Category: Uncategorized
-

Syrian Threat Actor EVLF Unmasked as Creator of CypherRAT and CraxsRAT Android Malware [email protected] (The Hacker News)
A Syrian threat actor named EVLF has been outed as the creator of malware families CypherRAT and CraxsRAT. “These RATs are designed to allow an attacker to remotely perform real-time actions and control the victim device’s camera, location, and microphone,” Cybersecurity firm Cyfirma said in a report published last week. CypherRAT and CraxsRAT are said to be offered to…
-

Agile Approach to Mass Cloud Credential Harvesting and Crypto Mining Sprints Ahead [email protected] (The Hacker News)
Developers are not the only people who have adopted the agile methodology for their development processes. From 2023-06-15 to 2023-07-11, Permiso Security’s p0 Labs team identified and tracked an attacker developing and deploying eight (8) incremental iterations of their credential harvesting malware while continuing to develop infrastructure for an upcoming (spoiler: now launched) campaignRead More
-
US Government Publishes Guidance on Migrating to Post-Quantum Cryptography Ionut Arghire
CISA, NSA, and NIST urge organizations to create quantum-readiness roadmaps and prepare for post-quantum cryptography migration. The post US Government Publishes Guidance on Migrating to Post-Quantum Cryptography appeared first on SecurityWeek. Read More
-
First Weekly Chrome Security Update Patches High-Severity Vulnerabilities Ionut Arghire
Google has released the first weekly Chrome security update, which patches five memory safety vulnerabilities, including four rated ‘high severity’. The post First Weekly Chrome Security Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. Read More
-

Spacecolon Toolset Fuels Global Surge in Scarab Ransomware Attacks [email protected] (The Hacker News)
A malicious toolset dubbed Spacecolon is being deployed as part of an ongoing campaign to spread variants of the Scarab ransomware across victim organizations globally. “It probably finds its way into victim organizations by its operators compromising vulnerable web servers or via brute forcing RDP credentials,” ESET security researcher Jakub Souček said in a detailed technical write-upRead More
-
Exploitation of Ivanti Sentry Zero-Day Confirmed Eduard Kovacs
While initially it was unclear if the Ivanti Sentry vulnerability CVE-2023-38035 has been exploited, the vendor and CISA have now confirmed it. The post Exploitation of Ivanti Sentry Zero-Day Confirmed appeared first on SecurityWeek. Read More
-

Over a Dozen Malicious npm Packages Target Roblox Game Developers [email protected] (The Hacker News)
More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer called Luna Token Grabber on systems belonging to Roblox developers. The ongoing campaign, first detected on August 1 by ReversingLabs, employs modules that masquerade as the legitimate package noblox.js, an…
-
Ivanti issues fix for third zero-day flaw exploited in the wild
Post ContentRead More
-
TP-Link Smart Bulb Vulnerabilities Expose Households to Hacker Attacks Ionut Arghire
Vulnerabilities in the TP-Link Tapo L530E smart bulb and accompanying mobile application can be exploited to obtain the local Wi-Fi password. The post TP-Link Smart Bulb Vulnerabilities Expose Households to Hacker Attacks appeared first on SecurityWeek. Read More
-
Hacker Conversations: Cris Thomas (AKA Space Rogue) From Lopht Heavy Industries Kevin Townsend
Cris Thomas, also known as Space Rogue, was a founding member of the Lopht Heavy Industries hacker collective. The post Hacker Conversations: Cris Thomas (AKA Space Rogue) From Lopht Heavy Industries appeared first on SecurityWeek. Read More
