Uncategorized

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft 2023-12-22 at 19:46 By Threat hunters have discovered a rogue WordPress plugin that’s capable of creating bogus administrator users and injecting malicious JavaScript code to steal credit card information. The skimming activity is part of a Magecart campaign targeting e-commerce websites, according to Sucuri. “As with many

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft Read More »

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs 2023-12-22 at 18:04 By Connor Jones How do you break into the bad guys’ ranks? Master the lingo and research, research, research Feature  When AlphV/BlackCat’s website went dark this month, it was like Chrimbo came early for cybersecurity defenders, some of whom seemingly believed law

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs Read More »

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities 2023-12-22 at 16:32 By Indian government entities and the defense sector have been targeted by a phishing campaign that’s engineered to drop Rust-based malware for intelligence gathering. The activity, first detected in October 2023, has been codenamed Operation RusticWeb by enterprise security firm SEQRITE. “New Rust-based payloads and encrypted

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities Read More »

Hunting for Android Privilege Escalation with a 32 Line Fuzzer

Hunting for Android Privilege Escalation with a 32 Line Fuzzer 22/12/2023 at 16:02 By Maksymilian Motyl Trustwave SpiderLabs tested a couple of Android OS-based mobile devices to conduct the research on privilege escalation scenarios. Specifically, we wanted to show a straightforward process attackers may use to exploit vulnerabilities in an Android device’s system services and

Hunting for Android Privilege Escalation with a 32 Line Fuzzer Read More »

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware 22/12/2023 at 16:01 By A new phishing campaign is leveraging decoy Microsoft Word documents as bait to deliver a backdoor written in the Nim programming language. “Malware written in uncommon programming languages puts the security community at a disadvantage as researchers and reverse engineers’ unfamiliarity can hamper

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware Read More »

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware 22/12/2023 at 11:49 By The threat actor known as UAC-0099 has been linked to continued attacks aimed at Ukraine, some of which leverage a high-severity flaw in the WinRAR software to deliver a malware strain called LONEPAGE. “The threat actor targets Ukrainian employees working for companies

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware Read More »

Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector

Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector 22/12/2023 at 09:18 By Organizations in the Defense Industrial Base (DIB) sector are in the crosshairs of an Iranian threat actor as part of a campaign designed to deliver a never-before-seen backdoor called FalseFont. The findings come from Microsoft, which is tracking the activity under

Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector Read More »

Cisco goes Christmas shopping, buys Cilium project originator Isovalent

Cisco goes Christmas shopping, buys Cilium project originator Isovalent 22/12/2023 at 08:32 By Simon Sharwood Swithchzilla likes what eBPF does for multicloud networking and security Cisco has bought itself a Christmas present: Isovalent, the startup that originated Cilium, an open source networking, observability, and security tool recently graduated to full project status by the Cloud

Cisco goes Christmas shopping, buys Cilium project originator Isovalent Read More »

Programmable or ‘purpose-bound’ money is coming, probably as a feature in central bank digital currencies

Programmable or ‘purpose-bound’ money is coming, probably as a feature in central bank digital currencies 22/12/2023 at 02:19 By Laura Dobberstein Governments may dictate where or when you use it, but it’s not a gift card Interview  As the tide of enthusiasm for cryptocurrency ebbs, new forms of digital currency are emerging, including something called

Programmable or ‘purpose-bound’ money is coming, probably as a feature in central bank digital currencies Read More »

Lapsus$ teen sentenced to indefinite detention in hospital after Nvidia, GTA cyberattacks

Lapsus$ teen sentenced to indefinite detention in hospital after Nvidia, GTA cyberattacks 22/12/2023 at 01:18 By Jessica Lyons Hardcastle Arion Kurtaj will remain hospitalized until a mental health tribunal says he can leave Two British teens who were members of the Lapsus$ gang have been sentenced for their roles in a cyber-crime spree that included

Lapsus$ teen sentenced to indefinite detention in hospital after Nvidia, GTA cyberattacks Read More »

Philips recalls 340 MRI machines because they may explode in an emergency

Philips recalls 340 MRI machines because they may explode in an emergency 22/12/2023 at 00:17 By Tobias Mann Rapid unscheduled disassembly not exactly a desirable quality for medical imaging equipment Philips is recalling hundreds of MRI machines around the globe over concerns the medical imaging equipment could explode during normal operation — something a US

Philips recalls 340 MRI machines because they may explode in an emergency Read More »

Chameleon Android Banking Trojan Variant Bypasses Biometric Authentication

Chameleon Android Banking Trojan Variant Bypasses Biometric Authentication 21/12/2023 at 20:16 By Cybersecurity researchers have discovered an updated version of an Android banking malware called Chameleon that has expanded its targeting to include users in the U.K. and Italy. “Representing a restructured and enhanced iteration of its predecessor, this evolved Chameleon variant excels in executing

Chameleon Android Banking Trojan Variant Bypasses Biometric Authentication Read More »

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware 21/12/2023 at 20:16 By A new analysis of the sophisticated commercial spyware called Predator has revealed that its ability to persist between reboots is offered as an “add-on feature” and that it depends on the licensing options opted by a customer. “In 2021, Predator spyware couldn’t

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware Read More »

Scroll to Top