Tag: threat intelligence

Abdullah Brothers & Co. has onboarded FlowHCM to enhance HR operations through a connected platform designed to support workforce management and business growth.
Microtech Inc. has received the Authorized Distributor Certificate from ZKTeco Inc., strengthening their partnership to expand security and smart technology solutions.

Kaspersky Details Silver Fox ValleyRAT Campaign Using Signed Chinese Adware

Kaspersky has uncovered a Silver Fox campaign that disguises the ValleyRAT backdoor as signed Chinese adware, using DLL sideloading to evade security controls and gain full access to compromised systems.

Malicious Chrome And Edge Extensions Target Crypto Wallets And User Credentials

Cybersecurity researchers have identified 19 Chrome and Edge extensions containing wallet stealing and cryptocurrency draining capabilities. The campaign has reportedly been active since February 2024 and uses compromised and newly created browser extensions.

HOOKEDGE Backdoor Campaign Linked To APT28 Targets European Government Networks

Recorded Future has identified a new HOOKEDGE backdoor linked to APT28, targeting government and diplomatic organizations in Romania, Spain, and Türkiye through malicious Microsoft Word documents.

GoCaracal Malware Adopts Ethereum Smart Contracts For Command And Control Resilience

Arctic Wolf has identified the new GoCaracal malware framework, linking it with medium confidence to Dark Caracal and revealing its use of Ethereum smart contracts to update command and control infrastructure.

FTP Banner Malware Campaign Uses E4del And PINHOLE RATs For Remote Access Attacks

Researchers have uncovered a malware campaign using FTP banners as dead drop resolvers to deliver E4del and PINHOLE RATs, introducing a new technique for command and control operations.

Critical SAP Commerce Cloud Flaw CVE 2026 58231 Draws Early Exploitation Activity

Security researchers have observed exploitation attempts targeting SAP Commerce Cloud vulnerability CVE 2026 58231 only days after SAP released a patch for the critical remote code execution flaw.

Updated CoolClient Malware Uses Signed Windows Rootkit For Advanced Stealth

Kaspersky has identified a new CoolClient malware variant linked to Mustang Panda that deploys a signed Windows kernel rootkit to hide malicious activity and strengthen persistence on compromised systems.

Active Exploitation Attempts Detected Against Unpatched GeoServer SQL Injection Flaw

Security researchers warn that a newly disclosed GeoServer zero day SQL injection vulnerability is being actively targeted and could lead to remote code execution on vulnerable systems.

Gunra Ransomware Targets Critical Infrastructure Through Fortinet And Schneider Electric Flaws

Cybersecurity agencies from South Korea and the United States have warned that Gunra ransomware operators are exploiting Fortinet and Schneider Electric vulnerabilities to compromise critical infrastructure organizations worldwide.

CISA Updates KEV Catalog With N-able N-central Authentication Bypass Vulnerability

CISA has added the actively exploited N-able N-central authentication bypass vulnerability CVE 2026 18577 to its KEV catalog following customer compromises and reports of ongoing attacks.

Dysphoria IoT Botnet Uses Blockchain Name Services To Strengthen Command And Control

Researchers report that the Dysphoria IoT botnet has adopted blockchain based name services and infected device relays after law enforcement disrupted JackSkid infrastructure, making the botnet more resilient.

Resecurity Pakistan Partners With Skills Share Hub For Cybersecurity Education

Resecurity Pakistan has signed an MOU with Skills Share Hub to deliver hands on cybersecurity training focused on threat intelligence, incident response, and digital risk management.

Recent articles

spot_img