07 Jun New SVCReady malware loads from Word doc properties A previously unknown malware loader named SVCReady has been discovered in phishing attacks, featuring an unusual way of loading the malware from Word documents onto compromised machines. […]
07 Jun Qbot malware now uses Windows MSDT zero-day in phishing attacks A critical Windows zero-day vulnerability, known as Follina and still waiting for an official fix from Microsoft, is now being actively exploited in ongoing phishing attacks to infect recipients with Qbot malware. […]
06 Jun QBot now pushes Black Basta ransomware in bot-powered attacks The Black Basta ransomware gang has partnered with the QBot malware operation to spread laterally through hacked corporate environments. […]
06 Jun Mandiant: “No evidence” we were hacked by LockBit ransomware American cybersecurity firm Mandiant is investigating LockBit ransomware gang’s claims that they hacked the company’s network and stole data. […]
06 Jun Ransomware gangs now give victims time to save their reputation Threat analysts have observed an unusual trend in ransomware group tactics, reporting that initial phases of victim extortion are becoming less open to the public as the actors tend to use hidden or anonymous entries. […]
06 Jun Windows zero-day exploited in US local govt phishing attacks European governments and US local governments were the targets of a phishing campaign using malicious Rich Text Format (RTF) documents designed to exploit a critical Windows zero-day vulnerability known as Follina. […]
05 Jun Exploit released for Atlassian Confluence RCE bug, patch now Proof-of-concept exploits for the actively exploited critical CVE-2022-26134 vulnerability impacting Atlassian Confluence and Data Center servers have been widely released this weekend. […]
05 Jun Evasive phishing mixes reverse tunnels and URL shortening services Security researchers are seeing an uptick in the use of reverse tunnel services along with URL shorteners for large-scale phishing campaigns, making the malicious activity more difficult to stop. […]
04 Jun Bored Ape Yacht Club, Otherside NFTs stolen in Discord server hack Hackers reportedly stole over $257,000 in Ethereum and thirty-two NFTs after the Yuga Lab’s Bored Ape Yacht Club and Otherside Metaverse Discord servers were compromised to post a phishing scam. […]
04 Jun Apple blocked 1.6 millions apps from defrauding users in 2021 Apple said this week that it blocked more than 343,000 iOS apps were blocked by the App Store App Review team for privacy violations last year, while another 157,000 were rejected for attempting to mislead or spamming iOS users. […]