• Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments

    Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments

    The threat actor tracked as Mustang Panda has refined its malware arsenal to include new tools in order to facilitate data exfiltration and the deployment of next-stage payloads, according to new findings from Trend Micro. The cybersecurity firm, which is monitoring the activity cluster under the name Earth Preta, said it observed “the propagation of…

    Read More

  • New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks

    New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks

    A novel side-channel attack has been found to leverage radio signals emanated by a device’s random access memory (RAM) as a data exfiltration mechanism, posing a threat to air-gapped networks. The technique has been codenamed RAMBO by Dr. Mordechai Guri, the head of the Offensive Cyber Research Lab in the Department of Software and Information…

    Read More

  • One More Tool Will Do It? Reflecting on the CrowdStrike Fallout

    One More Tool Will Do It? Reflecting on the CrowdStrike Fallout

    The proliferation of cybersecurity tools has created an illusion of security. Organizations often believe that by deploying a firewall, antivirus software, intrusion detection systems, identity threat detection and response, and other tools, they are adequately protected. However, this approach not only fails to address the fundamental issue of the attack surface but also introduces dangerous

    Read More

  • Blind Eagle Targets Colombian Insurance Sector with Customized Quasar RAT

    Blind Eagle Targets Colombian Insurance Sector with Customized Quasar RAT

    The Colombian insurance sector is the target of a threat actor tracked as Blind Eagle with the end goal of delivering a customized version of a known commodity remote access trojan (RAT) known as Quasar RAT since June 2024. “Attacks have originated with phishing emails impersonating the Colombian tax authority,” Zscaler ThreatLabz researcher Gaetano Pellegrino…

    Read More

  • Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks

    Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks

    The China-linked advanced persistent threat (APT) group known as Mustang Panda has been observed weaponizing Visual Studio Code software as part of espionage operations targeting government entities in Southeast Asia. “This threat actor used Visual Studio Code’s embedded reverse shell feature to gain a foothold in target networks,” Palo Alto Networks Unit 42 researcher Tom…

    Read More

  • Webinar: How to Protect Your Company from GenAI Data Leakage Without Losing It’s Productivity Benefits

    Webinar: How to Protect Your Company from GenAI Data Leakage Without Losing It’s Productivity Benefits

    GenAI has become a table stakes tool for employees, due to the productivity gains and innovative capabilities it offers. Developers use it to write code, finance teams use it to analyze reports, and sales teams create customer emails and assets. Yet, these capabilities are exactly the ones that introduce serious security risks. Register to our…

    Read More

  • North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams

    North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams

    Threat actors affiliated with North Korea have been observed leveraging LinkedIn as a way to target developers as part of a fake job recruiting operation. These attacks employ coding tests as a common initial infection vector, Google-owned Mandiant said in a new report about threats faced by the Web3 sector. “After an initial chat conversation,…

    Read More

  • FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals

    FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals

    Two men have been indicted in the U.S. for their alleged involvement in managing a dark web marketplace called WWH Club that specializes in the sale of sensitive personal and financial information. Alex Khodyrev, a 35-year-old Kazakhstan national, and Pavel Kublitskii, a 37-year-old Russian national, have been charged with conspiracy to commit access device fraud…

    Read More

  • SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation

    SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation

    SonicWall has revealed that a recently patched critical security flaw impacting SonicOS may have come under active exploitation, making it essential that users apply the patches as soon as possible. The vulnerability, tracked as CVE-2024-40766, carries a CVSS score of 9.3 out of a maximum of 10. “An improper access control vulnerability has been identified…

    Read More

  • GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware

    GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware

    A recently disclosed security flaw in OSGeo GeoServer GeoTools has been exploited as part of multiple campaigns to deliver cryptocurrency miners, botnet malware such as Condi and JenX, and a known backdoor called SideWalk. The security vulnerability is a critical remote code execution bug (CVE-2024-36401, CVSS score: 9.8) that could allow malicious actors to take…

    Read More