FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally.

The campaign, active since … Continue reading FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

Posted in Uncategorized

GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub is moving to strengthen software supply chain security by updating “actions/checkout” to block pwn request attacks that exploit the risky use of the “pull_request_target workflow” trigger to run malicious code with the workflow’s full privileges… Continue reading GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

Posted in Uncategorized

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software.

Per findings from Kaspersky, the active campaign… Continue reading WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

Posted in Uncategorized