Tag: malicious
-
Cybercriminals Abuse Stack Overflow to Promote Malicious Python Package
Cybersecurity researchers have warned of a new malicious Python package that has been discovered in the Python Package Index (PyPI) repository to faci… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/cybercriminals-abuse-stackoverflow-to.html
-
300+ Times Downloaded Package from PyPI Contains Wiper Components
ReversingLabs researchers recently uncovered a malicious open-source package named xFileSyncerx on the Python Package Index (PyPI). This package, whic… First seen on gbhackers.com Jump to article: gbhackers.com/300-times-downloaded-pypi-wiper/
-
Python Developers Beware! Russian Hackers Targeting You With Malicious Packages
A malicious Python package named >>crytic-compilers
-
PHP vulnerability allows attackers to run malicious code on Windows servers
First seen on arstechnica.com Jump to article: arstechnica.com/
-
Ukraine Hit by Cobalt Strike Campaign Using Malicious Excel Files
First seen on hackread.com Jump to article: hackread.com/ukraine-cobalt-strike-attack-malicious-excel-files/
-
Malicious use of BoxedApp tool on the rise
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-use-of-boxedapp-tool-on-the-rise
-
How DataDome Protects AI Apps from Prompt Injection Denial of Wallet Attacks
LLM prompt injection and denial of wallet attacks are new ways malicious actors can attack your company through generative AI apps, such as a chatbot…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/how-datadome-protects-ai-apps-from-prompt-injection-denial-of-wallet-attacks/
-
Beware Of Phishing Emails Prompting Execution Via Paste (CTRL+V)
Phishing attackers are distributing malicious HTML files as email attachments, containing code designed to exploit users by prompting them to directly… First seen on gbhackers.com Jump to article: gbhackers.com/phishing-emails-paste-execution/
-
WordPress Plugin Exploited to Steal Credit Card Data from E-commerce Sites
Unknown threat actors are abusing lesser-known code snippet plugins for WordPress to insert malicious PHP code in victim sites that are capable of har… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/wordpress-plugin-exploited-to-steal.html
-
TotalRecall shows how easily data collected by Windows Recall can be stolen
Ethical hacker Alexander Hagenah has created TotalRecall, a tool that demonstrates how malicious individuals could abuse Windows’ newly announced Reca… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/05/totalrecall-windows-recall-abuse/
-
Cybersecurity Training Reduces Phishing Threats With Numbers to Prove It
Train people. It makes a difference. In organizations without security awareness training, 34% of employees are likely to click on malicious links or … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/cybersecurity-training-reduces-phishing-threats-with-numbers-to-prove-it/
-
Threat Actors Weaponize Excel Files To Attack Windows Machines
Attackers are using malicious Excel files with VBA macros to deploy DLLs and ultimately install Cobalt Strike on compromised Windows machines, which u… First seen on gbhackers.com Jump to article: gbhackers.com/threat-actors-weaponize-excel-cobalt-strike/
-
Developers Beware Of Malicious npm Package Delivers Sophisticated RAT
Hackers have multiple reasons for abusing malicious npm packages, as they can first use popular open-source libraries as a medium for distributing mal… First seen on gbhackers.com Jump to article: gbhackers.com/developers-beware-malicious-npm-package-rat/
-
Hackers Hijack High-Profile TikTok Accounts in Zero-Day Cyberattack
Malicious actors recently hacked high-profile TikTok accounts of big companies and celebrities and exploited a zero-day vulnerability in TikTok’s dire… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/tiktok-zero-day-vulnerability/
-
Malicious payloads spread via fraudulent browser updates
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-payloads-spread-via-fraudulent-browser-updates
-
MS Exchange Server Flaw: Keylogger Deployment Revealed
In a recent revelation, an unidentified malicious actor has been exploiting vulnerabilities in Microsoft Exchange Server to infiltrate systems with a … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/ms-exchange-server-flaw-keylogger-deployment-revealed/
-
Russian Threat Groups Turn Eyes to the Paris Olympic Games
Russian threat groups are using old tactics and generative AI to run malicious disinformation campaigns meant to discredit the Paris Olympic Games, Fr… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/russian-threat-groups-turn-eyes-to-the-paris-olympic-games/
-
90+ Malicious Apps Totaling 5.5M Downloads Lurk on Google Play
First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/90-malicious-apps-55-million-downloads-google-play
-
Developers Beware Of Malicious npm Package That Delivers Sophisticated RAT
Hackers have multiple reasons for abusing malicious npm packages, as they can first use popular open-source libraries as a medium for distributing mal… First seen on gbhackers.com Jump to article: gbhackers.com/developers-beware-malicious-npm-package-rat/
-
VirusTotal Celebrates 20th Anniversary, What’s Next?
VirusTotal, a leading online service for analyzing files and URLs for viruses, worms, trojans, and other malicious content, is celebrating its 20th an… First seen on gbhackers.com Jump to article: gbhackers.com/virustotal-celebrates-anniversary/
-
#Infosec2024: Why Human Risk Management is Cybersecurity’s Next Step for Awareness
With most cyber-attacks still involving a non-malicious human element, it is clear that awareness training alone is insufficient, this is where human … First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/human-risk-management/
-
Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors
Malicious campaign exploits high-severity XSS flaws in three WordPress plugins to backdoor websites. The post s campaign exploits high-severity XSS fl… First seen on securityweek.com Jump to article: www.securityweek.com/critical-wordpress-plugin-flaws-exploited-to-inject-malicious-scripts-and-backdoors/
-
Discord facing deluge of malicious links
Tags: maliciousFirst seen on scmagazine.com Jump to article: www.scmagazine.com/brief/discord-facing-deluge-of-malicious-links
-
North Korea’s ‘Moonstone Sleet’ targets victims with malicious tools
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/north-koreas-moonstone-sleet-targets-victims-with-malicious-tools
-
Cybercriminals pose as helpful Stack Overflow users to push malware
Cybercriminals are abusing Stack Overflow in an interesting approach to spreading malware, answering users’ questions by promoting a malicious PyPi pa… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/
-
Phishing with Cloudflare Workers: Transparent Phishing and HTML Smuggling
Phishing campaigns are abusing Cloudflare workers in two ways, where one injects malicious content hidden by HTML smuggling, similar to Azorult malwar… First seen on gbhackers.com Jump to article: gbhackers.com/phishing-with-cloudflare-workers/
-
WordPress Plugin abused to install e-skimmers in e-commerce sites
Threat actors are exploiting a WordPress plugin to insert malicious PHP code in e-commerce sites and steal credit card data. Sucuri researchers observ… First seen on securityaffairs.com Jump to article: securityaffairs.com/163777/malware/wordpress-plugin-insert-e-skimmer.html
-
Malicious Minesweeper clone used to infiltrate financial organizations
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-minesweeper-clone-used-to-infiltrate-financial-organizations
-
Malicious PyPI Package ‘Pytoileur’ Targets Windows and Leverages Stack Overflow for Distribution
Another day, another PyPI malware package. But this one has a new way to (try to) sneak into your computer. The post day, another PyPI malware package… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/malicious-pypi-package-pytoileur-targets-windows-and-leverages-stack-overflow-for-distribution/
-
Over 90 malicious Android apps with 5.5M installs found on Google Play
Over 90 malicious Android apps were found installed over 5.5 million times through Google Play to deliver malware and adware, with the Anatsa banking … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-90-malicious-android-apps-with-55m-installs-found-on-google-play/

