Tag: malicious
-
Vulnerabilities in HFS Servers Exploited by Hackers to Distribute Malware and Mine Monero
Malicious actors are targeting HTTP File Servers (HFS) from Rejetto by leveraging vulnerabilities to deploy malware and cryptocurrency mining software… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/exploiting-cve-2024-23692/
-
New Cyberthreat ‘Boolka’ Deploying BMANAGER Trojan via SQLi Attacks
A previously undocumented threat actor dubbed Boolka has been observed compromising websites with malicious scripts to deliver a modular trojan codena… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/new-cyberthreat-boolka-deploying.html
-
Over 380,000+ Hosts Embedding Polyfill JS script Linking to Malicious Domain
Over 380,000 web hosts have been found embedding a compromised Polyfill.io JavaScript script, linking to a malicious domain. This supply chain attack … First seen on gbhackers.com Jump to article: gbhackers.com/hosts-embedding-polyfill-js/
-
Malicious payloads deployed via vulnerable Rejetto HFS instances
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-payloads-deployed-via-vulnerable-rejetto-hfs-instances
-
Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts
Multiple WordPress plugins have been backdoored to inject malicious code that makes it possible to create rogue administrator accounts with the aim of… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/multiple-wordpress-plugins-compromised.html
-
Grasshopper Hackers Mimic As Penetration Testing Service To Deploy Malware
Hackers often mimic penetration testing services to disguise their malicious activities as legitimate security assessments. By imitating authorized se… First seen on gbhackers.com Jump to article: gbhackers.com/grasshopper-hackers-penetration-testing-malware-deployment/
-
Telcos Hit Hardest by Cloud Malware, Report Finds
Telecom companies are being targeted by malicious actors at an alarming rate, according to a new report by Netskope Threat Labs. The report highlights… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/06/20/telcos-hit-hardest-by-cloud-malware-report-finds/
-
Polyfill.io Supply Chain Attack Smacks Down 100K+ Websites
The site is supplying malicious code that delivers dynamically generated payloads and can lead to other attacks, after a Chinese organization bought i… First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/polyfillio-supply-chain-attack-smacks-down-100k-websites
-
Fake IT support sites push malicious PowerShell scripts as Windows fixes
Fake IT support sites promote malicious PowerShell fixes for common Windows errors, like the 0x80070643 error, to infect devices with information-stea… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-it-support-sites-push-malicious-powershell-scripts-as-windows-fixes/
-
Cyber Attackers Turn to Cloud Services to Deploy Malware
A growing number of malware operators have turned to cloud-based command and control servers to deploy malicious campaigns, Fortinet researchers found… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/attackers-cloud-services-deploy/
-
SolarWinds Serv-U Vulnerability Under Active Attack – Patch Immediately
A recently patched high-severity flaw impacting SolarWinds Serv-U file transfer software is being actively exploited by malicious actors in the wild.T… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/solarwinds-serv-u-vulnerability-under.html
-
Web scraping is not just a security or fraud problem
Bots compose 42% of overall web traffic, and 65% of these bots are malicious, according to Akamai. Negative effects of scraper bots on business operat… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/28/web-scraping-problem/
-
PQShield secures $37M more for ‘quantum resistant’ cryptography
Malicious hacking is getting increasingly sophisticated, and that’s leading to a very clear trend in security technology. To keep people and organizat… First seen on techcrunch.com Jump to article: techcrunch.com/2024/06/20/pqshield-secures-37m-more-for-quantum-resistant-cryptography/
-
Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity
Namecheap shut down polyfill.io amid reports of malicious activity, but the Chinese owner claims it has good intentions. The post p shut down polyfill… First seen on securityweek.com Jump to article: www.securityweek.com/polyfill-domain-shut-down-as-owner-disputes-accusations-of-malicious-activity/
-
Chemical Facilities Warned of Possible Data Exfiltration Following CISA Breach
CISA has informed chemical facilities that its Chemical Security Assessment Tool (CSAT) was infiltrated by a malicious actor, and potentially exfiltra… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chemical-exfiltration-cisa-breach/
-
ASUS Patches Critical Authentication Bypass Flaw in Multiple Router Models
ASUS has shipped software updates to address a critical security flaw impacting its routers that could be exploited by malicious actors to bypass auth… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/asus-patches-critical-authentication.html
-
Mailcow Mail Server Flaws Expose Servers to Remote Code Execution
Two security vulnerabilities have been disclosed in the Mailcow open-source mail server suite that could be exploited by malicious actors to achieve a… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/mailcow-mail-server-flaws-expose.html
-
New Threat Actor ‘Void Arachne’ Targets Chinese Users with Malicious VPN Installers
Chinese-speaking users are the target of a never-before-seen threat activity cluster codenamed Void Arachne that employs malicious Windows Installer (… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html
-
Emojis Control the Malware in Discord Spy Campaign
Pakistani hackers are spying (▀̿Ĺ̯▀̿ Ì¿) on the highly sensitive organizations in India by using emojis (Ô¾_Ô¾) as malicious commands (⚆á—âš… First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/emojis-control-malware-discord-spy-campaign
-
Cut & Paste Tactics Import Malware to Unwitting Victims
ClearFake and ClickFix attackers are tricking people into cutting and pasting malicious PowerShell scripts to infect their own machines with RATs and … First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/cut-paste-tactics-import-malware
-
Plugins on WordPress.org backdoored in supply chain attack
A threat actor modified the source code of at least five plugins hosted on WordPress.org to include malicious PHP scripts that create new accounts wit… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/plugins-on-wordpressorg-backdoored-in-supply-chain-attack/
-
New North Korean Actor Distributing Malicious npm Packages To Compromise Organizations
Early in 2024, North Korean threat actors persisted in using the public npm registry to disseminate malicious packages that were similar to those that… First seen on gbhackers.com Jump to article: gbhackers.com/north-korean-actor-malicious-npm-packages/
-
Malware peddlers experimenting with BPL sideloading and masking malicious payloads as PGP keys
A newly spotted campaign is leveraging BPL sideloading and other uncommon tricks to deliver the IDAT Loader (aka HijackLoader) malware and prevent its… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/26/malware-bpl-sideloading/
-
Experts observed approximately 120 malicious campaigns using the Rafel RAT
Multiple threat actors are using an open-source Android remote administration tool called Rafel RAT to target Android Devices. Check Point Research id… First seen on securityaffairs.com Jump to article: securityaffairs.com/164844/cyber-crime/multiple-threat-actors-used-rafel-rat.html
-
Several Plugins Compromised in WordPress Supply Chain Attack
Five WordPress plugins were injected with malicious code that creates a new administrative account. The post dPress plugins were injected with malicio… First seen on securityweek.com Jump to article: www.securityweek.com/several-plugins-compromised-in-wordpress-supply-chain-attack/
-
Hackers Use Windows XSS Flaw To Execute Arbitrary Command In MMC Console
Attackers are leveraging a new infection technique called GrimResource that exploits MSC files. By crafting malicious MSC files, they can achieve full… First seen on gbhackers.com Jump to article: gbhackers.com/windows-xss-flaw-mmc-command-execution/
-
From Espionage to Ransomware: Rafel RAT’s Impact on Android Security
Among the diverse array of Android malware available on the dark web markets, Rafel RAT stands out as a particularly potent tool for malicious actors…. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/decoding-rafel-rat/
-
Mystery miscreant remotely bricked 600,000 SOHO routers with malicious firmware update
First seen on theregister.com Jump to article: www.theregister.com/2024/05/31/pumoking_eclipse_remote_router_attack/

