New macOS Malware “Cthulhu Stealer” Targets Apple Users’ Data post, augustus 23, 2024 Cybersecurity researchers have uncovered a new information stealer that’s designed to target Apple macOS hosts and harvest a wide range of information, underscoring how threat actors are increasingly setting their sights on the operating system. Dubbed Cthulhu Stealer, the malware has been available under a malware-as-a-service (MaaS) model for $500… Continue Reading
Google Fixes High-Severity Chrome Flaw Actively Exploited in the Wild post, augustus 22, 2024augustus 23, 2024 Google has rolled out security fixes to address a high-severity security flaw in its Chrome browser that it said has come under active exploitation in the wild. Tracked as CVE-2024-7971, the vulnerability has been described as a type confusion bug in the V8 JavaScript and WebAssembly engine. “Type confusion in V8… Continue Reading
Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk post, augustus 22, 2024februari 24, 2025 SolarWinds has issued patches to address a new security flaw in its Web Help Desk (WHD) software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances. “The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing [a] remote unauthenticated user to… Continue Reading
Microsoft Patches Zero-Day Flaw Exploited by North Korea’s Lazarus Group post, augustus 19, 2024februari 24, 2025 A newly patched security flaw in Microsoft Windows was exploited as a zero-day by Lazarus Group, a prolific state-sponsored actor affiliated with North Korea. The security vulnerability, tracked as CVE-2024-38193 (CVSS score: 7.8), has been described as a privilege escalation bug in the Windows Ancillary Function Driver (AFD.sys) for WinSock. “An attacker who… Continue Reading
Post-quantum cryptography: what comes next? post, augustus 14, 2024augustus 19, 2024 This month, a major milestone in post-quantum cryptography (PQC) has been reached: 3 algorithm standards (ML-KEM, ML-DSA, SLH-DSA) have been published by NIST, the US national standards organisation. The NCSC have updated our PQC white paper to reflect this milestone. While the core technical messages of the paper remain unchanged, we know that many… Continue Reading
Hackers breach ISP to poison software updates with malware post, augustus 3, 2024augustus 19, 2024 A Chinese hacking group tracked as StormBamboo has compromised an undisclosed internet service provider (ISP) to poison automatic software updates with malware. Also tracked as Evasive Panda, Daggerfly, and StormCloud, this cyber-espionage group has been active since at least 2012, targeting organizations across mainland China, Hong Kong, Macao, Nigeria, and various Southeast… Continue Reading
VMware ESXi flaw exploited post, juli 30, 2024februari 24, 2025 A recently patched security flaw impacting VMware ESXi hypervisors has been actively exploited by “several” ransomware groups to gain elevated permissions and deploy file-encrypting malware. The attacks involve the exploitation of CVE-2024-37085 (CVSS score: 6.8), an Active Directory integration authentication bypass that allows an attacker to obtain administrative access to the host. Continue Reading
CrowdStrike incident – Preliminary Post Incident Review post, juli 24, 2024 This is CrowdStrike’s preliminary Post Incident Review (PIR). We will be detailing our full investigation in the forthcoming Root Cause Analysis that will be released publicly. Throughout this PIR, we have used generalized terminology to describe the Falcon platform for improved readability. Terminology in other documentation may be more specific… Continue Reading
New ICS Malware ‘FrostyGoop’ Targeting Critical Infrastructure post, juli 23, 2024juli 24, 2024 Cybersecurity researchers have discovered what they say is the ninth Industrial Control Systems (ICS)-focused malware that has been used in a disruptive cyber attack targeting an energy company in the Ukrainian city of Lviv earlier this January. Industrial cybersecurity firm Dragos has dubbed the malware FrostyGoop, describing it as the first… Continue Reading
Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware post, juli 20, 2024juli 22, 2024 Cybersecurity firm CrowdStrike, which is facing the heat for causing worldwide IT disruptions by pushing out a flawed update to Windows devices, is now warning that threat actors are exploiting the situation to distribute Remcos RAT to its customers in Latin America under the guise of providing a hotfix. The attack chains… Continue Reading