Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware post, september 23, 2024 A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. “They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and… Continue Reading
Notorious Iranian Hackers Have Been Targeting the Space Industry With a New Backdoor post, augustus 28, 2024juli 3, 2025 The Iranian government-backed hacking group known as APT 33 has been active for more than 10 years, conducting aggressive espionage operations against a diverse array of public and private sector victims around the world, including critical infrastructure targets. And while the group is particularly known for strategic but technically simple attacks like “password spraying,” it has… Continue Reading
New macOS Malware “Cthulhu Stealer” Targets Apple Users’ Data post, augustus 23, 2024 Cybersecurity researchers have uncovered a new information stealer that’s designed to target Apple macOS hosts and harvest a wide range of information, underscoring how threat actors are increasingly setting their sights on the operating system. Dubbed Cthulhu Stealer, the malware has been available under a malware-as-a-service (MaaS) model for $500… Continue Reading
Hackers breach ISP to poison software updates with malware post, augustus 3, 2024augustus 19, 2024 A Chinese hacking group tracked as StormBamboo has compromised an undisclosed internet service provider (ISP) to poison automatic software updates with malware. Also tracked as Evasive Panda, Daggerfly, and StormCloud, this cyber-espionage group has been active since at least 2012, targeting organizations across mainland China, Hong Kong, Macao, Nigeria, and various Southeast… Continue Reading
Japanese space agency spotted zero-day attacks while cleaning up attack on M365 post, juli 11, 2024juli 12, 2024 The Japanese Space Exploration Agency (JAXA) discovered it was under attack using zero-day exploits while working with Microsoft to probe a 2023 cyberattack on its systems. But the space org’s statement also revealed the discovery of malware found and removed by an actor other than Microsoft. And then there’s the… Continue Reading
NiceRAT Malware Targets South Korean Users via Cracked Software post, juni 17, 2024 Threat actors have been observed deploying a malware called NiceRAT to co-opt infected devices into a botnet. The attacks, which target South Korean users, are designed to propagate the malware under the guise of cracked software, such as Microsoft Windows, or tools that purport to offer license verification for Microsoft… Continue Reading
Hamas Hackers Sling Stealthy Spyware Across Egypt, Palestine post, juni 17, 2024juli 3, 2025 Hamas-linked advanced persistent threat (APT) group Arid Viper has been observed using Android spyware AridSpy dating back to 2022. Now, for the first time, researchers have provided a full analysis of the malware’s previously mysterious later stages. Continue Reading
Chinese State-Backed Cyber Espionage Targets Southeast Asian Government post, juni 5, 2024 An unnamed high-profile government organization in Southeast Asia emerged as the target of a “complex, long-running” Chinese state-sponsored cyber espionage operation codenamed Crimson Palace. Continue Reading
Police seize over 100 malware loader servers, arrest four cybercriminals post, mei 30, 2024mei 30, 2024 An international law enforcement operation codenamed ‘Operation Endgame’ has seized over 100 servers worldwide used by multiple major malware loader operations, including IcedID, Pikabot, Trickbot, Bumblebee, Smokeloader, and SystemBC. The action, which occurred between May 27 and 29, 2024, involved 16 location searches across Europe and led to the arrest… Continue Reading
Polish bodies hit by malware attack post, mei 10, 2024juli 3, 2025 Polish government bodies were hit by a sophisticated malware attack orchestrated by the infamous APT28 hacking group. The campaign employed cunning tactics like email lures and legitimate service abuse to evade detection. Continue Reading