20 Sep Fake WinRAR proof-of-concept exploit drops VenomRAT malware A hacker is spreading a fake proof-of-concept (PoC) exploit for a recently fixed WinRAR vulnerability on GitHub, attempting to infect downloaders with the VenomRAT malware. […]
19 Sep Claimants in Celsius crypto bankruptcy targeted in phishing attack Scammers are impersonating the bankruptcy claim agent for crypto lender Celsius in phishing attacks that attempt to steal funds from cryptocurrency wallets. […]
19 Sep Trend Micro fixes endpoint protection zero-day used in attacks Trend Micro fixed a remote code execution zero-day vulnerability in the Trend Micro’s Apex One endpoint protection solution that was actively exploited in attacks. […]
19 Sep Hackers breached International Criminal Court’s systems last week The International Criminal Court (ICC) disclosed a cyberattack on Tuesday after discovering last week that its systems had been breached. […]
19 Sep GitLab urges users to install security updates for critical pipeline flaw GitLab has released security updates to address a critical severity vulnerability that allows attackers to run pipelines as other users via scheduled security scan policies. […]
18 Sep APT36 state hackers infect Android devices using YouTube app clones The APT36 hacking group, aka ‘Transparent Tribe,’ has been observed using at least three Android apps that mimic YouTube to infect devices with their signature remote access trojan (RAT), ‘CapraRAT.’ […]
18 Sep Thousands of Juniper devices vulnerable to unauthenticated RCE flaw An estimated 12,000 Juniper SRX firewalls and EX switches are vulnerable to a fileless remote code execution flaw that attackers can exploit without authentication. […]
18 Sep Bumblebee malware returns in new attacks abusing WebDAV folders The malware loader ‘Bumblebee’ has broken its two-month vacation with a new campaign that employs new distribution techniques that abuse 4shared WebDAV services. […]
17 Sep TikTok flooded by ‘Elon Musk’ cryptocurrency giveaway scams TikTok is flooded by a surge of fake cryptocurrency giveaways posted to the video-sharing platform, with almost all of the videos pretending to be themes based on Elon Musk, Tesla, or SpaceX. […]
16 Sep BlackCat ransomware hits Azure Storage with Sphynx encryptor The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets’ Azure cloud storage. […]