U.S. DoJ Cracks Down on North Korean IT Scammers Defrauding Global Businesses

20/10/2023 0 Comments 0 tags

The U.S. government has announced the seizure of 17 website domains used by North Korean information technology (IT) workers as part of an illicit scheme to defraud businesses across the world, evade

Microsoft Warns of North Korean Attacks Exploiting JetBrains TeamCity Flaw

20/10/2023 0 Comments 0 tags

North Korean threat actors are actively exploiting a critical security flaw in JetBrains TeamCity to opportunistically breach vulnerable servers, according to Microsoft. The attacks, which entail the exploitation of CVE-2023-42793 (CVSS score:

Google TAG Detects State-Backed Threat Actors Exploiting WinRAR Flaw

20/10/2023 0 Comments 0 tags

A number of state-back threat actors from Russia and China have been observed exploiting a recent security flaw in the WinRAR archiver tool for Windows as part of their operations.

Lazarus Group Targeting Defense Experts with Fake Interviews via Trojanized VNC Apps

20/10/2023 0 Comments 0 tags

The North Korea-linked Lazarus Group (aka Hidden Cobra or TEMP.Hermit) has been observed using trojanized versions of Virtual Network Computing (VNC) apps as lures to target the defense industry and nuclear engineers

Critical Citrix NetScaler Flaw Exploited to Target from Government, Tech Firms

20/10/2023 0 Comments 0 tags

Citrix is warning of exploitation of a recently disclosed critical security flaw in NetScaler ADC and Gateway appliances that could result in exposure of sensitive information. Tracked as CVE-2023-4966 (CVSS score: 9.4),

Unraveling Real-Life Attack Paths – Key Lessons Learned

20/10/2023 0 Comments 0 tags

In the ever-evolving landscape of cybersecurity, attackers are always searching for vulnerabilities and exploits within organizational environments. They don’t just target single weaknesses; they’re on the hunt for combinations of

Qubitstrike Targets Jupyter Notebooks with Crypto Mining and Rootkit Campaign

20/10/2023 0 Comments 0 tags

A threat actor, presumably from Tunisia, has been linked to a new campaign targeting exposed Jupyter Notebooks in a two-fold attempt to illicitly mine cryptocurrency and breach cloud environments. Dubbed Qubitstrike by

Google Play Protect Introduces Real-Time Code-Level Scanning for Android Malware

20/10/2023 0 Comments 0 tags

Google has announced an update to its Play Protect with support for real-time scanning at the code level to tackle novel malicious apps prior to downloading and installing them on

Iran-Linked OilRig Targets Middle East Governments in 8-Month Cyber Campaign

20/10/2023 0 Comments 0 tags

The Iran-linked OilRig threat actor targeted an unnamed Middle East government between February and September 2023 as part of an eight-month-long campaign. The attack led to the theft of files and passwords

Sophisticated MATA Framework Strikes Eastern European Oil and Gas Companies

20/10/2023 0 Comments 0 tags

An updated version of a sophisticated backdoor framework called MATA has been used in attacks aimed at over a dozen Eastern European companies in the oil and gas sector and defense industry