Technology

Experts Discover Backdoor Deployed on the U.S. Federal Agency’s Network

A U.S. federal government commission associated with international rights has been targeted by a backdoor that reportedly compromised its internal network in what the researchers described as a “classic APT-type operation.”  “This attack could have given total visibility of the network and complete control of a system and thus could be used as the first […]

Experts Discover Backdoor Deployed on the U.S. Federal Agency’s Network Read More »

New Local Attack Vector Expands the Attack Surface of Log4j Vulnerability

Cybersecurity researchers have discovered an entirely new attack vector that enables adversaries to exploit the Log4Shell vulnerability on servers locally by using a JavaScript WebSocket connection. “This newly-discovered attack vector means that anyone with a vulnerable Log4j version on their machine or local private network can browse a website and potentially trigger the vulnerability,”

New Local Attack Vector Expands the Attack Surface of Log4j Vulnerability Read More »

Apache Issues 3rd Patch to Fix New High-Severity Log4j Vulnerability

The issues with Log4j continued to stack up as the Apache Software Foundation (ASF) on Friday rolled out yet another patch — version 2.17.0 — for the widely used logging library that could be exploited by malicious actors to stage a denial-of-service (DoS) attack. Tracked as CVE-2021-45105 (CVSS score: 7.5), the new vulnerability affects all versions of

Apache Issues 3rd Patch to Fix New High-Severity Log4j Vulnerability Read More »

New PseudoManuscrypt Malware Infected Over 35,000 Computers in 2021

Industrial and government organizations, including enterprises in the military-industrial complex and research laboratories, are the targets of a new malware botnet dubbed PseudoManyscrypt that has infected roughly 35,000 Windows computers this year alone. The name comes from its similarities to the Manuscrypt malware, which is part of the Lazarus APT group’s attack toolset, Kaspersky

New PseudoManuscrypt Malware Infected Over 35,000 Computers in 2021 Read More »

Facebook Bans 7 ‘Cyber Mercenary’ Companies for Spying on 50,000 Users

Meta Platforms on Thursday revealed it took steps to deplatform seven cyber mercenaries that it said carried out “indiscriminate” targeting of journalists, dissidents, critics of authoritarian regimes, families of opposition, and human rights activists located in over 100 countries, amid mounting scrutiny of surveillance technologies. To that end, the company said it alerted 50,000 users of

Facebook Bans 7 ‘Cyber Mercenary’ Companies for Spying on 50,000 Users Read More »

How to Prevent Customer Support Help Desk Fraud Using VPN and Other Tools

It’s no secret that the internet isn’t a very safe place. And it’s not hard to understand why. It’s a medium that connects billions of people around the world that affords bad actors enough anonymity to wreak havoc without getting caught. It’s almost as if the internet’s tailor-made to enable scams and fraud. And that’s

How to Prevent Customer Support Help Desk Fraud Using VPN and Other Tools Read More »

New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

Cryptocurrency users in Ethiopia, Nigeria, India, Guatemala, and the Philippines are being targeted by a new variant of the Phorpiex botnet called Twizt that has resulted in the theft of virtual coins amounting to $500,000 over the last one year. Israeli security firm Check Point Research, which detailed the attacks, said the latest evolutionary version “enables the

New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency Read More »

Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw Emerges

Web infrastructure company Cloudflare on Wednesday revealed that threat actors are actively attempting to exploit a second bug disclosed in the widely used Log4j logging utility, making it imperative that customers move quickly to install the latest version as a barrage of attacks continues to pummel unpatched systems with a variety of malware. The new vulnerability, assigned

Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw Emerges Read More »

New Fileless Malware Uses Windows Registry as Storage to Evade Detection

A new JavaScript-based remote access Trojan (RAT) propagated via a social engineering campaign has been observed employing sneaky “fileless” techniques as part of its detection-evasion methods to elude discovery and analysis. Dubbed DarkWatchman by researchers from Prevailion’s Adversarial Counterintelligence Team (PACT), the malware uses a resilient domain generation algorithm (DGA) to identify

New Fileless Malware Uses Windows Registry as Storage to Evade Detection Read More »

The Guide to Automating Security Training for Lean Security Teams

Cyber threats used to be less threatening. While nobody wants their customers’ credit card numbers stolen in a data breach, or to see a deranged manifesto plastered over their company website, such incidents can almost seem quaint compared to ransomware attacks that bring all of your critical information systems to a dead halt. The frequency

The Guide to Automating Security Training for Lean Security Teams Read More »