Tag: malicious
-
3,000 >>ghost accounts<< on GitHub spreading malware
In the past, cyber criminals directly distributed malware on GitHub using encrypted scripting code or malicious executables. But now threat actors are… First seen on securityintelligence.com Jump to article: securityintelligence.com/news/3000-ghost-accounts-github-malware/
-
NCSC exposes Chinese company running malicious Mirai botnet
The NCSC and its Five Eyes allies have published details of the activities of a China-based cyber security company that is operating a Mirai IoT botne… First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366611295/NCSC-exposes-Chinese-company-running-malicious-Mirai-botnet
-
Malicious Apps Rake in Downloads on Google Play
First seen on scworld.com Jump to article: www.scworld.com/brief/malicious-apps-rake-in-downloads-on-google-play
-
New ConfusedPilot Attack Targets AI Systems with Data Poisoning
Researchers have discovered a new cyber-attack method called ConfusedPilot that can manipulate AI-generated responses by injecting malicious content i… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/confusedpilot-attack-targets-ai/
-
Eight Million Users Install 200+ Malicious Apps from Google Play
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/eight-million-download-200-mal/
-
Cerberus Android Banking Trojan Deployed in New Multi-Stage Malicious Campaign
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cerberus-android-banking-trojan/
-
Malicious ads exploited Internet Explorer zero day to drop malware
The North Korean hacking group ScarCruft launched a large-scale attack in May that leveraged an Internet Explorer zero-day flaw to infect targets with… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-ads-exploited-internet-explorer-zero-day-to-drop-malware/
-
EDRSilencer red team tool used in attacks to bypass security
A tool for red-team operations called EDRSilencer has been observed in malicious incidents attempting to identify security tools and mute their alerts… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/edrsilencer-red-team-tool-used-in-attacks-to-bypass-security/
-
OpenAI Disrupts 20+ Malicious Operations, Including Election Interference and Malware Development
OpenAI has published a report detailing its efforts to combat the misuse of its AI models, revealing the disruption of over 20 operations linked to cy… First seen on securityonline.info Jump to article: securityonline.info/openai-disrupts-20-malicious-operations-including-election-interference-and-malware-development/
-
Over 200 malicious apps on Google Play downloaded millions of times
Google Play, the official store for Android, distributed over a period of one year more than 200 malicious applications, which cumulatively counted ne… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-200-malicious-apps-on-google-play-downloaded-millions-of-times/
-
Command-jacking used to launch malicious code on open-source platforms
First seen on scworld.com Jump to article: www.scworld.com/news/command-jacking-used-to-launch-malicious-code-on-open-source-platforms
-
Sonatype Reports 156% Increase in OSS Malicious Packages
A new Sonatype report reveals a 156% surge in open source malware, with over 704,102 malicious packages identified since 2019, as OSS adoption continu… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/156-increase-in-oss-malicious/
-
Malicious packages in open-source repositories are surging
First seen on cyberscoop.com Jump to article: cyberscoop.com/open-source-security-supply-chain-sonatype/
-
OpenAI confirms threat actors use ChatGPT to write malware
OpenAI has disrupted over 20 malicious cyber operations abusing its AI-powered chatbot, ChatGPT, for debugging and developing malware, spreading misin… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-confirms-threat-actors-use-chatgpt-to-write-malware/
-
WordPress LiteSpeed Cache Plugin Security Flaw Exposes Sites to XSS Attacks
A new high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could enable malicious actors to execute arbitra… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/wordpress-litespeed-cache-plugin.html
-
New Generation of Malicious QR Codes Uncovered by Researchers
Barracuda researchers have identified a new wave of QR code phishing attacks that evade traditional security measures and pose a significant threat to… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-gen-malicious-qr-codes/
-
Malicious Chrome Extensions Skate Past Google’s Updated Security
Google’s Manifest V3 offers better privacy and security controls for browser extensions than the previous M2, but too many lax permissions and gaps re… First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/malicious-chrome-extensions-past-google-updated-security
-
Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit
Cybersecurity researchers have disclosed that 5% of all Adobe Commerce and Magento stores have been hacked by malicious actors by exploiting a securit… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/alert-adobe-commerce-and-magento-stores.html
-
DNS Tunneling: The Hidden Threat Exploited by Cyberattackers
Cyber attackers are increasingly exploiting DNS tunneling as a covert means to conduct malicious activities, evade detection, and exfiltrate data. Pal… First seen on securityonline.info Jump to article: securityonline.info/dns-tunneling-the-hidden-threat-exploited-by-cyberattackers/
-
5 Must-Have Tools for Effective Dynamic Malware Analysis
Dynamic malware analysis is a key part of any threat investigation. It involves executing a sample of a malicious program in the isolated environment … First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/5-must-have-tools-for-effective-dynamic.html
-
PyPI Repository Found Hosting Fake Crypto Wallet Recovery Tools That Steal User Data
A new set of malicious packages has been unearthed in the Python Package Index (PyPI) repository that masqueraded as cryptocurrency wallet recovery an… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/pypi-repository-found-hosting-fake.html
-
New Cryptojacking Attack Targets Docker API to Create Malicious Swarm Botnet
Cybersecurity researchers have uncovered a new cryptojacking campaign targeting the Docker Engine API with the goal of co-opting the instances to join… First seen on thehackernews.com Jump to article: thehackernews.com/2024/10/new-cryptojacking-attack-targets-docker.html
-
Malicious Pixels: Criminals Revamp QR Code Phishing Attacks
Attackers Use ASCII Characters to Create Tough-to-Spot QR Codes, Barracuda Warns. Attackers are moving beyond using QR code images added to phishing e… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/malicious-pixels-criminals-revamp-qr-code-phishing-attacks-a-26487
-
Crypto Scam App Disguised as WalletConnect Steals $70K in Five-Month Campaign
Cybersecurity researchers have discovered a malicious Android app on the Google Play Store that enabled the threat actors behind it to steal approxima… First seen on thehackernews.com Jump to article: thehackernews.com/2024/09/crypto-scam-app-disguised-as.html
-
Google Blocked Malicious Sideloading Apps for Indian Users
Google has launched a pilot program to block malicious sideloading apps. This initiative is part of Google’s ongoing efforts to protect users from fin… First seen on gbhackers.com Jump to article: gbhackers.com/google-blocked-malicious-sideloading-apps/
-
Indian Threat Actors Target South And East Asian Entities
Recent reports have revealed that Indian threat actors are using multiple cloud service providers for malicious purposes. The hacker activities are ma… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/10/indian-threat-actors-target-south-and-east-asian-entities/
-
Cloud Penetration Testing Checklist 2024
Cloud Penetration Testing is a method of actively checking and examining the Cloud system by simulating the attack from the malicious code. Cloud comp… First seen on gbhackers.com Jump to article: gbhackers.com/cloud-computing-penetration-testing-checklist-important-considerations/
-
Linux Malware perfctl Attacking Millions of Linux Servers
Researchers have uncovered a sophisticated Linux malware, dubbed >>perfctl,
-
Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware
As many as 25 websites linked to the Kurdish minority have been compromised as part of a watering hole attack designed to harvest sensitive informatio… First seen on thehackernews.com Jump to article: thehackernews.com/2024/09/watering-hole-attack-on-kurdish-sites.html
-
Millions of Enterprises at Risk: SquareX Shows How Malicious Extensions Bypass Google’s MV3 Restrictions
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/10/millions-of-enterprises-at-risk-squarex-shows-how-malicious-extensions-bypass-googles-mv3-restrictions/

