Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: Credential Access

WantToCry Ransomware Exploits SMB Vulnerabilities to Remotely Encrypts NAS Drives 

post, februari 1, 2025februari 24, 2025

The notorious WantToCry ransomware group leverages misconfigured Server Message Block (SMB) services to infiltrate networks and launch widespread attacks. The weaknesses in SMBs, such as weak credentials, outdated software, and poor security configurations, are providing attackers with an easy entry point through which attackers exploit publicly exposed network drives and…

Continue Reading

Threat Actors Exploit Government Website Vulnerabilities For Phishing Attacks

post, januari 30, 2025februari 24, 2025

A recent report by Cofense Intelligence shows that how attackers are weaponizing .gov top-level domains (TLDs) across multiple countries for malicious purposes, including credential phishing, malware delivery, and command-and-control (C2) operations.

Continue Reading

US arrests Scattered Spider suspect linked to telecom hacks

post, december 5, 2024februari 24, 2025

U.S. authorities have arrested a 19-year-old teenager linked to the notorious Scattered Spider cybercrime gang who is now charged with breaching a U.S. financial institution and two unnamed telecommunications firms. Remington Goy Ogletree (also known online as “remi”) breached the three companies’ networks using credentials stolen in text and voice…

Continue Reading

Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town

post, september 23, 2024februari 24, 2025

Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit…

Continue Reading

Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk

post, augustus 22, 2024februari 24, 2025

SolarWinds has issued patches to address a new security flaw in its Web Help Desk (WHD) software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances. “The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing [a] remote unauthenticated user to…

Continue Reading

China-Linked Cyber-Espionage Teams Target Asian Telecoms

post, juni 25, 2024februari 24, 2025

In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack. At least three cyber-espionage groups have compromised telecommunications operators in multiple countries in the Asia-Pacific region, placing backdoors inside the communications providers’ networks, stealing…

Continue Reading

Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

post, juni 20, 2024februari 24, 2025

Cyber espionage groups associated with China have been linked to a long-running campaign that has infiltrated several telecom operators located in a single Asian country at least since 2021. “The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials,” the Symantec Threat Hunter Team,…

Continue Reading

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes