Tag: Cyber Threats

PCPJack Hijacks 230 AWS, Google Cloud, And Azure Servers To Build Covert SMTP Relay Network

Threat actor PCPJack hijacked 230 AWS, Google Cloud, and Microsoft Azure servers to establish a covert SMTP relay network, according to Hunt.io findings.

Miasma Supply Chain Attack Compromises Red Hat npm Packages To Steal Credentials And Spread Self Propagating Malware

A new supply chain attack called Miasma has compromised Red Hat npm packages to steal credentials, target CI/CD environments, and deploy a self propagating malware campaign affecting developers and cloud systems.

MuddyWater Uses DLL Side Loading To Target Organizations Across Nine Countries

Iran linked hacking group MuddyWater has launched a cyber espionage campaign targeting organizations across nine countries using DLL side loading, credential theft, and covert access techniques.

Weekly Cybersecurity Recap Highlights Linux Flaws, Microsoft Defender Zero Days, Router Botnets, And Supply Chain Threats

This week’s cybersecurity developments included Linux kernel flaws, Microsoft Defender zero days, GitHub supply chain compromises, active router botnets, and increasing exploitation of vulnerabilities worldwide.

Global Authorities Dismantle First VPN Service Used By 25 Ransomware Groups

European and North American authorities have dismantled First VPN Service, a criminal VPN infrastructure reportedly used by 25 ransomware groups to conceal cyberattacks, fraud, and data theft operations.

Researchers Examine BYOVD Risks Through Vulnerable Windows Drivers Without Hardware Dependencies

New cybersecurity research highlights how vulnerable Windows kernel mode drivers may remain exploitable without dedicated hardware, raising concerns around BYOVD attacks and endpoint security risks.

Windows Zero Days Expose BitLocker Bypasses And CTFMON Privilege Escalation Risks

Security researchers have disclosed new Windows zero day vulnerabilities affecting BitLocker and CTFMON, exposing privilege escalation and encryption bypass risks across Windows 11 and Windows Server systems.

New TrickMo Android Malware Variant Uses TON And SOCKS5 To Expand Banking Attacks

Cybersecurity researchers have identified a new TrickMo Android banking trojan variant that uses TON based command and control infrastructure, SOCKS5 proxying, and SSH tunnelling to target banking and cryptocurrency users in Europe.

NDS Technologies Hosts Meet And Greet Event With Dell Technologies Focused On Cyber Resilience

NDS Technologies and Dell Technologies hosted a Meet and Greet session discussing cyber resilience, data protection, and business continuity with industry professionals and customers.

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver To Evade Security

A malvertising campaign targets U.S. users searching for tax forms, delivering ScreenConnect malware and HwAudKiller to bypass EDR using a Huawei driver.

Threat Actors Mass Scan Salesforce Experience Cloud Using Modified AuraInspector Tool

Salesforce warns of large scale scanning attempts targeting misconfigured Experience Cloud sites using a modified AuraInspector tool capable of extracting sensitive data from public endpoints.

New MacSync macOS Stealer Variant Uses Signed Apps To Bypass Apple Security

Researchers uncover a new MacSync macOS stealer variant distributed via a signed and notarized Swift app, abusing Apple trust mechanisms to evade Gatekeeper and deliver malware.

Recent articles

spot_img