DFIR via XDR: How to expedite your investigations with a DFIRent approach

18/04/2023 0 Comments 0 tags

Rapid technological evolution requires security that is resilient, up to date and adaptable. In this article, we will cover the transformation in the field of DFIR (digital forensics and incident

Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access

18/04/2023 0 Comments 0 tags

The Iranian threat actor known as MuddyWater is continuing its time-tested tradition of relying on legitimate remote administration tools to commandeer targeted systems. While the nation-state group has previously employed ScreenConnect,

Goldoson Android Malware Infects Over 100 Million Google Play Store Downloads

18/04/2023 0 Comments 0 tags

A new Android malware strain named Goldoson has been detected in the official Google Play Store spanning more than 60 legitimate apps that collectively have over 100 million downloads. An additional eight

What’s the Difference Between CSPM & SSPM?

18/04/2023 0 Comments 0 tags

Cloud Security Posture Management (CSPM) and SaaS Security Posture Management (SSPM) are frequently confused. The similarity of the acronyms notwithstanding, both security solutions focus on securing data in the cloud. In a

Google Uncovers APT41’s Use of Open Source GC2 Tool to Target Media and Job Sites

18/04/2023 0 Comments 0 tags

A Chinese nation-state group targeted an unnamed Taiwanese media organization to deliver an open source red teaming tool known as Google Command and Control (GC2) amid broader abuse of Google’s

Tour of the Underground: Master the Art of Dark Web Intelligence Gathering

18/04/2023 0 Comments 0 tags

The Deep, Dark Web – The Underground – is a haven for cybercriminals, teeming with tools and resources to launch attacks for financial gain, political motives, and other causes. But

Vice Society Ransomware Using Stealthy PowerShell Tool for Data Exfiltration

18/04/2023 0 Comments 0 tags

Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the process of exfiltrating data from

New Zaraza Bot Credential-Stealer Sold on Telegram Targeting 38 Web Browsers

18/04/2023 0 Comments 0 tags

A novel credential-stealing malware called Zaraza bot is being offered for sale on Telegram while also using the popular messaging service as a command-and-control (C2). “Zaraza bot targets a large number of web browsers and

LockBit Ransomware Now Targeting Apple macOS Devices

18/04/2023 0 Comments 0 tags

Threat actors behind the LockBit ransomware operation have developed new artifacts that can encrypt files on devices running Apple’s macOS operating system. The development, which was reported by the MalwareHunterTeam over the

Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose

18/04/2023 0 Comments 0 tags

Israeli spyware vendor QuaDream is allegedly shutting down its operations in the coming days, less than a week after its hacking toolset was exposed by Citizen Lab and Microsoft. The