Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware post, november 11, 2024november 14, 2024 Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT “provides purchases with a wide range of advanced features to remotely control computers belonging to the buyer,” Fortinet FortiGuard Labs researcher Xiaopeng Zhang said in an analysis published last week…. Continue Reading
Hackers now use ZIP file concatenation to evade detection post, november 10, 2024november 14, 2024 Hackers are targeting Windows machines using the ZIP file concatenation technique to deliver malicious payloads in compressed archives without security solutions detecting them. The technique exploits the different methods ZIP parsers and archive managers handle concatenated ZIP files. This new trend was spotted by Perception Point, who discovered a a concatentated ZIP… Continue Reading
North Korean Hackers Abuse Cloud-Based Services to Deploy Malware post, november 9, 2024november 14, 2024 ESET’s recent report details the activities of various advanced persistent threat (APT) groups from April to September 2024, highlighting key trends and developments observed during this period, including the use of sophisticated techniques such as targeted phishing attacks, malware distribution, and vulnerability exploitation. Continue Reading
FBI: Spike in Hacked Police Emails, Fake Subpoenas post, november 9, 2024november 14, 2024 The Federal Bureau of Investigation (FBI) is urging police departments and governments worldwide to beef up security around their email systems, citing a recent increase in cybercriminal services that use hacked police email accounts to send unauthorized subpoenas and customer data requests to U.S.-based technology companies. Continue Reading
U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign post, oktober 18, 2024 Cybersecurity and intelligence agencies from Australia, Canada, and the U.S. have warned about a year-long campaign undertaken by Iranian cyber actors to infiltrate critical infrastructure organizations via brute-force attacks. “Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations… Continue Reading
North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data post, oktober 18, 2024 North Korean information technology (IT) workers who obtain employment under false identities in Western companies are not only stealing intellectual property, but are also stepping up by demanding ransoms in order to not leak it, marking a new twist to their financially motivated attacks. “In some instances, fraudulent workers demanded… Continue Reading
Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts post, oktober 17, 2024juli 3, 2025 A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm)… Continue Reading
U.S. Charges Two Sudanese Brothers for Record 35,000 DDoS Attacks post, oktober 17, 2024 Federal prosecutors in the U.S. have charged two Sudanese brothers with running a distributed denial-of-service (DDoS) botnet for hire that conducted a record 35,000 DDoS attacks in a single year, including those that targeted Microsoft’s services in June 2023. The attacks, which were facilitated by Anonymous Sudan’s “powerful DDoS tool,” singled out… Continue Reading
Google: 70% of exploited flaws disclosed in 2023 were zero-days post, oktober 16, 2024oktober 17, 2024 Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software. Specifically, of the 138 vulnerabilities disclosed as actively exploited in 2023, Mandiant says 97 (70.3%) were leveraged as zero-days. This means that threat actors exploited… Continue Reading
China Possibly Hacking US “Lawful Access” Backdoor post, oktober 8, 2024februari 24, 2025 The Wall Street Journal is reporting that Chinese hackers (Salt Typhoon) penetrated the networks of US broadband providers, and might have accessed the backdoors that the federal government uses to execute court-authorized wiretap requests. Those backdoors have been mandated by law—CALEA—since 1994. It’s a weird story. The first line of the article is: “A… Continue Reading