Category: Uncategorized
-
Malicious QR Codes Used in Phishing Attack Targeting US Energy Company Ionut Arghire
A widespread phishing campaign utilizing malicious QR codes has hit organizations in various industries, including a major energy company in the US. The post Malicious QR Codes Used in Phishing Attack Targeting US Energy Company appeared first on SecurityWeek. Read More
-
Risk & Repeat: Highlights from Black Hat USA 2023
Post ContentRead More
-
Cisco Patches High-Severity Vulnerabilities in Enterprise Applications Ionut Arghire
Cisco has patched high-severity vulnerabilities in enterprise applications that could lead to privilege escalation, SQL injection, and denial-of-service. The post Cisco Patches High-Severity Vulnerabilities in Enterprise Applications appeared first on SecurityWeek. Read More
-

New Apple iOS 16 Exploit Enables Stealthy Cellular Access Under Fake Airplane Mode [email protected] (The Hacker News)
Cybersecurity researchers have documented a novel post-exploit persistence technique on iOS 16 that could be abused to fly under the radar and main access to an Apple device even when the victim believes it is offline. The method “tricks the victim into thinking their device’s Airplane Mode works when in reality the attacker (following successful…
-

New LABRAT Campaign Exploits GitLab Flaw for Cryptojacking and Proxyjacking Activities [email protected] (The Hacker News)
A new, financially motivated operation dubbed LABRAT has been observed weaponizing a now-patched critical flaw in GitLab as part of a cryptojacking and proxyjacking campaign. “The attacker utilized undetected signature-based tools, sophisticated and stealthy cross-platform malware, command-and-control (C2) tools which bypassed firewalls, and kernel-based rootkits to hide their presence,” Sysdig Read More
-
Thousands of Systems Turned Into Proxy Exit Nodes via Malware Ionut Arghire
Threat actors have been observed deploying a proxy application on Windows and macOS systems that were infected with malware. The post Thousands of Systems Turned Into Proxy Exit Nodes via Malware appeared first on SecurityWeek. Read More
-
CISA Releases Cyber Defense Plan to Reduce RMM Software Risks Ionut Arghire
CISA has published a cyber defense plan outlining strategies to help critical infrastructure organizations reduce the risks associated with RMM software. The post CISA Releases Cyber Defense Plan to Reduce RMM Software Risks appeared first on SecurityWeek. Read More
-

Why You Need Continuous Network Monitoring? [email protected] (The Hacker News)
Changes in the way we work have had significant implications for cybersecurity, not least in network monitoring. Workers no longer sit safely side-by-side on a corporate network, dev teams constantly spin up and tear down systems, exposing services to the internet. Keeping track of these users, changes and services is difficult – internet-facing attack surfaces…
-
Cybersecurity M&A Roundup for August 1-15, 2023 Eduard Kovacs
Twenty-five cybersecurity-related M&A deals were announced in the first half of August 2023. The post Cybersecurity M&A Roundup for August 1-15, 2023 appeared first on SecurityWeek. Read More
-

Russian Hackers Use Zulip Chat App for Covert C&C in Diplomatic Phishing Attacks [email protected] (The Hacker News)
An ongoing campaign targeting ministries of foreign affairs of NATO-aligned countries points to the involvement of Russian threat actors. The phishing attacks feature PDF documents with diplomatic lures, some of which are disguised as coming from Germany, to deliver a variant of a malware called Duke, which has been attributed to APT29 (aka BlueBravo, Cloaked Ursa, Cozy Bear,…
