What keeps CISOs up at night? Mandiant leaders share top cyber concerns

A trio of top brass for Mandiant shared the emerging advanced tactics, techniques and procedures that they see troubling cyber professionals.

The post What keeps CISOs up at night? Mandiant leaders share top cyber concerns appeared first on CyberScoop.

Continue reading What keeps CISOs up at night? Mandiant leaders share top cyber concerns

Zero-day exploitation surged in 2023, Google finds

2023 saw attackers increasingly focusing on the discovery and exploitation of zero-day vulnerabilities in third-party libraries (libvpx, ImagelO) and drivers (Mali GPU, Qualcomm Adreno GPU), as they can affect multiple products and effectively offer mo… Continue reading Zero-day exploitation surged in 2023, Google finds

Google TAG Reports Zero-Day Surge and Rise of State Hacker Threats

By Waqas
Google’s Threat Analysis Group (TAG) reports a concerning rise in zero-day exploits and increased activity from state-backed hackers.…
This is a post from HackRead.com Read the original post: Google TAG Reports Zero-Day Surge and R… Continue reading Google TAG Reports Zero-Day Surge and Rise of State Hacker Threats

Google Report: Despite Surge in Zero-Day Attacks, Exploit Mitigations Are Working

Despite a surge in zero-day attacks, data shows that security investments into OS and software exploit mitigations are forcing attackers to find new attack surfaces and bug patterns.
The post Google Report: Despite Surge in Zero-Day Attacks, Exploit Mi… Continue reading Google Report: Despite Surge in Zero-Day Attacks, Exploit Mitigations Are Working

Spyware and zero-day exploits increasingly go hand-in-hand, researchers find

Researchers found 97 zero-days exploited in the wild in 2023; nearly two thirds of mobile and browser flaws were used by spyware firms.

The post Spyware and zero-day exploits increasingly go hand-in-hand, researchers find appeared first on CyberScoop.

Continue reading Spyware and zero-day exploits increasingly go hand-in-hand, researchers find

APT29 hit German political parties with bogus invites and malware

APT29 (aka Cozy Bear, aka Midnight Blizzard) has been spotted targeting German political parties for the first time, Mandiant researchers have shared. Phishing leading to malware The attack started in late February 2024, with phishing emails containing… Continue reading APT29 hit German political parties with bogus invites and malware

German political party targeted by SVR-linked group in spearphishing campaign, Mandiant says

The group may have been seeking insights on shifting European sentiments on Ukraine, threat analysts suggest.

The post German political party targeted by SVR-linked group in spearphishing campaign, Mandiant says appeared first on CyberScoop.

Continue reading German political party targeted by SVR-linked group in spearphishing campaign, Mandiant says

Russian APT29 Hackers Caught Targeting German Political Parties 

Russia’s APT29 hacking group is expanding targets to political parties in Germany using a new backdoor variant tracked as Wineloader.
The post Russian APT29 Hackers Caught Targeting German Political Parties  appeared first on SecurityWeek.
Continue reading Russian APT29 Hackers Caught Targeting German Political Parties 

State-sponsored hackers know enterprise VPN appliances inside out

Suspected Chinese state-sponsored hackers leveraging Ivanti Connect Secure VPN flaws to breach a variety of organizations have demonstrated “a nuanced understanding of the appliance”, according to Mandiant incident responders and threat hun… Continue reading State-sponsored hackers know enterprise VPN appliances inside out