Latest Cybersecurity News and Articles
19 January 2024
In a recent incident, a malicious package called "oscompatible" was uploaded to the npm registry. The package was found to contain a sophisticated remote access trojan for Windows machines.
19 January 2024
The CISA and the FBI issued a joint warning about the Androxgh0st malware botnet, indicating that threat actors are building a botnet network to extract cloud credentials. Threat actors were also observed using stolen AWS credentials to create new users and user policies on a vulnerable website. The agencies have released IOCs associated with the Androxgh0st malware operation and recommended mitigations.
19 January 2024
In the current digital landscape, data has emerged as a crucial asset for organizations, akin to currency. It’s the lifeblood of any organization in today's interconnected and digital world. Thus, safeguarding the data is of paramount importance. Its importance is magnified in on-premises Exchange Server environments where vital business communication and emails are stored and managed.
In
19 January 2024
Kansas State University is managing a cybersecurity incident that has disrupted various network systems, including VPN, email services, and video platforms, impacting the educational continuity for its 20,000 students and 1,400 academic personnel.
19 January 2024
The stress caused by ransomware attacks can lead to burnout and sickness among IT teams, potentially resulting in personnel leaving their jobs or being absent on sick leave.
19 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in Ivanti Endpoint Manager Mobile and MobileIron Core to its list of actively exploited vulnerabilities.
19 January 2024
The Remcos RAT is being distributed in South Korea through webhards, leveraging adult-themed games as a disguise. In this tactic, users are deceived into opening files posing as adult games. This campaign emphasizes the need for heightened vigilance when downloading files from the internet.
19 January 2024
Mary Callahan Erdoes, head of the bank’s asset and wealth management division, highlighted a significant rise in cybercrime, with a 65% increase in fraud losses for U.S. financial institutions from 2022 to 2023.
19 January 2024
Oleria, a company specializing in adaptive and autonomous identity security solutions, has secured $33.1 million in Series A funding, led by Evolution Equity Partners with participation from Salesforce Ventures, Tapestry VC, and Zscaler.
19 January 2024
Russian state hackers from Center 18, a unit within Russia’s Federal Security Service (FSB), have been using sophisticated tactics to deploy backdoors on the devices of targets in NATO countries and Ukraine.
19 January 2024
A report by SecurityScorecard revealed that wealthier regions have better cybersecurity defenses and lower cyber risk compared to poorer regions. The study found that organizations in regions with lower GDP are more likely to suffer data breaches.
19 January 2024
The attack on Kyivstar, believed to have been carried out by Sandworm APT, aimed to cause a destructive impact, deliver a psychological blow, and gather intelligence, marking a significant incident in the ongoing cyberwar between Ukraine and Russia.
19 January 2024
A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines.
The package, named "oscompatible," was published on January 9, 2024, attracting a total of 380 downloads before it was taken down.
oscompatible included a "few strange binaries," according to software supply chain security firm Phylum, including a single
19 January 2024
The malware employs tactics such as lateral movement via PSEXEC, malicious download and execution, proxy setup, and RDP configuration to exfiltrate data and establish command and control communications.
18 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a now-patched critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core to its Known Exploited Vulnerabilities (KEV) catalog, stating it's being actively exploited in the wild.
The vulnerability in question is CVE-2023-35082 (CVSS score: 9.8), an authentication bypass
18 January 2024
The bot gains access to the databases, deletes all tables and databases, and leaves a ransom note demanding payment for data recovery. However, the bot only saves a small portion of the data, even if the ransom is paid.
18 January 2024
The new campaign by TA866 involved a large volume of emails with attached PDFs containing OneDrive URLs that initiated a multi-step infection chain leading to malware payload.
18 January 2024
Vulnerable Docker services are being targeted by a novel campaign in which the threat actors are deploying XMRig cryptocurrency miner as well as the 9Hits Viewer software as part of a multi-pronged monetization strategy.
"This is the first documented case of malware deploying the 9Hits application as a payload," cloud security firm Cado said, adding the development is a sign that adversaries are
18 January 2024
Attackers are using off-the-shelf images from Dockerhub to spread malware, with the 9Hits app visiting various websites and the XMRig miner disabled from visiting crypto-related sites to prevent analysis.
18 January 2024
Continuous integration and delivery misconfigurations in TensorFlow could have been exploited for supply chain attacks, allowing malicious code injection and compromise of GitHub and PyPi releases.