November 24, 2024
Articles CyberSecurity Technology

Chinese Hackers Utilize Golang Malware in Dragon Spark Attacks

Organizations in East Asia are targeted by likely Chinese-speaking actor dubbed DragonSpark while employing uncommon tactics to go past security layers. Chinese hackers utilize malware and attacks are characterized by use of open source SparkRAT and malware which attempts to evade detection through a Golang source code interpretation. A striking aspect of the intrusions is […]

Read More
Articles CyberSecurity Technology

Emotet Malware Makes a Comeback with New Evasion Technique

The Emotet malware operation has continued to refine its tactics in a effort to fly under the radar while acting as a conduit for other dangerous malware such as Bumblebee and IcedID. Emotet which is officially reemerged in late 2021 after which a coordinated takedown of its infrastructure by authorities earlier that year which has […]

Read More
Articles CyberSecurity Technology

Apple issues Update for older Devices

Apple has fixes for a recently disclosed critical security flaw that is affecting older devices which is reciting evidence of active exploitation. The issue which is tracked as CVE-2022-42856 and is a type confusion vulnerability in the WebKit browser engine that could result in arbitrary code execution when processing maliciously crafted web content. While it […]

Read More
Articles CyberSecurity Technology

Samsung Galaxy Store App Vulnerable to Sneaky App Install

Two security flaws has disclosed in Samsung’s Galaxy Store app for Android that are exploited by a local attacker to install arbitrary apps to fraudulent landing pages on the web. The issues that tracked as CVE-2023-21433 and CVE-2023-21434, were discovered by NCC Group which is notified to the South Korean chaebol in November and December […]

Read More
CyberSecurity Technology

Chinese Hackers Exploited Recent Fortinet Flaw

Suspected China-nexus threat actor exploited a recently patched vulnerability in Fortinet FortiOS SSL-VPN as a zero-day in attacks which are targeting a European government entity and a managed service provider (MSP)that is located in Africa. Telemetry evidence gathered by Google-owned Mandiant indicates that the exploitation is occurred as early as October 2022which is at least […]

Read More
Articles CyberSecurity Technology

Warning for Android Users,New Hook Malware with RAT Capabilities Emerges

The threat actor behind the BlackRock and ERMAC Android banking trojans has uncovered yet another malware for rent called Hook which introduces new capabilities to access files that are stored in the devices and create a remote interactive session. Hook as a novel ERMAC fork which is advertised for sale for $7,000 per month while […]

Read More
Articles CyberSecurity Technology

WhatsApp Fined €5.5 Million for Violating Data Protection Laws

The Irish Data Protection Commission imposed fresh fines of €5.5 million against Meta’s WhatsApp for violating data protection laws which was processing users’ personal information. Main point of focus of the ruling is an update to the messaging platform like whatsapp Terms of Service which was imposed in the days which leads enforcement of the […]

Read More
Articles CyberSecurity Technology

Raccoon and Vidar Stealers Spreading through Massive Network of Fake Cracked Software

A resilient infrastructure comprising over 250 domains used to distribute information-stealing malware such as Raccoon and Vidar since early 2020. The infection chain uses about a hundred of fake cracked software catalogue websites which are redirect to several links before downloading the payload hosted on file share platforms such as GitHub.It led to distribution of […]

Read More
Articles CyberSecurity Technology

Malware Attack on CircleCI Engineer’s Laptop

DevOps platform CircleCI disclosed that unidentified threat actors compromised an employee’s laptop and leveraged malware to steal their two-factor authentication-backed credentials to breach the company’s systems and data last month. The sophisticated attack took place in mid December 2022 and that the malware went undetected by its antivirus software led to malware attack on laptop […]

Read More
CyberSecurity Technology

Cisco warned for unpatched vulnurabilities in EoL Buisness routers

Cisco warned of two security vulnerabilities which affects end-of-life Small Business RV016, RV042, RV042G, and RV082 routers which will not be fixedaccording to them as it acknowledged the public availability of proof-of-concept exploit. The issues of cisco are present in the routers web-based management interface which enables a remote adversary to sidestep authentication which malicious […]

Read More