Aggregator
ScarCruft Abuses Legitimate Cloud Services for C2 and OLE-based Chain to Drop Malware
ScarCruft, a prolific North Korean-backed advanced persistent threat (APT) group, has significantly refined its cyberespionage capabilities in a newly identified campaign distributing the ROKRAT malware. This recent activity marks a strategic deviation from their traditional reliance on LNK-based attack chains, pivoting instead to a complex infection method utilizing Object Linking and Embedding (OLE) objects embedded […]
The post ScarCruft Abuses Legitimate Cloud Services for C2 and OLE-based Chain to Drop Malware appeared first on Cyber Security News.
【安全圈】SandboxJS 四大高危漏洞(CVSS 10.0)可导致宿主系统沦陷
【安全圈】初始访问黑客借 Tsundere Bot 入侵网络,或为勒索攻击铺路
【安全圈】快手被罚 1 个亿,该来的还是来了
AI security’s ‘Great Wall’ problem
AI security requires more than cloud hardening. The real attack surface isn't your infrastructure—it's the supply chains, agents, and humans that make up the system around it.
The post AI security’s ‘Great Wall’ problem appeared first on CyberScoop.
Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign
How to outsmart modern phishing techniques
European Commission Contains Cyber-Attack Targeting Staff Mobile Data
The European Commission has confirmed the detection and containment of a security incident affecting the central infrastructure that manages staff mobile devices. The breach, identified on January 30 through internal telemetry, resulted in unauthorized access to a limited subset of Personally Identifiable Information (PII), specifically staff names and mobile numbers. Crucially, the attack appears to […]
The post European Commission Contains Cyber-Attack Targeting Staff Mobile Data appeared first on Cyber Security News.