Aggregator
Армия хакеров КНДР выросла до рекордных 8400 человек
DEV#POPPER Attacking developers via New Social Engineering Tactics
Threat actors masquerade as interviewers and send a ZIP file (onlinestoreforhirog.zip) to candidates as part of a fake interview, which contains legitimate files and a malicious JavaScript file (printfulRoute.js) that is obfuscated to evade detection. The obfuscated code uses techniques like base64 encoding, dynamic function names, and string concatenation to hide its functionality. After deobfuscation, […]
The post DEV#POPPER Attacking developers via New Social Engineering Tactics appeared first on Cyber Security News.
Fissare i concetti
Leading Silver Producer Fresnillo PLC Suffer Cyberattack
Fresnillo PLC, the world’s largest primary silver producer, and Mexico’s largest gold producer has announced that it has been the target of a significant cybersecurity incident. The breach resulted in unauthorized access to specific IT systems and data. Upon discovering the incident, Fresnillo immediately activated its response protocols to mitigate the impact. The company’s IT […]
The post Leading Silver Producer Fresnillo PLC Suffer Cyberattack appeared first on Cyber Security News.
Tricky OneDrive Phishing Campaign Tricks Users To Execute PowerShell Script
A sophisticated phishing campaign targets Microsoft OneDrive users, employing social engineering to trick victims into executing malicious PowerShell scripts. The attack leverages a false sense of urgency by claiming a DNS issue prevents file access, enticing users to click a button that triggers PowerShell script execution and compromising affected systems. An Email-Borne Phishing Attack Leverages […]
The post Tricky OneDrive Phishing Campaign Tricks Users To Execute PowerShell Script appeared first on Cyber Security News.
Audi Q7 Car For Sale – But Malware Will be Delivered Instead of Car
A Russian threat actor known as Fighting Ursa (also referred to as APT28, Fancy Bear, and Sofacy) has been identified in a new campaign that began in March 2024. This campaign uses a fake car sale advertisement to distribute the HeadLace backdoor malware, primarily targeting diplomats. The campaign leverages legitimate services such as Webhook.site to […]
The post Audi Q7 Car For Sale – But Malware Will be Delivered Instead of Car appeared first on Cyber Security News.
UNC4393 Actors Behind BASTA Ransomware Exploited via Partnerships
In mid-2022, Mandiant’s Managed Defense first uncovered UNC4393, the primary user of BASTA ransomware. This financially motivated threat cluster has attacked over 40 business entities and 20 industry verticals. Recently, it focused on healthcare firms. QAKBOT botnet infections are generally exploited by UNC4393 to gain initial access, with distribution being mainly done through phishing emails […]
The post UNC4393 Actors Behind BASTA Ransomware Exploited via Partnerships appeared first on Cyber Security News.
Не убивайте видеоигры: геймеры готовят петицию для властей ЕС
Server Proofpoint usati per inviare milioni di e-mail di phishing
SLUBStick Linux Vulnerability Let Attackers Gain Full System Control
Security researchers have discovered a severe vulnerability in the Linux kernel that could allow attackers to gain full control over affected systems. Dubbed “SLUBStick,” the exploit technique uses memory allocation flaws to achieve arbitrary read and write access to kernel memory. The vulnerability, detailed in a paper by Graz University of Technology researchers, affects recent […]
The post SLUBStick Linux Vulnerability Let Attackers Gain Full System Control appeared first on Cyber Security News.