Follina. Unpatched Microsoft Office zero-day vulnerability exploited in the wild

The world is waiting for a patch from Microsoft, after a zero-day vulnerability in Microsoft Office was found to be being exploited in boobytrapped Word documents to remotely execute code on victims’ PCs. Continue reading Follina. Unpatched Microsoft Office zero-day vulnerability exploited in the wild

Get Lifetime Access To Microsoft Office 2021 For Just $56

Whether you’re starting a new business venture and need Microsoft Office’s help or you just want to get better organized in your personal life, it’s a good time to take advantage of this limited-time deal. Continue reading Get Lifetime Access To Microsoft Office 2021 For Just $56

Smashing Security podcast #262: Macro progress, eyeball-tracking ads, and encryption backdoors

How does Microsoft hope to defeat the macro terror? How is the UK Government trying to influence the public’s opinion on end-to-end encryption? And what is MoviePass hoping to do with your eyeballs?

All this and much more is discussed in the latest … Continue reading Smashing Security podcast #262: Macro progress, eyeball-tracking ads, and encryption backdoors

Smashing Security podcast #262: Macro progress, eyeball-tracking ads, and encryption backdoors

How does Microsoft hope to defeat the macro terror? How is the UK Government trying to influence the public’s opinion on end-to-end encryption? And what is MoviePass hoping to do with your eyeballs?

All this and much more is discussed in the latest … Continue reading Smashing Security podcast #262: Macro progress, eyeball-tracking ads, and encryption backdoors

25 years on, Microsoft makes another stab at stopping macro malware

Bravo to Microsoft, because it sounds like they’re doing something to improve the security of Office users. Way back in 1995, Microsoft accidentally shipped a virus on CD ROM. At first Microsoft refused to call it a virus, preferring to call it a… Continue reading 25 years on, Microsoft makes another stab at stopping macro malware

The BlueNoroff cryptocurrency hunt is still on

It appears that BlueNoroff shifted focus from hitting banks and SWIFT-connected servers to solely cryptocurrency businesses as the main source of the group’s illegal income. Continue reading The BlueNoroff cryptocurrency hunt is still on

ScarCruft surveilling North Korean defectors and human rights activists

The ScarCruft group (also known as APT37 or Temp.Reaper) is a nation-state sponsored APT actor. Recently, we had an opportunity to perform a deeper investigation on a host compromised by this group. Continue reading ScarCruft surveilling North Korean defectors and human rights activists

WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019

In this report we provide details on a malicious VBS implant distributed via MS Excel droppers and a fake “Kaspersky Update Agent” which we attribute to WIRTE APT who may be linked to Gaza Cybergang. Continue reading WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019