Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: 2024

Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool

post, juni 12, 2025juni 13, 2025

Cybersecurity researchers have uncovered a new account takeover (ATO) campaign that leverages an open-source penetration testing framework called TeamFiltration to breach Microsoft Entra ID (formerly Azure Active Directory) user accounts. The activity, codenamed UNK_SneakyStrike by Proofpoint, has targeted over 80,000 user accounts across hundreds of organizations’ cloud tenants since a surge in…

Continue Reading

U.S. Treasury Breached By People’s Republic of China (PRC) In ‘Major Incident’

post, december 31, 2024januari 9, 2025

U.S. officials have disclosed a state-sponsored Chinese hacker infiltrated the U.S. Treasury Department’s systems, gaining access to employee workstations and some unclassified documents. The breach, which occurred in early December, was revealed in a letter the Treasury Department sent to lawmakers notifying them of the incident.

Continue Reading

Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS

post, december 12, 2024december 13, 2024

Details have emerged about a now-patched security vulnerability in Apple’s iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and result in unauthorized access to sensitive information. The flaw, tracked as CVE-2024-44131 (CVSS score: 5.3), resides in the FileProvider component, per Apple, and has been…

Continue Reading

Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States

post, december 12, 2024december 13, 2024

The Russia-linked state-sponsored threat actor tracked as Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking the first time the adversary has been discovered using mobile-only malware families in its attack campaigns. “BoneSpy and PlainGnome target former Soviet states and focus on Russian-speaking victims,” Lookout said in an analysis….

Continue Reading

ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms

post, december 11, 2024februari 24, 2025

Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago. “Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and…

Continue Reading

Ransomware attack hits leading heart surgery device maker

post, december 9, 2024december 11, 2024

Artivion, a leading manufacturer of heart surgery medical devices, has disclosed a November 21 ransomware attack that disrupted its operations and forced it to take some systems offline. The Atlanta-based company employs over 1,250 people worldwide and has sales representatives in more than 100 countries. It also operates manufacturing facilities…

Continue Reading

US arrests Scattered Spider suspect linked to telecom hacks

post, december 5, 2024februari 24, 2025

U.S. authorities have arrested a 19-year-old teenager linked to the notorious Scattered Spider cybercrime gang who is now charged with breaching a U.S. financial institution and two unnamed telecommunications firms. Remington Goy Ogletree (also known online as “remi”) breached the three companies’ networks using credentials stolen in text and voice…

Continue Reading

Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested

post, november 30, 2024december 2, 2024

A Russian cybercriminal wanted in the U.S. in connection with LockBit and Hive ransomware operations has been arrested by law enforcement authorities in the country. According to a news report from Russian media outlet RIA Novosti, Mikhail Pavlovich Matveev has been accused of developing a malicious program designed to encrypt files and…

Continue Reading

Russian Spies Jumped From One Network to Another Via Wi-Fi in an Unprecedented Hack

post, november 22, 2024juli 3, 2025

In a first, Russia’s APT28 hacking group appears to have remotely breached the Wi-Fi of an espionage target by hijacking a laptop in another building across the street. For determined hackers, sitting in a car outside a target’s building and using radio equipment to breach its Wi-Fi network has long…

Continue Reading

NSO Group Exploited WhatsApp to Install Pegasus Spyware Even After Meta’s Lawsuit

post, november 18, 2024

Legal documents released as part of an ongoing legal tussle between Meta’s WhatsApp and NSO Group have revealed that the Israeli spyware vendor used multiple exploits targeting the messaging app to deliver Pegasus, including one even after it was sued by Meta for doing so. They also show that NSO Group repeatedly…

Continue Reading
  • 1
  • 2
  • …
  • 12
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes