Russian Hackers Heavily Using Malicious Traffic Direction System to Distribute Malware

Potential connections between a subscription-based crimeware-as-a-service (CaaS) solution and a cracked copy of Cobalt Strike have been established in what the researchers suspect is being offered as a tool for its customers to stage post-exploitation… Continue reading Russian Hackers Heavily Using Malicious Traffic Direction System to Distribute Malware

Posted in Uncategorized

FIN8 Hackers Spotted Using New ‘White Rabbit’ Ransomware in Recent Attacks

The financially motivated FIN8 actor, in all likelihood, has resurfaced with a never-before-seen ransomware strain called “White Rabbit” that was recently deployed against a local bank in the U.S. in December 2021.
That’s according to new findings pub… Continue reading FIN8 Hackers Spotted Using New ‘White Rabbit’ Ransomware in Recent Attacks

Posted in Uncategorized

Ukraine: Recent Cyber Attacks Part of Wider Plot to Sabotage Critical Infrastructure

The coordinated cyberattacks targeting Ukrainian government websites and the deployment of a data-wiper malware called WhisperGate on select government systems are part of a broader wave of malicious activities aimed at sabotaging critical infrastruct… Continue reading Ukraine: Recent Cyber Attacks Part of Wider Plot to Sabotage Critical Infrastructure

Posted in Uncategorized

Researchers Bypass SMS-based Multi-Factor Authentication Protecting Box Accounts

Cybersecurity researchers have disclosed details of a now-patched bug in Box’s multi-factor authentication (MFA) mechanism that could be abused to completely sidestep SMS-based login verification.
“Using this technique, an attacker could use stolen cr… Continue reading Researchers Bypass SMS-based Multi-Factor Authentication Protecting Box Accounts

Posted in Uncategorized

Zoho Releases Patch for Critical Flaw Affecting ManageEngine Desktop Central

Enterprise software maker Zoho on Monday issued patches for a critical security vulnerability in Desktop Central and Desktop Central MSP that a remote adversary could exploit to perform unauthorized actions in affected servers.
Tracked as CVE-2021-447… Continue reading Zoho Releases Patch for Critical Flaw Affecting ManageEngine Desktop Central

Posted in Uncategorized

Earth Lusca Hackers Aimed at High-Value Targets in Government and Private Sectors

An elusive threat actor called Earth Lusca has been observed striking organizations across the world as part of what appears to be simultaneously an espionage campaign and an attempt to reap monetary profits.
“The list of its victims includes high-val… Continue reading Earth Lusca Hackers Aimed at High-Value Targets in Government and Private Sectors

Posted in Uncategorized