Aggregator
月度安全态势:9月最值得关注的网络安全动态
CrowdStrike меняет систему обновлений после масштабного сбоя
RansomHub Ransomware Using Multiple Techniques To Disable EDR And Antivirus
The RansomHub ransomware group tracked as Water Bakunawa, employs targeted spear-phishing to exploit the Zerologon vulnerability, allowing them to gain unauthorized access to networks, affecting various industries and critical infrastructure sectors, demanding ransom payments for data release. The group’s recent integration of EDRKillShifter, a tool designed to evade detection and disrupt security processes, poses a […]
The post RansomHub Ransomware Using Multiple Techniques To Disable EDR And Antivirus appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
前经营者称民宿偷拍已成产业链
Octo2 Android Malware Attacking To Steal Banking Credentials
The original threat actor behind the Octo malware family has released a new variant, Octo2, with enhanced stability for remote action capabilities to facilitate Device Takeover attacks. This new variant targets European countries and employs sophisticated obfuscation techniques, including the Domain Generation Algorithm (DGA), to evade detection and ensure the Trojan remains undetected. The Exobot […]
The post Octo2 Android Malware Attacking To Steal Banking Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Квантовый вызов: как изменится финансовая безопасность в ближайшие 10 лет
New Mallox Ransomware Linux Variant Attacking Enterprise Linux Servers
Kryptina RaaS, a free and open-source RaaS platform for Linux, initially struggled to attract attention. Still, after a Mallox affiliate’s staging server was leaked in May 2024, Kryptina’s modified version, branded Mallox v1.0, gained prominence. The research examines the data exposed in the leak, highlighting differences between the original Kryptina RaaS (v2.2) and Mallox v1.0 […]
The post New Mallox Ransomware Linux Variant Attacking Enterprise Linux Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023
Минцифры: Google блокирует новые аккаунты из России
Beware Of Fake Verify You Are A Human Request That Delivers Malware
Researchers observed two distinct instances where users were inadvertently led to malicious websites after conducting Google searches for video streaming services. These victims were redirected to malicious URLs that employed a deceptive tactic while attempting to access sports or movie content. The victims were presented with a prompt requesting human verification, which, upon completion, executed […]
The post Beware Of Fake Verify You Are A Human Request That Delivers Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-8704 | Advanced File Manager Plugin up to 5.2.8 on WordPress fma_locale file inclusion
CVE-2024-8633 | Form Maker Plugin up to 1.15.27 on WordPress cross site scripting
CVE-2024-9177 | Themedy Toolbox Plugin up to 1.0.15 on WordPress Shortcode cross site scripting
CVE-2024-8126 | Advanced File Manager Plugin up to 5.2.8 on WordPress unrestricted upload
CVE-2024-8725 | Advanced File Manager Plugin up to 5.2.8 on WordPress unrestricted upload
CVE-2024-47044 | Nippon Telegraph and Telephone East Hikari Denwa router RT-400MI Device Setting Page clickjacking
Google Warns Of North Korean IT Workers Have Infiltrated The U.S. Workforce
North Korean IT workers, disguised as non-North Koreans, infiltrate various industries to generate revenue for their regime, evading sanctions and funding WMD programs by exploiting privileged access to enable cyber intrusions. Facilitators, often non-North Koreans, assist these workers by laundering money, hosting company laptops, using stolen identities, and accessing international financial systems, which help the […]
The post Google Warns Of North Korean IT Workers Have Infiltrated The U.S. Workforce appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.