FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ Threatpost | The first stop for security news

iPhone Users Urged to Update to Patch 2 Zero-Days

By: Elizabeth Montalbano β€” August 19th 2022 at 15:25
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Google Patches Chrome’s Fifth Zero-Day of the Year

By: Elizabeth Montalbano β€” August 18th 2022 at 14:31
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
☐ β˜† βœ‡ Threatpost | The first stop for security news

APT Lazarus Targets Engineers with macOS Malware

By: Elizabeth Montalbano β€” August 17th 2022 at 15:07
The North Korean APT is using a fake job posting for Coinbase in a cyberespionage campaign targeting users of both Apple and Intel-based systems.
☐ β˜† βœ‡ Threatpost | The first stop for security news

U.K. Water Supplier Hit with Clop Ransomware Attack

By: Elizabeth Montalbano β€” August 16th 2022 at 14:30
The incident disrupted corporate IT systems at one company while attackers misidentified the victim in a post on its website that leaked stolen data.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Feds: Zeppelin Ransomware Resurfaces with New Compromise, Encryption Tactics

By: Elizabeth Montalbano β€” August 12th 2022 at 18:20
The CISA has seen a resurgence of the malware targeting a range of verticals and critical infrastructure organizations by exploiting RDP, firewall vulnerabilities.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Starlink Successfully Hacked Using $25 Modchip

By: Elizabeth Montalbano β€” August 11th 2022 at 15:48
Belgian researcher Lennert Wouters revealed at Black Hat how he mounted a successful fault injection attack on a user terminal for SpaceX’s satellite-based internet system
☐ β˜† βœ‡ Threatpost | The first stop for security news

New Hacker Forum Takes Pro-Ukraine Stance

By: Elizabeth Montalbano β€” August 11th 2022 at 15:14
A uniquely politically motivated site called DUMPS focuses solely on threat activity directed against Russia and Belarus
☐ β˜† βœ‡ Threatpost | The first stop for security news

Virtual Currency Platform β€˜Tornado Cash’ Accused of Aiding APTs

By: Elizabeth Montalbano β€” August 9th 2022 at 17:58
U.S. Treasury blocked the business of the virtual currency mixer for laundering more than $7 billion for hackers, including $455 million to help fund North Korea’s missile program.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Phishers Swim Around 2FA in Coinbase Account Heists

By: Elizabeth Montalbano β€” August 8th 2022 at 15:26
Attackers are spoofing the widely used cryptocurrency exchange to trick users into logging in so they can steal their credentials and eventually their funds.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Open Redirect Flaw Snags Amex, Snapchat User Data

By: Elizabeth Montalbano β€” August 5th 2022 at 13:17
Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims.
☐ β˜† βœ‡ Threatpost | The first stop for security news

VMWare Urges Users to Patch Critical Authentication Bypass Bug

By: Elizabeth Montalbano β€” August 3rd 2022 at 15:23
Vulnerabilityβ€”for which a proof-of-concept is forthcomingβ€”is one of a string of flaws the company fixed that could lead to an attack chain.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Universities Put Email Users at Cyber Risk

By: Elizabeth Montalbano β€” August 2nd 2022 at 23:02
DMARC analysis by Proofpoint shows that institutions in the U.S. have among some of the poorest protections to prevent domain spoofing and lack protections to block fraudulent emails.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Malicious Npm Packages Tapped Again to Target Discord Users

By: Elizabeth Montalbano β€” July 29th 2022 at 15:07
Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Threat Actors Pivot Around Microsoft’s Macro-Blocking in Office

By: Elizabeth Montalbano β€” July 28th 2022 at 17:24
Cybercriminals turn to container files and other tactics to get around the company’s attempt to thwart a popular way to deliver malicious phishing payloads.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Messaging Apps Tapped as Platform for Cybercriminal Activity

By: Elizabeth Montalbano β€” July 27th 2022 at 16:57
Built-in Telegram and Discord services are fertile ground for storing stolen data, hosting malware and using bots for nefarious purposes.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Novel Malware Hijacks Facebook Business Accounts

By: Elizabeth Montalbano β€” July 26th 2022 at 18:15
Newly discovered malware linked to Vietnamese threat actors targets users through a LinkedIn phishing campaign to steal data and admin privileges for financial gain.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Hackers for Hire: Adversaries Employ β€˜Cyber Mercenaries’

By: Elizabeth Montalbano β€” July 21st 2022 at 12:59
Also known as the Atlantis Cyber-Army, the emerging organization has an enigmatic leader and a core set of admins that offer a range of services, including exclusive data leaks, DDoS and RDP.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems

By: Elizabeth Montalbano β€” July 20th 2022 at 12:14
300 restaurants and at least 50,000 payment cards compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services.
☐ β˜† βœ‡ Threatpost | The first stop for security news

FBI Warns Fake Crypto Apps are Bilking Investors of Millions

By: Elizabeth Montalbano β€” July 19th 2022 at 15:20
Threat actors offer victims what appear to be investment services from legitimate companies to lure them into downloading malicious apps aimed at defrauding them.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Google Boots Multiple Malware-laced Android Apps from Marketplace

By: Elizabeth Montalbano β€” July 18th 2022 at 12:32
Google removed eight Android apps, with 3M cumulative downloads, from its marketplace for being infected with a Joker spyware variant.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Emerging H0lyGh0st Ransomware Tied to North Korea

By: Elizabeth Montalbano β€” July 15th 2022 at 16:26
Microsoft has linked a threat that emerged in June 2021 and targets small-to-mid-sized businesses to state-sponsored actors tracked as DEV-0530.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Journalists Emerge as Favored Attack Target for APTs

By: Elizabeth Montalbano β€” July 14th 2022 at 15:08
Since 2021, various state-aligned threat groups have turned up their targeting of journalists to siphon data and credentials and also track them.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Large-Scale Phishing Campaign Bypasses MFA

By: Elizabeth Montalbano β€” July 13th 2022 at 11:45
Attackers used adversary-in-the-middle attacks to steal passwords, hijack sign-in sessions and skip authentication and then use victim mailboxes to launch BEC attacks against other targets.
☐ β˜† βœ‡ Threatpost | The first stop for security news

β€˜Callback’ Phishing Campaign Impersonates Security Firms

By: Elizabeth Montalbano β€” July 12th 2022 at 11:43
Victims instructed to make a phone call that will direct them to a link for downloading malware.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Sneaky Orbit Malware Backdoors Linux Devices

By: Elizabeth Montalbano β€” July 8th 2022 at 14:45
The novel threat steals data and can affect all processes running on the OS, stealing information from different commands and utilities and then storing it on the affected machine.
☐ β˜† βœ‡ Threatpost | The first stop for security news

U.S. Healthcare Orgs Targeted with Maui Ransomware

By: Elizabeth Montalbano β€” July 8th 2022 at 10:46
State-sponsored actors are deploying the unique malware--which targets specific files and leaves no ransomware note--in ongoing attacks.
❌