 June 2024
EXECUTIVE SUMMARY: The benefits of AI in cyber security are phenomenal, yet not sufficiently well-known. In this article, get insights that cut through the noise; that show you how to put AI to work in ways that will yield worthwhile results. AI-powered cyber security solutions drive proactive threat prevention, accelerated response times, reduced false positives, […] The post 5 underappreciated benefits of AI in cyber security appeared first on CyberTalk.

'Mirai-Like' Botnet Observed Attacking EOL Zyxel NAS devices

24 June 2024
The Shadowserver Foundation, in collaboration with top security agencies and vendors, detected multiple remote command execution attempts by a Mirai-like botnet. It advised Zyxel NAS owners to actively search for signs of compromise.

Coinstats Says North Korean Hackers Breached 1,590 Crypto Wallets

24 June 2024
CoinStats, a crypto portfolio app with 1.5 million users, experienced a significant security breach affecting 1,590 cryptocurrency wallets. North Korean threat actors are suspected to be behind the attack.

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

24 June 2024
The vulnerability, tracked as CVE-2024-37032 and dubbed Probllama, was patched in version 0.1.34 released on May 7, 2024. Ollama is a service used for running large language models locally on Windows, Linux, and macOS devices.

Google Introduces Project Naptime for AI-Powered Vulnerability Research

24 June 2024
Google has developed a new framework called Project Naptime that it says enables a large language model (LLM) to carry out vulnerability research with an aim to improve automated discovery approaches. "The Naptime architecture is centered around the interaction between an AI agent and a target codebase," Google Project Zero researchers Sergei Glazunov and Mark Brand said. "The agent is provided

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

24 June 2024
Cybersecurity researchers have detailed a now-patch security flaw affecting the Ollama open-source artificial intelligence (AI) infrastructure platform that could be exploited to achieve remote code execution. Tracked as CVE-2024-37032, the vulnerability has been codenamed Probllama by cloud security firm Wiz. Following responsible disclosure on May 5, 2024, the issue was addressed in version

Researchers Say Microsoft Power BI Reports Expose Sensitive Data on the Web

24 June 2024
The vulnerability in Power BI reports allows access to underlying raw data when shared with others. This includes detailed records, hidden tables, non-displayed columns, and filtered-out data.