This Week in Security: The Github Supply Chain Attack, Ransomware Decryption, and Paragon

Last Friday Github saw a supply chain attack hidden in a popular Github Action. To understand this, we have to quickly cover Continuous Integration (CI) and Github Actions. CI essentially …read more Continue reading This Week in Security: The Github Supply Chain Attack, Ransomware Decryption, and Paragon

UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

Threat hunters have uncovered a new threat actor named UAT-5918 that has been attacking critical infrastructure entities in Taiwan since at least 2023.
“UAT-5918, a threat actor believed to be motivated by establishing long-term access for information … Continue reading UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

Posted in Uncategorized

Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates

The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a malicious driver dubbed ABYSSWORKER as part of a bring your own vulnerable driver (BYOVD) attack designed to disable anti-malware tools.
Elastic Sec… Continue reading Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates

Posted in Uncategorized