WantToCry Ransomware Exploits SMB Vulnerabilities to Remotely Encrypts NAS Drives post, februari 1, 2025februari 24, 2025 The notorious WantToCry ransomware group leverages misconfigured Server Message Block (SMB) services to infiltrate networks and launch widespread attacks. The weaknesses in SMBs, such as weak credentials, outdated software, and poor security configurations, are providing attackers with an easy entry point through which attackers exploit publicly exposed network drives and… Continue Reading
Threat Actors Exploit Government Website Vulnerabilities For Phishing Attacks post, januari 30, 2025februari 24, 2025 A recent report by Cofense Intelligence shows that how attackers are weaponizing .gov top-level domains (TLDs) across multiple countries for malicious purposes, including credential phishing, malware delivery, and command-and-control (C2) operations. Continue Reading
US arrests Scattered Spider suspect linked to telecom hacks post, december 5, 2024februari 24, 2025 U.S. authorities have arrested a 19-year-old teenager linked to the notorious Scattered Spider cybercrime gang who is now charged with breaching a U.S. financial institution and two unnamed telecommunications firms. Remington Goy Ogletree (also known online as “remi”) breached the three companies’ networks using credentials stolen in text and voice… Continue Reading
Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town post, september 23, 2024februari 24, 2025 Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit… Continue Reading
Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk post, augustus 22, 2024februari 24, 2025 SolarWinds has issued patches to address a new security flaw in its Web Help Desk (WHD) software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances. “The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing [a] remote unauthenticated user to… Continue Reading
China-Linked Cyber-Espionage Teams Target Asian Telecoms post, juni 25, 2024februari 24, 2025 In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack. At least three cyber-espionage groups have compromised telecommunications operators in multiple countries in the Asia-Pacific region, placing backdoors inside the communications providers’ networks, stealing… Continue Reading
Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021 post, juni 20, 2024februari 24, 2025 Cyber espionage groups associated with China have been linked to a long-running campaign that has infiltrated several telecom operators located in a single Asian country at least since 2021. “The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials,” the Symantec Threat Hunter Team,… Continue Reading