W3LL Store: How a Secret Phishing Syndicate Targets 8,000+ Microsoft 365 Accounts

06/09/2023 0 Comments 0 tags

A previously undocumented “phishing empire” has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years. “The threat actor created a hidden

Ukraine’s CERT Thwarts APT28’s Cyberattack on Critical Energy Infrastructure

06/09/2023 0 Comments 0 tags

The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country. The intrusion, per the

Chinese-Speaking Cybercriminals Launch Large-Scale iMessage Smishing Campaign in U.S.

04/09/2023 0 Comments 0 tags

A new large-scale smishing campaign is targeting the U.S. by sending iMessages from compromised Apple iCloud accounts with an aim to conduct identity theft and financial fraud. “The Chinese-speaking threat

PoC Exploit Released for Critical VMware Aria’s SSH Auth Bypass Vulnerability

04/09/2023 0 Comments 0 tags

Proof-of-concept (PoC) exploit code has been made available for a recently disclosed and patched critical flaw impacting VMware Aria Operations for Networks (formerly vRealize Network Insight). The flaw, tracked as CVE-2023-34039,

Hackers Exploit MinIO Storage System Vulnerabilities to Compromise Servers

04/09/2023 0 Comments 0 tags

An unknown threat actor has been observed weaponizing high-severity security flaws in the MinIO high-performance object storage system to achieve unauthorized code execution on affected servers. Cybersecurity and incident response

X (Twitter) to Collect Biometric Data from Premium Users to Combat Impersonation

04/09/2023 0 Comments 0 tags

X, the social media site formerly known as Twitter, has updated its privacy policy to collect users’ biometric data to tackle fraud and impersonation on the platform. “Based on your

Everything You Wanted to Know About AI Security but Were Afraid to Ask

04/09/2023 0 Comments 0 tags

There’s been a great deal of AI hype recently, but that doesn’t mean the robots are here to replace us. This article sets the record straight and explains how businesses

Vietnamese Cybercriminals Targeting Facebook Business Accounts with Malvertising

04/09/2023 0 Comments 0 tags

Malicious actors associated with the Vietnamese cybercrime ecosystem are leveraging advertising-as-a-vector on social media platforms such as Meta-owned Facebook to distribute malware. “Threat actors have long used fraudulent ads as

Beware of MalDoc in PDF: A New Polyglot Attack Allowing Attackers to Evade Antivirus

04/09/2023 0 Comments 0 tags

Cybersecurity researchers have called attention to a new antivirus evasion technique that involves embedding a malicious Microsoft Word file into a PDF file. The sneaky method, dubbed MalDoc in PDF by JPCERT/CC,

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges

02/09/2023 0 Comments 0 tags

Identity services provider Okta on Friday warned of social engineering attacks orchestrated by threat actors to obtain elevated administrator permissions. “In recent weeks, multiple US-based Okta customers have reported a