This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here. On the last Friday in December, a German businessman in his mid-40s allegedly met...
Counterfeit products are a growing problem in today’s market. With advancements in technology, counterfeiters have become more skilled…
AI systems are becoming a huge part of our lives, but they are not perfect. Red teaming helps…
Cybercriminals are skilled at using public information to their advantage. Knowing how they gather this data can help…
Following last week’s creation of a new Council for National Security, the U.S. Federal Communications Commission (FCC) has... The post US FCC launches probes into CCP-linked entities amid...
Oracle denies breach claims as hacker alleges access to 6 million cloud records. CloudSEK reports a potential zero-day exploit affecting 140,000 tenants.
The U.S. Treasury Department has announced that it's removing sanctions against Tornado Cash, a cryptocurrency mixer service that has been accused of aiding the North Korea-linked Lazarus Group to...
Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com. [...]
Cybercriminals are abusing Microsoft's Trusted Signing platform to code-sign malware executables with short-lived three-day certificates. [...]
Cybercriminals are abusing Microsoft's Trusted Signing platform to code-sign malware executables with short-lived three-day certificates. [...]
New phishing scam targets Instagram business accounts using fake chatbots and support emails, tricking users into handing over login credentials.
Botnets are becoming more sophisticated and accessible. DDoS attacks, cryptocurrency mining and data theft are just a few examples of botnet capabilities.
Part 1 of 2: The data in motion edition
Valve removed a video game called Sniper: Phantom's Resolution from Steam after users reported that its free demo contained malware.
Researchers have determined that Coinbase was the primary target in a recent GitHub Actions cascading supply chain attack that compromised secrets in hundreds of repositories. [...]
Threat hunters have uncovered a new threat actor named UAT-5918 that has been attacking critical infrastructure entities in Taiwan since at least 2023. "UAT-5918, a threat actor believed to be...
Authorities in at least two U.S. states last week independently announced arrests of Chinese nationals accused of perpetrating a novel form of tap-to-pay fraud using mobile devices. Details...
The FCC commissioner said letters of inquiry and at least one subpoena have been sent to Chinese-owned companies. The post FCC’s Carr alleges Chinese companies are making ‘end run’ around Chinese...
The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a malicious driver dubbed ABYSSWORKER as part of a bring your own vulnerable driver (BYOVD)...
After Windows defenses improved, the attackers switched to targeting Mac and Safari users with these very effective scams.
After Windows defenses improved, the attackers switched to targeting Mac and Safari users with these very effective scams.
The latest version patches a critical security flaw that could allow a web page to run malicious code in the browser.
Credential theft alert! Venak Security discovers a BYOVD attack using .SYS drivers to bypass Windows security. Learn how…
Oracle denies it was breached after a threat actor claimed to be selling 6 million data records allegedly stolen from the company's Oracle Cloud federated SSO login servers [...]
After conducting over 10,000 automated internal network penetration tests last year, vPenTest has uncovered a troubling reality that many businesses still have critical security gaps that...
The China-linked advanced persistent threat (APT) group. known as Aquatic Panda has been linked to a "global espionage campaign" that took place in 2022 targeting seven organizations. These...
Tornado Cash, which the U.S. sanctioned in 2022, was dropped from that list by the Trump administration following a court decision favoring the cryptocurrency mixer in November.
Two known threat activity clusters codenamed Head Mare and Twelve have likely joined forces to target Russian entities, new findings from Kaspersky reveal. "Head Mare relied heavily on tools...
2025-03-12 • Red Canary • Red Canary • win.hijackloader, win.lumma, win.netsupportmanager_rat Open article on Malpedia
2025-03-20 • ESET Research • Matthieu Faou • win.shadowpad, win.sodamaster, win.spyder Open article on Malpedia