Lazarus Group Exploits Critical Zoho ManageEngine Flaw to Deploy Stealthy QuiteRAT Malware

24/08/2023 0 Comments 0 tags

The North Korea-linked threat actor known as Lazarus Group has been observed exploiting a now-patched critical security flaw impacting Zoho ManageEngine ServiceDesk Plus to distribute a remote access trojan called

Over a Dozen Malicious npm Packages Target Roblox Game Developers

23/08/2023 0 Comments 0 tags

More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer called Luna Token

Spacecolon Toolset Fuels Global Surge in Scarab Ransomware Attacks

23/08/2023 0 Comments 0 tags

A malicious toolset dubbed Spacecolon is being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations globally. “It probably finds its way into victim

Syrian Threat Actor EVLF Unmasked as Creator of CypherRAT and CraxsRAT Android Malware

23/08/2023 0 Comments 0 tags

A Syrian threat actor named EVLF has been outed as the creator of malware families CypherRAT and CraxsRAT. “These RATs are designed to allow an attacker to remotely perform real-time actions and

Agile Approach to Mass Cloud Credential Harvesting and Crypto Mining Sprints Ahead

23/08/2023 0 Comments 0 tags

Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker

New Variant of XLoader macOS Malware Disguised as ‘OfficeNote’ Productivity App

22/08/2023 0 Comments 0 tags

A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called “OfficeNote.” “The new version of XLoader

Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates

22/08/2023 0 Comments 0 tags

A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. The Symantec Threat Hunter

CISOs Tout SaaS Cybersecurity Confidence, But 79% Admit to SaaS Incidents, New Report Finds

22/08/2023 0 Comments 0 tags

A new State of SaaS Security Posture Management Report from SaaS cybersecurity provider AppOmni indicates that Cybersecurity, IT, and business leaders alike recognize SaaS cybersecurity as an increasingly important part of the cyber threat

Critical Adobe ColdFusion Flaw Added to CISA’s Exploited Vulnerability Catalog

22/08/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability,

Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry Software

22/08/2023 0 Comments 0 tags

Software services provider Ivanti is warning of a new critical zero-day flaw impacting Ivanti Sentry (formerly MobileIron Sentry) that it said is being actively exploited in the wild, marking an escalation of