North Korean Hackers Abuse Cloud-Based Services to Deploy Malware post, november 9, 2024november 14, 2024 ESET’s recent report details the activities of various advanced persistent threat (APT) groups from April to September 2024, highlighting key trends and developments observed during this period, including the use of sophisticated techniques such as targeted phishing attacks, malware distribution, and vulnerability exploitation. Continue Reading
FBI: Spike in Hacked Police Emails, Fake Subpoenas post, november 9, 2024november 14, 2024 The Federal Bureau of Investigation (FBI) is urging police departments and governments worldwide to beef up security around their email systems, citing a recent increase in cybercriminal services that use hacked police email accounts to send unauthorized subpoenas and customer data requests to U.S.-based technology companies. Continue Reading
U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign post, oktober 18, 2024 Cybersecurity and intelligence agencies from Australia, Canada, and the U.S. have warned about a year-long campaign undertaken by Iranian cyber actors to infiltrate critical infrastructure organizations via brute-force attacks. “Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations… Continue Reading
North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data post, oktober 18, 2024 North Korean information technology (IT) workers who obtain employment under false identities in Western companies are not only stealing intellectual property, but are also stepping up by demanding ransoms in order to not leak it, marking a new twist to their financially motivated attacks. “In some instances, fraudulent workers demanded… Continue Reading
U.S. Charges Two Sudanese Brothers for Record 35,000 DDoS Attacks post, oktober 17, 2024 Federal prosecutors in the U.S. have charged two Sudanese brothers with running a distributed denial-of-service (DDoS) botnet for hire that conducted a record 35,000 DDoS attacks in a single year, including those that targeted Microsoft’s services in June 2023. The attacks, which were facilitated by Anonymous Sudan’s “powerful DDoS tool,” singled out… Continue Reading
Google: 70% of exploited flaws disclosed in 2023 were zero-days post, oktober 16, 2024oktober 17, 2024 Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software. Specifically, of the 138 vulnerabilities disclosed as actively exploited in 2023, Mandiant says 97 (70.3%) were leveraged as zero-days. This means that threat actors exploited… Continue Reading
China Possibly Hacking US “Lawful Access” Backdoor post, oktober 8, 2024februari 24, 2025 The Wall Street Journal is reporting that Chinese hackers (Salt Typhoon) penetrated the networks of US broadband providers, and might have accessed the backdoors that the federal government uses to execute court-authorized wiretap requests. Those backdoors have been mandated by law—CALEA—since 1994. It’s a weird story. The first line of the article is: “A… Continue Reading
American Water Works IT Systems Hit by Cyber Attack post, oktober 8, 2024oktober 9, 2024 American Water Works Company, Inc., the largest regulated water and wastewater utility in the United States, reported a cybersecurity incident on October 3, 2024, affecting its computer networks and systems. The company, which provides services to over 14 million people across 14 states and 18 military installations, immediately activated its incident… Continue Reading
Chinese Government Hackers Infiltrate U.S Telecommunications Companies post, oktober 6, 2024oktober 7, 2024 A group of hackers linked to the Chinese government has infiltrated multiple US telecommunications companies in recent months, likely in an effort to access sensitive national security information. The hacking activity was first reported by The Wall Street Journal (WSJ). US investigators suspect that the hackers may have gained access… Continue Reading
Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town post, september 23, 2024februari 24, 2025 Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit… Continue Reading