Skip to content

Malware

Security and Technology news from various third party sources. All attribution remains the property of the original authors

351 Topics 351 Posts
  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Threat actors are creating accounts within the Adobe Cloud suite and sending images and PDFs that appear legitimate to target Office 365 and Gmail users, researchers from Avanan discovered.

    https://threatpost.com/adobe-cloud-steal-office-365-gmail-credentials/177625/

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    A cloudy campaign delivers commodity remote-access trojans to steal information and execute code.

    https://threatpost.com/amazon-azure-clouds-rat-infostealing/177606/

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    The FBI warned that attackers are impersonating Health & Human Services and/or Amazon to mail BadUSB-poisoned USB devices to targets in transportation, insurance & defense.

    https://threatpost.com/fin7-mailing-malicious-usb-sticks-ransomware/177541/

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    The malware establishes initial access on targeted machines, then waits for additional code to execute.

    https://threatpost.com/undetected-sysjoker-backdoor-malwarewindows-linux-macos/177532/

  • 0 Votes
    1 Posts
    36 Views
    CerberusC

    Cyberattacks increased 50 percent YoY in 2021 and peaked in December due to a frenzy of Log4j exploits, researchers found.

    https://threatpost.com/cyber-spike-attacks-high-log4j/177481/

  • 0 Votes
    1 Posts
    44 Views
    CerberusC

    End of life, end of support, pandemic-induced shipping delays and remote work, scanning failures: It’s a recipe for a patching nightmare, federal cyberserurity CTO Matt Keller says.

    https://threatpost.com/eol-systems-stonewalling-log4j-fixes-for-fed-agencies/177475/

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    There are active ransomware and brute-force attacks being launched against internet-exposed, network-attached storage devices, the device maker warned.

    https://threatpost.com/qnap-nas-devices-ransomware-attacks/177452/

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    Activision is suing to shut down the EngineOwning cheat-code site and hold individual developers and coders liable for damages.

    https://threatpost.com/activision-lawsuit-call-of-duty-cheat-codes/177443/

  • 0 Votes
    1 Posts
    43 Views
    CerberusC

    The ‘NoReboot’ technique is the ultimate in persistence for iPhone malware, preventing reboots and enabling remote attackers to do anything on the device while remaining completely unseen.

    https://threatpost.com/apple-iphone-malware-fake-shutdowns-spying/177420/

  • 0 Votes
    1 Posts
    41 Views
    CerberusC

    The group blends into an environment before loading up trivial, thickly stacked, fraudulent financial transactions too tiny to be noticed but adding up to millions of dollars.

    https://threatpost.com/elephant-beetle-months-networks-financial/177393/

  • 0 Votes
    1 Posts
    30 Views
    CerberusC

    Companies that fail to protect secure consumer data from Log4J attacks are at risk of facing Equifax-esque legal action and fines, the FTC warned.

    https://threatpost.com/ftc-pursue-companies-log4j/177368/

  • 0 Votes
    1 Posts
    48 Views
    CerberusC

    The info-stealing campaign using ZLoader malware – previously used to deliver Ryuk and Conti ransomware – already has claimed more than 2,000 victims across 111 countries.

    https://threatpost.com/malsmoke-microsoft-e-signature-verification/177363/

  • 0 Votes
    1 Posts
    39 Views
    CerberusC

    Microsoft says it’s only going to get worse: It’s seen state-sponsored and cyber-criminal attackers probing systems for the Log4Shell flaw through the end of December.

    https://threatpost.com/microsoft-rampant-log4j-exploits-testing/177358/

  • 0 Votes
    1 Posts
    40 Views
    CerberusC

    The campaign was an opportunistic supply-chain attack abusing a weaponized cloud video player.

    https://threatpost.com/data-skimmer-sothebys-real-estate-websites/177347/

  • 0 Votes
    1 Posts
    37 Views
    CerberusC

    Multiple malicious installers were delivering the same Purple Fox rootkit version using the same attack chain, possibly distributed via email or phishing sites.

    https://threatpost.com/purple-fox-rootkit-telegram-installers/177330/

  • 0 Votes
    1 Posts
    29 Views
    CerberusC

    The Pacific Northwest hospitality stalwart is also still operationally crippled by a Dec. 12 ransomware attack.

    https://threatpost.com/mcmenamins-data-breach-employee-info/177336/

  • 0 Votes
    1 Posts
    46 Views
    CerberusC

    The websites of the company and the Expresso newspaper, as well as all of its SIC TV channels remained offline Tuesday after the New Year’s weekend attack.

    https://threatpost.com/portuguese-media-giant-impresa-ransomware/177323/

  • 0 Votes
    1 Posts
    38 Views
    CerberusC

    Expect many more zero-day exploits in 2022, and cyberattacks using them being launched at a significantly higher rate, warns Aamir Lakhani, researcher at FortiGuard Labs.

    https://threatpost.com/rise-cyber-recon-security-strategy/177317/

  • 5 Cybersecurity Trends to Watch in 2022

    1
    0 Votes
    1 Posts
    37 Views
    CerberusC

    Here’s what cybersecurity watchers want infosec pros to know heading into 2022.

    https://threatpost.com/5-cybersecurity-trends-2022/177273/

  • 0 Votes
    1 Posts
    35 Views
    CerberusC

    The year wasn’t ALL bad news. These sometimes cringe-worthy/sometimes laughable cybersecurity and other technology stories offer schadenfreude and WTF opportunities, and some giggles.

    https://threatpost.com/2021-log4j-year-review-funny-cybersecurity/177215/