Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

14/03/2023 0 Comments 0 tags

An open source adversary-in-the-middle (AiTM) phishing kit has found a number of takers in the cybercrime world for its ability to orchestrate attacks at scale. Microsoft Threat Intelligence is tracking

Fortinet FortiOS Flaw Exploited in Targeted Cyberattacks on Government Entities

14/03/2023 0 Comments 0 tags

Government entities and large organizations have been targeted by an unknown threat actor by exploiting a security flaw in Fortinet FortiOS software to result in data loss and OS and

GoBruteforcer: New Golang-Based Malware Breaches Web Servers Via Brute-Force Attacks

14/03/2023 0 Comments 0 tags

A new Golang-based malware dubbed GoBruteforcer has been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a botnet. “GoBruteforcer chose a Classless Inter-Domain Routing (CIDR)

Large-scale Cyber Attack Hijacks East Asian Websites for Adult Content Redirects

13/03/2023 0 Comments 0 tags

A widespread malicious cyber operation has hijacked thousands of websites aimed at East Asian audiences to redirect visitors to adult-themed content since early September 2022. The ongoing campaign entails injecting

How to Apply NIST Principles to SaaS in 2023

13/03/2023 0 Comments 0 tags

The National Institute of Standards and Technology (NIST) is one of the standard-bearers in global cybersecurity. The U.S.-based institute’s cybersecurity framework helps organizations of all sizes understand, manage, and reduce

Warning: AI-generated YouTube Video Tutorials Spreading Infostealer Malware

13/03/2023 0 Comments 0 tags

Threat actors have been increasingly observed using AI-generated YouTube Videos to spread a variety of stealer malware such as Raccoon, RedLine, and Vidar. “The videos lure users by pretending to

Fake ChatGPT Chrome Extension Hijacking Facebook Accounts for Malicious Advertising

13/03/2023 0 Comments 0 tags

A fake ChatGPT-branded Chrome browser extension has been found to come with capabilities to hijack Facebook accounts and create rogue admin accounts, highlighting one of the different methods cyber criminals

Researchers Uncover Over a Dozen Security Flaws in Akuvox E11 Smart Intercom

13/03/2023 0 Comments 0 tags

More than a dozen security flaws have been disclosed in E11, a smart intercom product made by Chinese company Akuvox. “The vulnerabilities could allow attackers to execute code remotely in

KamiKakaBot Malware Used in Latest Dark Pink APT Attacks on Southeast Asian Targets

13/03/2023 0 Comments 0 tags

The Dark Pink advanced persistent threat (APT) actor has been linked to a fresh set of attacks targeting government and military entities in Southeast Asian countries with a malware called KamiKakaBot. Dark

BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads

11/03/2023 0 Comments 0 tags

The malware downloader known as BATLOADER has been observed abusing Google Ads to deliver secondary payloads like Vidar Stealer and Ursnif. According to cybersecurity company eSentire, malicious ads are used to spoof a