Aggregator
CVE-2022-25350 | puppet-facter getFact command injection
CVE-2020-22327 | HFish 0.5.1 Name cross site scripting (Issue 61)
New Surge of IRS-Themed Attacks Targets Taxpayers’ Mobile Devices
As the U.S. tax filing deadline approaches, cybercriminals are intensifying their efforts to exploit taxpayers through a new wave of IRS-themed scams. Research from McAfee Labs has revealed a sharp increase in fraudulent activities targeting mobile devices, with scammers using deceptive text messages and fake IRS websites to steal personal and financial information. Mobile Attacks […]
The post New Surge of IRS-Themed Attacks Targets Taxpayers’ Mobile Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
KoiLoader Exploits PowerShell Scripts to Drop Malicious Payloads
Cybersecurity experts at eSentire’s Threat Response Unit (TRU) uncovered a sophisticated malware campaign leveraging KoiLoader, a malicious loader designed to deploy information-stealing payloads. This campaign utilized PowerShell scripts and obfuscation techniques to bypass security measures and infect systems. The investigation revealed a multi-stage infection chain, highlighting the evolving tactics of cybercriminals. Infection Chain and Delivery […]
The post KoiLoader Exploits PowerShell Scripts to Drop Malicious Payloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
APT34 Deploys Custom Malware Targeting Finance and Telecom Sectors
APT34, also known as OilRig or Helix Kitten, has intensified its cyber-espionage campaigns, deploying custom malware to target entities within the finance and telecommunications sectors. The group, active since 2012, is a well-documented advanced persistent threat (APT) actor linked to the Middle East. Recent investigations by the ThreatBook Research and Response Team have revealed that […]
The post APT34 Deploys Custom Malware Targeting Finance and Telecom Sectors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Plantronics Hub Flaw Allows Attackers to Gain Elevated Privileges
A critical vulnerability has been identified in the Plantronics Hub software, a client application commonly used to configure Plantronics audio devices such as headsets. The flaw, classified as an unquoted search path vulnerability, allows attackers to execute arbitrary files and escalate privileges to administrative levels under certain conditions. This issue is particularly concerning as the […]
The post Plantronics Hub Flaw Allows Attackers to Gain Elevated Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
HijackLoader Evolves with New Modules for Stealth and Malware Analysis Evasion
HijackLoader, a malware loader first identified in 2023, has undergone significant evolution with the addition of new modules designed to enhance its stealth capabilities and evade malware analysis environments. Recent research by Zscaler ThreatLabz reveals that these updates include advanced techniques such as call stack spoofing, virtual machine (VM) detection, and persistence mechanisms, marking a […]
The post HijackLoader Evolves with New Modules for Stealth and Malware Analysis Evasion appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.