Tag: malicious
-
IT pros targeted with malicious Google ads for PuTTY, FileZilla
An ongoing malvertising campaign is targeting IT administrators looking to download system utilities such as PuTTY (a free SSH and Telnet client) and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/10/malvertising-putty-filezilla/
-
Zscaler Buys Airgap Networks to Fuel Segmentation in IoT, OT
Deal Will Thwart Lateral Movement of Malicious Traffic Inside of Corporate Networks. Zscaler purchased an agentless segmentation startup founded by lo… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/zscaler-buys-airgap-networks-to-fuel-segmentation-in-iot-ot-a-24843
-
Client-Side Exploitation: Poisoning WebDAV+URL+LNK to Deliver Malicious Payloads
WebDAV incidents simulate an offensive attack employing a WebDAV server to distribute malware to a client PC. Attackers store malicious payloads and a… First seen on gbhackers.com Jump to article: gbhackers.com/poisoning-webdavurllnk/
-
Latrodectus Uses Sandbox Evasion Techniques To Launch Malicious Payloads
Tags: maliciousFirst seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35749/Latrodectus-Uses-Sandbox-Evasion-Techniques-To-Launch-Malicious-Payloads.html
-
Why Intelligence Sharing Is Vital to Building a Robust Collective Cyber Defense Program
With automated, detailed, contextualized threat intelligence, organizations can better anticipate malicious activity and utilize intelligence to speed… First seen on securityweek.com Jump to article: www.securityweek.com/why-intelligence-sharing-is-vital-to-building-a-robust-collective-cyber-defense-program/
-
Malicious Apps Caught Secretly Turning Android Phones into Proxies for Cybercriminals
Several malicious Android apps that turn mobile devices running the operating system into residential proxies (RESIPs) for other threat actors have be… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/malicious-apps-caught-secretly-turning.html
-
Malicious PowerShell script pushing malware looks AI-written
A threat actor is using a PowerShell script that was likely created with the help of an artificial intelligence system such as OpenAI’s ChatGPT, Googl… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-powershell-script-pushing-malware-looks-ai-written/
-
Malicious Latrodectus Downloader Picks Up Where QBot Left Off
Tags: maliciousFirst seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/new-loader-takes-over-where-qbot-left-off
-
ScrubCrypt used to drop VenomRAT along with many malicious plugins
Researchers discovered a sophisticated multi-stage attack that leverages ScrubCrypt to drop VenomRAT along with many malicious plugins. Fortinet resea… First seen on securityaffairs.com Jump to article: securityaffairs.com/161639/cyber-crime/scrubcrypt-venomrat-plugins.html
-
Malicious Visual Studio projects on GitHub push Keyzetsu malware
Threat actors are abusing GitHub automation features and malicious Visual Studio projects to push a new variant of the Keyzetsu clipboard-hijacking ma… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-visual-studio-projects-on-github-push-keyzetsu-malware/
-
Beware of Encrypted Phishing Attack With Weaponized SVG Files
Attackers are now leveraging encrypted phishing emails that utilize Scalable Vector Graphics (SVG) files to execute malicious JavaScript code. The phi… First seen on gbhackers.com Jump to article: gbhackers.com/beware-of-encrypted-phishing-attack/
-
Hackers Target macOS Users with Malicious Ads Spreading Stealer Malware
Malicious ads and bogus websites are acting as a conduit to deliver two different stealer malware, including Atomic Stealer, targeting Apple macOS use… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/hackers-target-macos-users-with.html
-
New SharePoint Technique Lets Hackers Bypass Security Measures
Two new techniques uncovered in SharePoint enable malicious actors to bypass traditional security measures and exfiltrate sensitive data without trigg… First seen on gbhackers.com Jump to article: gbhackers.com/sharepoint-technique-bypas/
-
Ahoi Attacks New Attack Breaking VMs With Malicious Interrupts
Ahoy, which is often associated with communicating to ships, has now been playfully adopted in pirate language. We coin ‘Ahoi,’ an anagram of ‘Iago,’ … First seen on gbhackers.com Jump to article: gbhackers.com/ahoi-attacks-confidential-vms/
-
PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers
The maintainers of the Python Package Index (PyPI) repository briefly suspended new user sign-ups following an influx of malicious projects uploaded a… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/pypi-halts-sign-ups-amid-surge-of.html
-
PyPI Malicious Package Uploads Used To Target Developers
In light of the recent cybercriminal activity, new user sign-ups on the PyPI platform were halted. Currently, an increase in PyPI malicious package up… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/pypi-malicious-package-uploads-used-to-target-developers/
-
Cybercriminal adoption of browser fingerprinting
Browser fingerprinting is one of many tactics phishing site authors use to evade security checks and lengthen the lifespan of malicious campaigns. Whi… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/04/05/browser-fingerprinting/
-
Confidential VMs Hacked via New Ahoi Attacks
New Ahoi attacks Heckler and WeSee target AMD SEV-SNP and Intel TDX with malicious interrupts to hack confidential VMs. The post attacks Heckler and … First seen on securityweek.com Jump to article: www.securityweek.com/confidential-vms-hacked-via-new-ahoi-attacks/
-
Cisco IOS Vulnerability Allows DOS Attacks via Malicious Traffic
Cisco recently fixed a high-severityvulnerability in Cisco IOS Software for Catalyst 6000 Series Switches, which could lead to a denial of service (Do… First seen on gbhackers.com Jump to article: gbhackers.com/cisco-ios-vulnerability-dos-attacks/
-
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions
A now-patched security flaw in the Microsoft Edge web browser could have been abused to install arbitrary extensions on users’ systems and carry out m… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/microsoft-edge-bug-could-have-allowed.html
-
Cybercriminals Weigh Options for Using LLMs: Buy, Build, or Break?
While some cybercriminals have bypassed guardrails to force legitimate AI models to turn bad, building their own malicious chatbot platforms and makin… First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/cybercriminals-options-lms-buy-build-break
-
Critical Progress Flowmon Vulnerability Let Attackers Inject Malicious Code
A new critical vulnerability has been discovered in Progress Flowmon, assigned with CVE-2024-2389. Progress Flowmon is a Cloud Application Performance… First seen on gbhackers.com Jump to article: gbhackers.com/progress-flowmon-vulnerability/
-
AI Package Hallucination Hackers Abusing ChatGPT, Gemini to Spread Malware
The research investigates the persistence and scale of AI package hallucination, a technique where LLMs recommend non-existent malicious packages. The… First seen on gbhackers.com Jump to article: gbhackers.com/ai-package-hallucination/
-
New Latrodectus malware replaces IcedID in network breaches
A relatively new malware called Latrodectus is believed to be an evolution of the IcedID loader, seen in malicious email campaigns since November 2023… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-latrodectus-malware-replaces-icedid-in-network-breaches/
-
‘Latrodectus’ uses sandbox evasion techniques to launch malicious payloads
Tags: maliciousFirst seen on scmagazine.com Jump to article: www.scmagazine.com/news/latrodectus-uses-sandbox-evasion-techniques-to-launch-malicious-payloads
-
TheMoon Malware Rises Again with Malicious Botnet for Hire
First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/themoon-malware-rises-malicious-botnet-for-hire
-
XSS flaw in WordPress WP-Members Plugin can lead to script injection
A cross-site scripting vulnerability (XXS) in the WordPress WP-Members Membership plugin can lead to malicious script injection. Researchers from Defi… First seen on securityaffairs.com Jump to article: securityaffairs.com/161407/hacking/wordpress-wp-members-plugin-xss.html
-
Hackers Hijacked Notepad++ Plugin to Execute Malicious Code
The AhnLab Security Intelligence Center (ASEC) has detected a sophisticated cyberattack targeting users of the popular text and code editor, Notepad++… First seen on gbhackers.com Jump to article: gbhackers.com/hackers-hijacked-notepad-plugin-to-execute-malicious-code/
-
Gesture Jacking New Attack That Deceives Website Visitors
The Web Platform is incredibly powerful, but regrettably, malicious websites will do all in their capacity to misuse it. To prevent such exploitation,… First seen on gbhackers.com Jump to article: gbhackers.com/gesture-jacking-deceives-visitors/
-
Pervasive LLM Hallucinations Expand Code Developer Attack Surface
The tendency of popular AI-based tools to recommend nonexistent code libraries offers a bigger opportunity than thought to distribute malicious packag… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/pervasive-llm-hallucinations-expand-code-developer-attack-surface

