CanesSpy Spyware Discovered in Modified WhatsApp Versions

03/11/2023 0 Comments 0 tags

Cybersecurity researchers have unearthed a number of WhatsApp mods for Android that come fitted with a spyware module dubbed CanesSpy. These modified versions of the instant messaging app have been observed

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems

03/11/2023 0 Comments 0 tags

A new set of 48 malicious npm packages have been discovered in the npm repository with capabilities to deploy a reverse shell on compromised systems. “These packages, deceptively named to

Mysterious Kill Switch Disrupts Mozi IoT Botnet Operations

03/11/2023 0 Comments 0 tags

The unexpected drop in malicious activity connected with the Mozi botnet in August 2023 was due to a kill switch that was distributed to the bots. “First, the drop manifested

Kinsing Actors Exploiting Recent Linux Flaw to Breach Cloud Environments

03/11/2023 0 Comments 0 tags

The threat actors linked to Kinsing have been observed attempting to exploit the recently disclosed Linux privilege escalation flaw called Looney Tunables as part of a “new experimental campaign” designed to breach

SaaS Security is Now Accessible and Affordable to All

02/11/2023 0 Comments 0 tags

This new product offers SaaS discovery and risk assessment coupled with a free user access review in a unique “freemium” model Securing employees’ SaaS usage is becoming increasingly crucial for

Iran’s MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign

02/11/2023 0 Comments 0 tags

The Iranian nation-state actor known as MuddyWater has been linked to a new spear-phishing campaign targeting two Israeli entities to ultimately deploy a legitimate remote administration tool from N-able called Advanced Monitoring Agent.

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover

02/11/2023 0 Comments 0 tags

As many as 34 unique vulnerable Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers could be exploited by non-privileged threat actors to gain full control of the devices

FIRST Announces CVSS 4.0 – New Vulnerability Scoring System

02/11/2023 0 Comments 0 tags

The Forum of Incident Response and Security Teams (FIRST) has officially announced CVSS v4.0, the next generation of the Common Vulnerability Scoring System standard, more than eight years after the release

HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability

02/11/2023 0 Comments 0 tags

Cybersecurity researchers are warning of suspected exploitation of a recently disclosed critical security flaw in the Apache ActiveMQ open-source message broker service that could result in remote code execution. “In

Researchers Expose Prolific Puma’s Underground Link Shortening Service

02/11/2023 0 Comments 0 tags

A threat actor known as Prolific Puma has been maintaining a low profile and operating an underground link shortening service that’s offered to other threat actors for at least over the past