Tag: malicious
-
Fancy Bear sniffs out Ubiquiti router users
The authorities have warned users of Ubiquiti EdgeRouter products to take remedial action after a number of devices were hijacked into a malicious bot… First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366571816/Fancy-Bear-sniffs-out-Ubiquiti-router-users
-
Malicious Android apps facilitate device transformation into proxies
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-android-apps-facilitate-device-transformation-into-proxies
-
Beware of New Mighty Stealer That Takes Webcam Pictures Capture Cookies
A new menace has emerged that targets personal information with alarming precision. Dubbed the >>Mighty Stealer,
-
Info stealer attacks target macOS users
Experts warn of info stealer malware, including Atomic Stealer, targeting Apple macOS users via malicious ads and rogue websites. Jamf Threat Labs res… First seen on securityaffairs.com Jump to article: securityaffairs.com/161287/malware/info-stealer-malware-macos.html
-
Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects
A massive malware campaign dubbed;Sign1;has compromised over 39,000 WordPress sites in the last six months, using malicious JavaScript injections to r… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/massive-sign1-campaign-infects-39000.html
-
Malicious NuGet Package Linked to Industrial Espionage Targets Developers
Threat hunters have identified a suspicious package in the NuGet package manager that’s likely designed to target developers working with tools made b… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/malicious-nuget-package-linked-to.html
-
Hackers Claiming that EagleSpy Android RAT 3.0 Steals 2FA Google Authenticator Code
A malicious software known as EagleSpy Android RAT (Remote Access Trojan) 3.0 has been shared on a notorious online forum by a threat actor. This adva… First seen on gbhackers.com Jump to article: gbhackers.com/hackers-claiming-eaglespy-android/
-
Free VPN apps on Google Play turned Android phones into proxies
Over 15 free VPN apps on Google Play were found using a malicious software development kit that turned Android devices into unwitting residential prox… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/free-vpn-apps-on-google-play-turned-android-phones-into-proxies/
-
Hackers Exploit Calendly Links to Spread Malware on macOS
Cryptocurrency enthusiasts should be on the lookout, as malicious hackers are leveraging popular scheduling applications like Calendly to execute soph… First seen on sensorstechforum.com Jump to article: sensorstechforum.com/calendly-links-macos-malware/
-
Iran-Linked APT TA450 embeds malicious links in PDF attachments
In recent campaigns, Iran-linked APT group MuddyWater used a legitimate Remote Monitoring and Management (RMM) solution called Atera. Proofpoint resea… First seen on securityaffairs.com Jump to article: securityaffairs.com/161042/apt/iran-ta450-rmm-atera.html
-
Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers
Chinese users looking for legitimate software such as Notepad++ and VNote on search engines like Baidu are being targeted with malicious ads and bogus… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/malicious-ads-targeting-chinese-users.html
-
US Treasury Slaps Sanctions on China-Linked APT31 Hackers
The US Treasury Department sanctions a pair of Chinese hackers linked to malicious cyber operations targeting US critical infrastructure sectors. The… First seen on securityweek.com Jump to article: www.securityweek.com/us-treasury-slaps-sanctions-on-china-linked-apt31-hackers/
-
Researchers Detail Kubernetes Vulnerability That Enables Windows Node Takeover
Details have been made public about a now-patched high-severity flaw in Kubernetes that could allow a malicious attacker to achieve remote code execut… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/researchers-detail-kubernetes.html
-
‘Conversation Overflow’ Cyberattacks Bypass AI Security to Target Execs
Credential-stealing emails are getting past artificial intelligence’s known good email security controls by cloaking malicious payloads within seeming… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/conversation-overflow-cyberattacks-bypass-ai-security
-
UN resolution on AI encourages measures against malicious use
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/un-resolution-on-ai-encourages-measures-against-malicious-use
-
Researchers Propose An Invisible Backdoor Attack Dubbed DEBA
As deep neural networks (DNNs) become more prevalent, concerns over their security against backdoor attacks that implant hidden malicious functionalit… First seen on gbhackers.com Jump to article: gbhackers.com/invisible-backdoor-attack-deba/
-
‘GhostRace’ Speculative Execution Attack Impacts All CPU, OS Vendors
Like Spectre, the new GhostRace exploit could give attackers a way to access sensitive information from system memory and take other malicious actions… First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ghostrace-speculative-execution-attack-cpu-os-vendors
-
Evasive Panda Cyber Attacks: Threat Actor Targets Tibetans
Cybersecurity experts at ESET have come across a malicious campaign that targets Tibetans in many countries by leveraging the website of a religious g… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/03/evasive-panda-cyber-attacks-threat-actor-targets-tibetans/
-
Alert: Cybercriminals Deploying VCURMS and STRRAT Trojans via AWS and GitHub
A new phishing campaign has been observed delivering remote access trojans (RAT) such as VCURMS and STRRAT by means of a malicious Java-based download… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/alert-cybercriminals-deploying-vcurms.html
-
Azorult Malware Abuses Google Sites To Steal Login Credentials
A new evasive Azorult campaign that uses HTML smuggling to deliver a malicious JSON payload from an external website. The JSON file is then loaded us… First seen on gbhackers.com Jump to article: gbhackers.com/azorult-malware-google-sites/
-
Hackers Exploiting Microsoft Office Templates to Execute Malicious Code
In a cyberattack campaign dubbed >>PhantomBlu,
-
WhiteSnake Stealer Checks for Mutex VM Function Before Execution
A new variant of the WhiteSnake Stealer, a formidable malware that has been updated to be more elusive and efficient in its malicious endeavors. One o… First seen on gbhackers.com Jump to article: gbhackers.com/whitesnake-stealer-checks/
-
TMChecker Tool Lowers Barrier for Malicious Hacking
rc=https://130e178e8f8ba617604b-8aedd782b7d22cfe0d1146da69a52436.ssl.cf1.rackcdn.com/tmchecker-tool-lowers-barrier-for-malicious-hacking-image_file-2-… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/tmchecker-tool-lowers-barrier-for-malicious-hacking-a-24624
-
Cyberattackers Exploit QEMU for Stealthy Network Tunneling
In recent times, malicious actors have been found using innovative techniques to infiltrate systems and networks. One such development involves abusin… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/03/cyberattackers-exploit-qemu-for-stealthy-network-tunneling/
-
Hackers Trick Users to Install Malware Via Weaponized PDF
In a sophisticated cyberattack campaign, malicious actors impersonating Colombian government agencies target individuals across Latin America. The att… First seen on gbhackers.com Jump to article: gbhackers.com/hackers-trick-users-to-install-malware-via-weaponized-pdf/
-
Chrome’s Standard Safe Browsing Now Has Real-Time URL Protection
Chrome’s standard Safe Browsing protections now provide real-time malicious site detection and Password Checkup on iOS now flags weak passwords. The p… First seen on securityweek.com Jump to article: www.securityweek.com/chromes-standard-safe-browsing-now-has-real-time-url-protection/
-
Hiring Kit: Cryptographer
In the modern digital era, where businesses experience constant and persistent attacks on their information technology infrastructure from malicious a… First seen on techrepublic.com Jump to article: www.techrepublic.com/resource-library/toolstemplates/hiring-kit-cryptographer/
-
Critical ChatGPT Plugins Flaw Let Attackers Gain Control Over Organization’s Account
Threat actors can exploit ChatGPT’s ecosystem for several illicit purposes, such as crafting prompts to generate malicious code, phishing lures, and d… First seen on gbhackers.com Jump to article: gbhackers.com/critical-chatgpt-plugins-flaw/
-
Andariel Hackers Attacking Asset Management Companies to Inject Malicious Code
The Andariel threat group was observed conducting persistent attacks against domestic businesses, specifically installing MeshAgent for remote screen … First seen on gbhackers.com Jump to article: gbhackers.com/hackers-attacking-asset-management/
-
Beware Of New Malicious PyPI Packages That Steal Wallet Passwords
Threat actors use malicious PyPI packages to infiltrate systems and execute various attacks like data exfiltration, ransomware deployment, or system c… First seen on gbhackers.com Jump to article: gbhackers.com/malicious-pypi-packages-crypto-wallets/

