Security
Headlines
HeadlinesLatestCVEs

Tag

#intel

ModernLoader delivers multiple stealers, cryptominers and RATs

By Vanja Svajcer Cisco Talos recently observed three separate, but related, campaigns between March and June 2022 delivering a variety of threats, including the ModernLoader bot, RedLine information-stealer and cryptocurrency-mining malware to victims. The actors use PowerShell, .NET assemblies, and HTA and VBS files to spread across a targeted network, eventually dropping other pieces of malware, such as the SystemBC trojan and DCRAT, to enable various stages of their operations. The attackers' use of a variety of off-the-shelf tools makes it difficult to attribute this activity to a specific adversary. The final payload appears to be ModernLoader, which acts as a remote access trojan (RAT) by collecting system information and deploying various modules. In the earlier campaigns from March, we also observed the attackers delivering the cryptocurrency mining malware XMRig. The March campaigns appeared to be targeting Eastern European users, as the constructor utility we analyzed had...

TALOS
#web#mac#windows#google#microsoft#amazon#cisco#js#git#wordpress#intel#php#auth#sap
Inside the Shadow Evacuation of Kabul

In the last two weeks of the war, an ad hoc team armed with group chats, QR codes, and satellite maps launched a mad dash to save imperiled Afghan allies.

CVE-2022-32993: TOTOLINK

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

Receipt for €8M iOS Zero-Day Sale Pops Up on Dark Web

Documents appear to show that Israeli spyware company Intellexa sold a full suite of services around a zero-day affecting both Android and iOS ecosystems.

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.

Cyber-Insurance Firms Limit Payouts, Risk Obsolescence

Businesses need to re-evaluate their cyber-insurance policies as firms like Lloyd's of London continue to add restrictions, including excluding losses related to state-backed cyberattackers.

The Telegram-Powered News Outlet Waging Guerrilla War on Russia

Anti-Putin media network February Morning has become a central player in the underground fight against the Kremlin.

NATO Probes Hackers Selling Data from Top Missile Firm MBDA

By Waqas MBDA is the world's 2nd largest manufacturer of missiles and currently, hackers are selling 70 GB worth of its alleged data for 1 BTC on a Russian forum. This is a post from HackRead.com Read the original post: NATO Probes Hackers Selling Data from Top Missile Firm MBDA

CVE-2022-38555: Linksys | Networking & WiFi Technology

Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

A US Propaganda Operation Hit Russia and China With Memes

Plus: An Iranian hacking tool steals inboxes, LastPass gets hacked, and a deepfake scammer targets the crypto world.