Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks

25/11/2024 0 Comments 0 tags

Cybersecurity researchers have disclosed two new attack techniques against infrastructure-as-code (IaC) and policy-as-code (PaC) tools like HashiCorp’s Terraform and Open Policy Agent (OPA) that leverage dedicated, domain-specific languages (DSLs) to

Flying Under the Radar – Security Evasion Techniques

25/11/2024 0 Comments 0 tags

Dive into the evolution of phishing and malware evasion techniques and understand how attackers are using increasingly sophisticated methods to bypass security measures. The Evolution of Phishing Attacks “I really

THN Recap: Top Cybersecurity Threats, Tools, and Practices (Nov 18 – Nov 24)

25/11/2024 0 Comments 0 tags

We hear terms like “state-sponsored attacks” and “critical vulnerabilities” all the time, but what’s really going on behind those words? This week’s cybersecurity news isn’t just about hackers and headlines—it’s

Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections

25/11/2024 0 Comments 0 tags

Cybersecurity researchers have uncovered a new malicious campaign that leverages a technique called Bring Your Own Vulnerable Driver (BYOVD) to disarm security protections and ultimately gain access to the infected

North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn

23/11/2024 0 Comments 0 tags

The North Korea-linked threat actor known as Sapphire Sleet is estimated to have stolen more than $10 million worth of cryptocurrency as part of social engineering campaigns orchestrated over a

Google Exposes GLASSBRIDGE: A Pro-China Influence Network of Fake News Sites

23/11/2024 0 Comments 0 tags

Government agencies and non-governmental organizations in the United States have become the target of a nascent China state threat actor known as Storm-2077. The adversary, believed to be active since

China-Linked TAG-112 Targets Tibetan Media with Cobalt Strike Espionage Campaign

22/11/2024 0 Comments 0 tags

A China-linked nation-state group called TAG-112 compromised Tibetan media and university websites in a new cyber espionage campaign designed to facilitate the delivery of the Cobalt Strike post-exploitation toolkit for

APT-K-47 Uses Hajj-Themed Lures to Deliver Advanced Asyncshell Malware

22/11/2024 0 Comments 0 tags

The threat actor known as Mysterious Elephant has been observed using an advanced version of malware called Asynshell. The attack campaign is said to have used Hajj-themed lures to trick

Unlocking Google Workspace Security: Are You Doing Enough to Protect Your Data?

22/11/2024 0 Comments 0 tags

Google Workspace has quickly become the productivity backbone for businesses worldwide, offering an all-in-one suite with email, cloud storage and collaboration tools. This single-platform approach makes it easy for teams

Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and Asia

22/11/2024 0 Comments 0 tags

Threat actors with ties to Russia have been linked to a cyber espionage campaign aimed at organizations in Central Asia, East Asia, and Europe. Recorded Future’s Insikt Group, which has