[ad_1] Sep 28, 2023NewsroomSupply Chain / Malware A new deceptive campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers. “The malicious code exfiltrates the GitHub project’s defined secrets to a malicious C2 server and modify any existing javascript files in the…
Blog
Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
[ad_1] Sep 29, 2023NewsroomVulnerability / Network Security Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to achieve remote code execution on affected systems. The medium-severity vulnerability is tracked as CVE-2023-20109, and has a CVSS score of 6.6. It…
Microsoft’s AI-Powered Bing Chat Ads May Lead Users to Malware-Distributing Sites
[ad_1] Malicious ads served inside Microsoft Bing’s artificial intelligence (AI) chatbot are being used to distribute malware when searching for popular tools. The findings come from Malwarebytes, which revealed that unsuspecting users can be tricked into visiting booby-trapped sites and installing malware directly from Bing Chat conversations. Introduced by Microsoft in February 2023, Bing Chat…
Finally Real in Consumer Apps?
[ad_1] Sep 29, 2023The Hacker NewsQuantum Computing / Network Security Most people are barely thinking about basic cybersecurity, let alone post-quantum cryptography. But the impact of a post-quantum world is coming for them regardless of whether or not it’s keeping them up tonight. Today, many rely on encryption in their daily lives to protect their…
Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm
[ad_1] Sep 29, 2023NewsroomCyber Espionage / Malware The North Korea-linked Lazarus Group has been linked to a cyber espionage attack targeting an unnamed aerospace company in Spain in which employees of the firm were approached by the threat actor posing as a recruiter for Meta. “Employees of the targeted company were contacted by a fake…
Cybercriminals Using New ASMCrypt Malware Loader to Fly Under the Radar
[ad_1] Threat actors are selling a new crypter and loader called ASMCrypt, which has been described as an “evolved version” of another loader malware known as DoubleFinger. “The idea behind this type of malware is to load the final payload without the loading process or the payload itself being detected by AV/EDR, etc.,” Kaspersky said…
Iranian APT Group OilRig Using New Menorah Malware for Covert Operations
[ad_1] Sep 30, 2023NewsroomCyber Espionage / Malware Sophisticated cyber actors backed by Iran known as OilRig have been linked to a spear-phishing campaign that infects victims with a new strain of malware called Menorah. “The malware was designed for cyberespionage, capable of identifying the machine, reading and uploading files from the machine, and downloading another…
Zanubis Android Banking Trojan Poses as Peruvian Government App to Target Users
[ad_1] Oct 02, 2023NewsroomMalware / Cyber Threat An emerging Android banking trojan called Zanubis is now masquerading as a Peruvian government app to trick unsuspecting users into installing the malware. “Zanubis’s main infection path is through impersonating legitimate Peruvian Android applications and then tricking the user into enabling the Accessibility permissions in order to take…
OpenRefine’s Zip Slip Vulnerability Could Let Attackers Execute Malicious Code
[ad_1] Oct 02, 2023NewsroomVulnerability / Cyber Attack A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems. Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially…
A Year-Long Web Skimming Campaign Targeting Online Payment Businesses
[ad_1] Oct 02, 2023NewsroomWebb Security / Payment Security A financially motivated campaign has been targeting online payment businesses in the Asia Pacific, North America, and Latin America with web skimmers for more than a year. The BlackBerry Research and Intelligence Team is tracking the activity under the name Silent Skimmer, attributing it to an actor…









