Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: 2025

North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages

post, april 5, 2025april 7, 2025

The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. “These latest samples employ hexadecimal string encoding to evade automated detection systems and…

Continue Reading

Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE Malware

post, april 4, 2025april 7, 2025

Ivanti has disclosed details of a now-patched critical security vulnerability impacting its Connect Secure product that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2025-22457 (CVSS score: 9.0), concerns a case of a stack-based buffer overflow that could be exploited to execute arbitrary code on affected systems.

Continue Reading

Six Governments Likely Use Israeli Paragon Spyware to Hack IM Apps and Harvest Data

post, maart 20, 2025augustus 21, 2025

The governments of Australia, Canada, Cyprus, Denmark, Israel, and Singapore are likely customers of spyware developed by Israeli company Paragon Solutions, according to a new report from The Citizen Lab. Paragon, founded in 2019 by Ehud Barak and Ehud Schneorson, is the maker of a surveillance tool called Graphite that’s capable of…

Continue Reading

Threat Actor Impersonates Booking.com in Phishing Scheme

post, maart 14, 2025maart 17, 2025

Microsoft detailed a sophisticated campaign that relies on a social engineering technique, “ClickFix,” in which a phisher uses security verification like captcha to give the target a false sense of safety. That’s according to Microsoft, which published threat intelligence on March 13 regarding a threat actor tracked as Storm-1865. The actor was…

Continue Reading

Threat Actor Tied to LockBit Ransomware Targets Fortinet Users

post, maart 14, 2025maart 17, 2025

Since January, threat actors have been exploiting two Fortinet vulnerabilities tracked as CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware. It’s believed that the threat actor, dubbed “Mora_001” by researchers at Forescout Research–Vedere Labs, is responsible for the attacks that use Russian-language artifacts and other characteristics. Mora_001 is exploiting the two…

Continue Reading

Undocumented commands found in Bluetooth chip used by a billion devices

post, maart 8, 2025maart 10, 2025

The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains undocumented commands that could be leveraged for attacks. The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence.

Continue Reading

Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access

post, maart 6, 2025maart 10, 2025

Over 1,000 websites powered by WordPress have been infected with a third-party JavaScript code that injects four separate backdoors. “Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed,” c/side researcher Himanshu Anand said in a Wednesday analysis. The malicious JavaScript code has been found…

Continue Reading

Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus

post, februari 28, 2025

The threat actor known as Sticky Werewolf has been linked to targeted attacks primarily in Russia and Belarus with the aim of delivering the Lumma Stealer malware by means of a previously undocumented implant. Cybersecurity company Kaspersky is tracking the activity under the name Angry Likho, which it said bears a “strong…

Continue Reading

Belgium probes if Chinese hackers breached its intelligence service

post, februari 27, 2025februari 28, 2025

The Belgian federal prosecutor’s office is investigating whether Chinese hackers were behind a breach of the country’s State Security Service (VSSE). Chinese state-backed attackers reportedly gained access to VSSE’s external email server between 2021 and May 2023, siphoning around 10% of all emails sent and received by the agency’s staff.

Continue Reading

Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist in Sophisticated Cold Wallet Attack

post, februari 22, 2025februari 24, 2025

Cryptocurrency exchange Bybit on Friday revealed that a “sophisticated” attack led to the theft of over $1.5 billion worth of cryptocurrency from one of its Ethereum cold (offline) wallets, making it the largest ever single crypto heist in history. “The incident occurred when our ETH multisig cold wallet executed a transfer to…

Continue Reading
  • Previous
  • 1
  • …
  • 12
  • 13
  • 14
  • …
  • 16
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes