19 Apr UK cyber-argency warns of a new ‘class’ of Russian hackers The United Kingdom’s NCSC (National Cyber Security Centre) is warning of a heightened risk from attacks by state-aligned Russian hacktivists, urging all organizations in the country to apply recommended security measures. […]
19 Apr Hackers actively exploit critical RCE bug in PaperCut servers Print management software developer PaperCut is warning customers to update their software immediately, as hackers are actively exploiting flaws to gain access to vulnerable servers. […]
19 Apr Google patches another actively exploited Chrome zero-day Google has released a security update for the Chrome web browser to fix the second zero-day vulnerability found to be exploited in attacks this year. […]
19 Apr Play ransomware gang uses custom Shadow Volume Copy data-theft tool The Play ransomware group has developed two custom tools in .NET, namely Grixba and VSS Copying Tool, which it uses to improve the effectiveness of its cyberattacks. […]
18 Apr Australians lost a record $3.1 billion to scams last year The Australian Competition & Consumer Commission (ACCC) says Australians lost a record $3.1 billion to scams in 2022, an 80% increase over the total losses recorded in 2021. […]
18 Apr New sandbox escape PoC exploit available for VM2 library, patch now Security researchers have released yet another sandbox escape proof of concept (PoC) exploit that makes it possible to execute unsafe code on the host running the VM2 sandbox. […]
18 Apr The Attacks that can Target your Windows Active Directory Hackers commonly target Active Directory with various attack techniques spanning many attack vectors. Let’s consider a few of these attacks and what organizations can do to protect themselves. […]
17 Apr Ex-Conti members and FIN7 devs team up to push new Domino malware Ex-Conti ransomware members have teamed up with the FIN7 threat actors to distribute a new malware family named ‘Domino’ in attacks on corporate networks. […]
17 Apr Hackers abuse Google Command and Control red team tool in attacks The Chinese state-sponsored hacking group APT41 was found abusing the GC2 (Google Command and Control) red teaming tool in data theft attacks against a Taiwanese media and an Italian job search company. […]
17 Apr New QBot email attacks use PDF and WSF combo to install malware QBot malware is now distributed in phishing campaigns utilizing PDFs and Windows Script Files (WSF) to infect Windows devices. […]