From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese

25/09/2023 0 Comments 0 tags

Tibetan, Uyghur, and Taiwanese individuals and organizations are the targets of a persistent campaign orchestrated by a threat actor codenamed EvilBamboo to gather sensitive information. “The attacker has created fake Tibetan websites,

New Report Uncovers 3 Distinct Clusters of China-Nexus Attacks on Southeast Asian Government

25/09/2023 0 Comments 0 tags

An unnamed Southeast Asian government has been targeted by multiple China-nexus threat actors as part of espionage campaigns targeting the region over extended periods of time. “While this activity occurred

Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics

24/09/2023 0 Comments 0 tags

Cybersecurity researchers have discovered a previously undocumented advanced backdoor dubbed Deadglyph employed by a threat actor known as Stealth Falcon as part of a cyber espionage campaign. “Deadglyph’s architecture is unusual as

New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware

24/09/2023 0 Comments 0 tags

The three zero-day flaws addressed by Apple on September 21, 2023, were leveraged as part of an iPhone exploit chain in an attempt to deliver a spyware strain called Predator targeting former Egyptian member

How to Interpret the 2023 MITRE ATT&CK Evaluation Results

22/09/2023 0 Comments 0 tags

Thorough, independent tests are a vital resource for analyzing provider’s capabilities to guard against increasingly sophisticated threats to their organization. And perhaps no assessment is more widely trusted than the

Iranian Nation-State Actor OilRig Targets Israeli Organizations

22/09/2023 0 Comments 0 tags

Israeli organizations were targeted as part of two different campaigns orchestrated by the Iranian nation-state actor known as OilRig in 2021 and 2022. The campaigns, dubbed Outer Space and Juicy Mix, entailed

High-Severity Flaws Uncovered in Atlassian Products and ISC BIND Server

22/09/2023 0 Comments 0 tags

Atlassian and the Internet Systems Consortium (ISC) have disclosed several security flaws impacting their products that could be exploited to achieve denial-of-service (DoS) and remote code execution. The Australian software

Apple Rushes to Patch 3 New Zero-Day Flaws: iOS, macOS, Safari, and More Vulnerable

22/09/2023 0 Comments 0 tags

Apple has released yet another round of security patches to address three actively exploited zero-day flaws impacting iOS, iPadOS, macOS, watchOS, and Safari, taking the total tally of zero-day bugs

New Variant of Banking Trojan BBTok Targets Over 40 Latin American Banks

22/09/2023 0 Comments 0 tags

An active malware campaign targeting Latin America is dispensing a new variant of a banking trojan called BBTok, particularly users in Brazil and Mexico. “The BBTok banker has a dedicated functionality

Do You Really Trust Your Web Application Supply Chain?

22/09/2023 0 Comments 0 tags

Well, you shouldn’t. It may already be hiding vulnerabilities. It’s the modular nature of modern web applications that has made them so effective. They can call on dozens of third-party