Category: Attack Feeds

Data Governance in DevOps: Ensuring Compliance in the AI Era – [email protected] (The Hacker News)

– With the evolution of modern software development, CI/CD pipeline governance has emerged as a critical factor in maintaining both agility and compliance. As we enter the age of artificial intelligence (AI), the importance of robust pipeline governance has only intensified. With that said, we’ll explore the concept of CI/CD pipeline governance and why it’s vital, especially as AI becomes ...

Amnesty International exposes Serbian police’s use of spyware on journalists, activists – Tim Starks

– [[{“value”:” Serbian police and intelligence authorities have combined phone-cracking technology with spyware to eavesdrop on activists and journalists there, Amnesty International revealed in a report Monday, in what the human rights group says could be a disturbing preview of a future era of digital surveillance. Amnesty International’s 87-page document surveys the broader picture of digital spying on civil society...

New Glutton Malware Exploits Popular PHP Frameworks Like Laravel and ThinkPHP – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States, Cambodia, Pakistan, and South Africa. QiAnXin XLab, which discovered the malicious activity in late April 2024, attributed the previously unknown malware with moderate confidence to the prolific Chinese nation-state group tracked Winnti (“}]]  – Read...

New Investment Scam Leverages AI, Social Media Ads to Target Victims Worldwide – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers are calling attention to a new kind of investment scam that leverages a combination of social media malvertising, company-branded posts, and artificial intelligence (AI) powered video testimonials featuring famous personalities, ultimately leading to financial and data loss. “The main goal of the fraudsters is to lead victims to phishing websites and forms that harvest”}]]  – Read More ...

Ukrainian Minors Recruited for Cyber Ops and Reconnaissance in Russian Airstrikes – [email protected] (The Hacker News)

– [[{“value”:”The Security Service of Ukraine (SBU or SSU) has exposed a novel espionage campaign suspected to be orchestrated by Russia’s Federal Security Service (FSB) that involves recruiting Ukrainian minors for criminal activities under the guise of “quest games.” Law enforcement officials said that it detained two FSB agent groups following a special operation in Kharkiv. These groups, per the...

Devices with new AI updates are misunderstood as hacking – cyberpro

– [[{“value”:” As AI (artificial intelligence) continues to permeate our world at a very fast pace, we are witnessing the fact that it has entered the landscape at a faster rate than the development of protection software. Companies are gleefully and with almost reckless abandon, adding AI at every turn, and this alone makes use feel a […] The post...

Germany Disrupts BADBOX Malware on 30,000 Devices Using Sinkhole Action – [email protected] (The Hacker News)

– [[{“value”:”Germany’s Federal Office of Information Security (BSI) has announced that it has disrupted a malware operation called BADBOX that came preloaded on at least 30,000 internet-connected devices sold across the country. In a statement published earlier this week, authorities said they severed the communications between the devices and their command-and-control (C2) servers by sinkholing the domains”}]]  – Read More ...

Thai Officials Targeted in Yokai Backdoor Campaign Using DLL Side-Loading Techniques – [email protected] (The Hacker News)

– [[{“value”:”Thai government officials have emerged as the target of a new campaign that leverages a technique called DLL side-loading to deliver a previously undocumented backdoor dubbed Yokai. “The target of the threat actors were Thailand officials based on the nature of the lures,” Nikhil Hegde, senior engineer for Netskope’s Security Efficacy team, told The Hacker News. “The Yokai backdoor...

390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits – [email protected] (The Hacker News)

– [[{“value”:”A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000 credentials. The malicious activity is part of a broader attack campaign undertaken by a threat actor, dubbed MUT-1244 (where MUT refers to “mysterious unattributed threat”) by Datadog Security Labs, that”}]] ...

Arizona man arrested for alleged involvement in violent online terror networks – Greg Otto

– [[{“value”:” Baron Martin, a 20-year-old resident of Tucson, Arizona, was arrested Wednesday on charges of producing child sexual abuse material and cyberstalking. His arrest is connected to his involvement in online terror networks, specifically 764 and CVLT, which are known for violent extremist activities. Martin, also known under the alias “Convict,” is charged with significant involvement in these networks...

Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection – [email protected] (The Hacker News)

– [[{“value”:”A security flaw has been disclosed in OpenWrt’s Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicious firmware packages. The vulnerability, tracked as CVE-2024-54143, carries a CVSS score of 9.3 out of a maximum of 10, indicating critical severity. Flatt Security researcher RyotaK has been credited with discovering and reporting the”}]]  – Read...

DoJ Indicts 14 North Koreans for $88M IT Worker Fraud Scheme Over Six Years – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Department of Justice (DoJ) has indicted 14 nationals belonging to the Democratic People’s Republic of Korea (DPRK or North Korea) for their alleged involvement in a long-running conspiracy to violate sanctions and commit wire fraud, money laundering, and identity theft by illegally seeking employment in U.S. companies and non-profit organizations. “The conspirators, who worked for”}]]  – Read...

How to Generate a CrowdStrike RFM Report With AI in Tines – [email protected] (The Hacker News)

– [[{“value”:”Run by the team at orchestration, AI, and automation platform Tines, the Tines library contains pre-built workflows shared by real security practitioners from across the community, all of which are free to import and deploy via the Community Edition of the platform.  Their bi-annual “You Did What with Tines?!” competition highlights some of the most interesting workflows submitted by...

Iran-Linked IOCONTROL Malware Targets SCADA and Linux-Based IoT Platforms – [email protected] (The Hacker News)

– [[{“value”:”Iran-affiliated threat actors have been linked to a new custom malware that’s geared toward IoT and operational technology (OT) environments in Israel and the United States. The malware has been codenamed IOCONTROL by OT cybersecurity company Claroty, highlighting its ability to attack IoT and supervisory control and data acquisition (SCADA) devices such as IP cameras, routers, programmable”}]]  – Read...

New Linux Rootkit PUMAKIT Uses Advanced Stealth Techniques to Evade Detection – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have uncovered a new Linux rootkit called PUMAKIT that comes with capabilities to escalate privileges, hide files and directories, and conceal itself from system tools, while simultaneously evading detection. “PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with”}]]  – Read More  – The Hacker...

FBI Busts Rydox Marketplace with 7,600 PII Sales, Cryptocurrency Worth $225K Seized – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Department of Justice (DoJ) on Thursday announced the shutdown of an illicit marketplace called Rydox (“rydox.ru” and “rydox[.]cc”) for selling stolen personal information, access devices, and other tools for conducting cybercrime and fraud. In tandem, three Kosovo nationals and administrators of the service, Ardit Kutleshi, Jetmir Kutleshi, and Shpend Sokoli, have been arrested. Ardit”}]]  – Read More ...

Cybercriminal marketplace Rydox seized in international law enforcement operation – Greg Otto

– [[{“value”:” The Justice Department announced Thursday that it had participated in a coordinated effort to seize and dismantle Rydox, an online marketplace for stolen personal information and cybercrime tools. The operation led to the arrest of three individuals alleged to be the site’s administrators. Rydox has been linked to over 7,600 illicit sales and generated substantial profits since its...

Court indicts 14 North Korean IT workers tied to $88 million in illicit gains – Tim Starks

– [[{“value”:” A federal court has indicted 14 more North Korean IT workers as part of an ongoing U.S. government campaign to crack down on Pyongyang’s use of tech professionals to swindle American companies and nonprofits. The Justice Department said the 14 indicted workers generated at least $88 million throughout a conspiracy that stretched over approximately six years, ending in...

SolarWinds Access Rights Manager: One Vulnerability to LPE Them All – Piotr Bazydło

– [[{“value”:” Some time ago, I spent some time researching a core SolarWinds product, SolarWinds Platform (previously Orion Platform). At that time, I hadn’t been aware of the SolarWinds Access Right Manager product (Solar Winds ARM). Afterward, Trend Micro’s Zero Day Initiative began receiving submissions of vulnerabilities in Access Rights Manager (ARM). The first submissions we received were from Sina...

Doughnut orders disrupted! Krispy Kreme suffers hack attack – Graham Cluley

– [[{“value”:”Krispy Kreme, the dispenser of delectable doughnuts, says that it suffered a cyber attack at the end of last month which saw its IT systems compromised and has disrupted online orders in parts of the United States. Read more in my article on the Hot for Security blog.”}]]  – Read More  – Graham Cluley 

Notorious Nigerian cybercriminal tied to BEC scams extradited to U.S. – Greg Otto

– [[{“value”:” Abiola Kayode, a 37-year-old Nigerian national, has been extradited from Ghana to the United States to face charges of conspiracy to commit wire fraud.  Kayode, who was on the FBI’s Most Wanted cybercriminal list, is charged with participating in a business email compromise (BEC) scheme and romance fraud from January 2015 to September 2016, defrauding businesses of over...

International crackdown disrupts DDoS-for-hire operations – Greg Otto

– [[{“value”:” In a sweeping international crackdown, law enforcement agencies from 15 countries, including the United States and multiple European nations, have dismantled 27 of the most popular platforms used for carrying out distributed denial-of-service (DDoS) attacks, Europol announced Wednesday. The operation, known as PowerOFF, has led to the arrest of three administrators in France and Germany and identified 300...

Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States – [email protected] (The Hacker News)

– [[{“value”:”The Russia-linked state-sponsored threat actor tracked as Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking the first time the adversary has been discovered using mobile-only malware families in its attack campaigns. “BoneSpy and PlainGnome target former Soviet states and focus on Russian-speaking victims,” Lookout said in an analysis. “Both”}]]  – Read More ...

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers are warning that thousands of servers hosting the Prometheus monitoring and alerting toolkit are at risk of information leakage and exposure to denial-of-service (DoS) as well as remote code execution (RCE) attacks. “Prometheus servers or exporters, often lacking proper authentication, allowed attackers to easily gather sensitive information, such as credentials and API”}]]  – Read More  – The...

Scammers Exploit Fake Domains in Dubai Police Phishing Scams – Waqas

– BforeAI has discovered a surge in phishing attacks targeting the Dubai Police, a government-run entity. Learn how cybercriminals are exploiting the Dubai Police name to steal personal information and money.  – Read More  – Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News 

27 DDoS-for-hire services disrupted in run-up to holiday season – Graham Cluley

– [[{“value”:”Operation PowerOFF has disrupted what was anticipated to be a surge of distributed denial-of-service (DDoS) attacks over the Christmas period by taking over two dozen “booter” or “stresser” websites offline. Read more in my article on the Tripwire State of Security blog.”}]]  – Read More  – Graham Cluley 

SaaS Budget Planning Guide for IT Professionals – [email protected] (The Hacker News)

– [[{“value”:”SaaS services are one of the biggest drivers of OpEx (operating expenses) for modern businesses. With Gartner projecting $247.2 billion in global SaaS spending this year, it’s no wonder SaaS budgets are a big deal in the world of finance and IT. Efficient SaaS utilization can significantly affect both the bottom line and employee productivity.  In this article, we’ll...

Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS – [email protected] (The Hacker News)

– [[{“value”:”Details have emerged about a now-patched security vulnerability in Apple’s iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and result in unauthorized access to sensitive information. The flaw, tracked as CVE-2024-44131 (CVSS score: 5.3), resides in the FileProvider component, per Apple, and has been addressed with improved”}]]  – Read More  –...

Smashing Security podcast #397: Snowflake hackers, and under the influence – Graham Cluley

– [[{“value”:”A Canadian man is arrested in relation to the Snowflake hacks from earlier this year – after a cybersecurity researcher managed to track his identity, and a cryptocurrency-trading Instagram influencer is in trouble with the law. All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault.”}]] ...

WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins – [email protected] (The Hacker News)

– [[{“value”:”Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks. The flaw, tracked as CVE-2024-11972 (CVSS score: 9.8), affects all versions of the plugin prior to 1.9.0. The plugin has over 10,000 active installations. “This flaw poses a significant security...

Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations; Admins Arrested – [email protected] (The Hacker News)

– [[{“value”:”A global law enforcement operation has failed 27 stresser services that were used to conduct distributed denial-of-service (DDoS) attacks and took them offline as part of a multi-year international exercise called PowerOFF. The effort, coordinated by Europol and involving 15 countries, dismantled several booter and stresser websites, including zdstresser.net, orbitalstress.net, and”}]]  – Read More  – The Hacker News 

Senators, witnesses: $3B for ‘rip and replace’ a good start to preventing Salt Typhoon-style breaches – Tim Starks

– [[{“value”:” The $3 billion that Congress folded into the annual defense policy bill to remove Chinese-made telecommunications technology from U.S. networks would be a huge start to defending against breaches like the Salt Typhoon espionage campaign, senators and hearing witnesses said Wednesday. Federal Communications Commission Chairwoman Jessica Rosenworcel recently told Hill leaders that the $1.9 billion Congress had devoted...

How Cryptocurrency Turns to Cash in Russian Banks – BrianKrebs

– [[{“value”:” A financial firm registered in Canada has emerged as the payment processor for dozens of Russian cryptocurrency exchanges and websites hawking cybercrime services aimed at Russian-speaking customers, new research finds. Meanwhile, an investigation into the Vancouver street address used by this company shows it is home to dozens of foreign currency dealers, money transfer businesses, and cryptocurrency exchanges...

Secret Blizzard Deploys Kazuar Backdoor in Ukraine Using Amadey Malware-as-a-Service – [email protected] (The Hacker News)

– [[{“value”:”The Russian nation-state actor tracked as Secret Blizzard has been observed leveraging malware associated with other threat actors to deploy a known backdoor called Kazuar on target devices located in Ukraine. The new findings come from the Microsoft threat intelligence team, which said it observed the adversary leveraging the Amadey bot malware to download custom malware onto “specifically”}]]  –...

Turla living off other cybercriminals’ tools in order to attack Ukrainian targets – Greg Otto

– [[{“value”:” A Russian nation-state threat actor has been observed leveraging tools from other cybercriminal groups to compromise targets in Ukraine, a recent report by Microsoft Threat Intelligence disclosed. This clandestine approach, which is the second time in as many weeks that Microsoft has highlighted the group’s effort, shows how Turla uses a wide range of attack vectors to infiltrate...