Tag: cyber attacks

Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks
News

Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks

On Sunday, Microsoft published security updates for a SharePoint vulnerability that was being actively exploited. The company also revealed information on another vulnerability that it said had been fixed with stronger safeguards. The IT behemoth admitted that it is aware of ongoing attacks that take advantage of flaws that the July Security Update only partially fixed and target users of on-premises SharePoint Server. As the exploited vulnerability is recorded, CVE-2025-53770 (CVSS score: 9.8) relates to a situation of remote code execution that occurs when untrusted data is deserialized in on-premise versions of Microsoft SharePoint Server. The recently revealed vulnerability is a SharePoint spoofing vulnerability (CVE-2025-53771, CVSS score: 6.3). The bug has been identified a...
China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial Access
News

China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial Access

The threat actor with ties to China that exploited security holes in Microsoft Exchange servers in January 2021 using zero-day exploits has changed its strategy to target the IT supply chain in order to gain early access to business networks. In order to gain traction, the Silk Typhoon (formerly Hafnium) hacking organization is now focusing on IT solutions including cloud apps and remote management tools, according to recent research from the Microsoft Threat Intelligence team. In order to accomplish their espionage goals, Silk Typhoon uses the credentials and keys they have stolen to breach customer networks and exploit a range of installed applications, such as Microsoft services, according to a report released today by the tech giant read more about China-Linked Silk Typhoon Expa...
Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials
News

Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials

Over the course of the last year, more than 140,000 phishing websites have been discovered to be connected to the PhaaS platform Sniper Dz, suggesting that many fraudsters are using it to steal credentials. In a technical report, researchers Shehroze Farooqi, Howard Tong, and Alex Starov of Palo Alto Networks Unit 42 stated that Sniper Dz provides an online admin panel with a collection of phishing URLs for potential attackers. Phishers can either host these phishing pages on Sniper Dz-owned infrastructure or obtain Sniper Dz phishing templates to install on their own servers." The fact that these services are given away for free may be what makes it even more profitable read more about Free Sniper Dz Phishing Tools Fuel 140000+ Cyber Attacks Targeting User Credentials. Get up...
Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks
News

Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks

Microsoft has disclosed that the notorious cybercrime collective known as Scattered Spider has included ransomware strains like Qilin and RansomHub in its repertoire. A threat actor noted for using complex social engineering techniques to compromise targets and create persistence for later exploitation and data theft is called the "Scattered Spider." Additionally, it has a history of using the BlackCat ransomware to attack VMware ESXi servers. It overlaps with activity clusters that are monitored under the names 0ktapus, Octo Tempest, and UNC3944 by the larger cybersecurity community. An important gang member was reportedly detained in Spain last month read more about Scattered Spider Adopts RansomHub and Qilin Ransomware for Cyber Attacks. Get up to date on the latest cybersecur...
French Diplomatic Entities Targeted in Russian-Linked Cyber Attacks
News

French Diplomatic Entities Targeted in Russian-Linked Cyber Attacks

The information security agency of France, ANSSI, released an advice stating that targeted cyberattacks against diplomatic entities have been connected to state-sponsored actors with ties to Russia. Microsoft's Midnight Blizzard (previously Nobelium) cluster, which overlaps with activities monitored as APT29, BlueBravo, Cloaked Ursa, Cozy Bear, and The Dukes, has been blamed for the attacks. Although intrusion sets linked to the Russian Foreign Intelligence Service (SVR) have been referred to by the names APT29 and Midnight Blizzard interchangeably, ANSSI stated that it prefers to treat them as separate threat clusters in addition to a third one known as Dark Halo, which has been implicated in the 2020 supply chain attack using SolarWinds software read more about French Diplomatic E...
Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks
News

Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks

As part of a mission to target South Korean organizations, the Kimsuky (also known as Springtail) advanced persistent threat (APT) group, associated with North Korea's Reconnaissance General Bureau (RGB), has been seen spreading a Linux variant of its GoBear backdoor. The Gomir backdoor shares a lot of code with other malware variants and is structurally nearly identical to GoBear, according to a recent analysis from the Broadcom-owned Symantec Threat Hunter Team. Any operating system-specific functionality from GoBear has either been removed or reimplemented in Gomir. Early in February 2024, GoBear was discovered by the South Korean security company S2W in relation to a campaign that distributed malware known as Troll Stealer (also known as TrollAgent), which overlaps with families...
Linux Version of DinodasRAT Spotted in Cyber Attacks Across Several Countries
News

Linux Version of DinodasRAT Spotted in Cyber Attacks Across Several Countries

Recent research from Kaspersky shows that a Linux variant of the multi-platform backdoor DinodasRAT, which targets China, Taiwan, Turkey, and Uzbekistan, has been found in the wild. DinodasRAT, a malware that is built on C++ and goes by the name XDealer, is capable of collecting a variety of private information from infiltrated systems. Operation Jacana, a cyberespionage campaign aimed at deploying the Windows version of the implant, targeted a government agency in Guyana, according to information released by the Slovak cybersecurity company ESET in October 2023. Subsequently, Trend Micro described this week a threat activity cluster that it monitors as Earth Krahang, which has switched to employing DinodasRAT read more Linux Version of DinodasRAT Spotted in Cyber Attacks Across ...
U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks
News

U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks

Six Iranian intelligence service officials were sanctioned by the Office of Foreign Assets Control (OFAC) of the U.S. Treasury Department for hacking vital infrastructure facilities in the United States and other nations. Members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) include Hamid Reza Lashgarian, Mahdi Lashgarian, Hamid Homayunfal, Milad Mansuri, Mohammad Bagher Shirinkar, and Reza Mohammad Amin Saberian. Reza Lashgarian is a commander in the IRGC-Quds Force and the chairman of the IRGC-CEC. He is said to have taken part in several intelligence and read more U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with ou...
Albanian Parliament and One Albania Telecom Hit by Cyber Attacks
News

Albanian Parliament and One Albania Telecom Hit by Cyber Attacks

The National Authority for Electronic Certification and Cyber Security (AKCESK) of Albania disclosed this week that cyberattacks had targeted the Assembly of the Republic of Albania and telecom provider One Albania. "These infrastructures, under the legislation in force, are not currently classified as critical or important information infrastructure," AKCESK stated. With almost 1.5 million users, One Albania said in a Facebook post on December 25 that it had managed the security problem flawlessly and that none of its services—including IPTV, landline, and mobile—were impacted. Noting that the breaches did not come from IP addresses in Albania read more Albanian Parliament and One Albania Telecom Hit by Cyber Attacks. Get up to date on the latest cybersecurity news and enhanc...
Beware: MetaStealer Malware Targets Apple macOS in Recent Attacks
News

Beware: MetaStealer Malware Targets Apple macOS in Recent Attacks

After MacStealer, Pureland, Atomic Stealer, and Realst, a brand-new information-stealing malware family by the name of MetaStealer has its eyes set on the Apple macOS operating system. According to a Monday investigation by SentinelOne security researcher Phil Stokes, "threat actors are actively targeting macOS businesses by posing as fake clients in order to socially engineer victims into launching malicious payloads." The targets of these assaults are approached by threat actors posing as potential design clients in order to share a password-protected ZIP package containing the DMG file, which is how MetaStealer is transmitted in these attacks read more MetaStealer Malware Targets Apple macOS in Recent Attacks. Stay informed with the best cybersecurity news and raise your cyber...