Category: Attack Feeds

0

A Comprehensive Guide to Finding Service Accounts in Active Directory – [email protected] (The Hacker News)

– Service accounts are vital in any enterprise, running automated processes like managing applications or scripts. However, without proper monitoring, they can pose a significant security risk due to their elevated privileges. This guide will walk you through how to locate and secure these accounts within Active Directory (AD), and explore how Silverfort’s solutions can help enhance your  – Read...

0

Malicious npm Packages Target Developers’ Ethereum Wallets with SSH Backdoor – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have discovered a number of suspicious packages published to the npm registry that are designed to harvest Ethereum private keys and gain remote access to the machine via the secure shell (SSH) protocol. The packages attempt to “gain SSH access to the victim’s machine by writing the attacker’s SSH public key in the root user’s authorized_keys file,”...

0

Bumblebee and Latrodectus Malware Return with Sophisticated Phishing Strategies – [email protected] (The Hacker News)

– [[{“value”:”Two malware families that suffered setbacks in the aftermath of a coordinated law enforcement operation called Endgame have resurfaced as part of new phishing campaigns. Bumblebee and Latrodectus, which are both malware loaders, are designed to steal personal data, along with downloading and executing additional payloads onto compromised hosts. Tracked under the names BlackWidow, IceNova, Lotus,”}]]  – Read More ...

0

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability – [email protected] (The Hacker News)

– [[{“value”:”VMware has released software updates to address an already patched security flaw in vCenter Server that could pave the way for remote code execution. The vulnerability, tracked as CVE-2024-38812 (CVSS score: 9.8), concerns a case of heap-overflow vulnerability in the implementation of the DCE/RPC protocol. “A malicious actor with network access to vCenter Server may trigger this vulnerability by”}]] ...

0

Pwn2Own Ireland Day One – The Results – Dustin Childs

– [[{“value”:” Welcome to the first day of Pwn2Own Ireland 2024! We have four tremendous days of research planned, including multiple SOHO attempts. We’ll be updating this blog in real time as results become available. We have a full schedule of attempts today, so stay tuned! All times are Irish Standard Time (GMT +1:00). “}]]  – Read More  – Zero...

0

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation as a zero-day. The vulnerability in question, tracked as CVE-2024-9537 (CVSS v4 score: 9.3), refers to a bug involving an unspecified third-party component that could”}]]  – Read More  –...

0

Justice Department rule aims to curb the sale of Americans’ personal data overseas – djohnson

– [[{“value”:” The Justice Department has formally proposed new regulations that would prevent or restrict the selling and transferring of Americans’ sensitive personal data to adversarial countries. The proposed rule, first previewed in March, stems from an executive order issued by the Biden administration in February and imposes a series of restrictions on how American entities can sell “bulk” sensitive...

0

Pwn2Own Ireland – The Full Schedule – Dustin Childs

– [[{“value”:” Welcome to Pwn2Own Ireland 2024 – our first event ever from the emerald isle! This year’s contest is set to be one of our largest ever – both in terms of entries and potential prizes. If everything hits, we will end up paying out over $1,000,000 in cash and prizes. We’ve got four days of exciting competition ahead....

0

A Look at the Social Engineering Element of Spear Phishing Attacks – [email protected]

– [[{“value”:” When you think of a cyberattack, you probably envision a sophisticated hacker behind a Matrix-esque screen actively penetrating networks with their technical prowess. However, the reality of many attacks is far more mundane. A simple email with an innocent subject line such as “Missed delivery attempt” sits in an employee’s spam folder. They open it absentmindedly, then enter...

0

Sophos to acquire Secureworks for $859 million in cash – Christian Vasquez

– [[{“value”:” The cybersecurity firm Sophos agreed to acquire Secureworks in an all-cash transaction valued at $859 million, the two companies announced Monday. Sophos, a privately owned United Kingdom-based cybersecurity firm, said it intends to integrate security solutions for all small, mid-sized and enterprise customers focusing on automated prevention, detection, and response using artificial intelligence.  “Secureworks’ renowned expertise in cybersecurity...

0

Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain – [email protected] (The Hacker News)

– [[{“value”:”The prolific Chinese nation-state actor known as APT41 (aka Brass Typhoon, Earth Baku, Wicked Panda, or Winnti) has been attributed to a sophisticated cyber attack targeting the gambling and gaming industry. “Over a period of at least six months, the attackers stealthily gathered valuable information from the targeted company including, but not limited to, network configurations, user passwords,”}]]  –...

0

State Department offers $10 million reward for info on Russian propaganda outlet – Greg Otto

– [[{“value”:” The U.S. government has announced a reward of up to $10 million for information about the Russian media organization Rybar and its employees, amid allegations it’s involved in spreading propaganda aimed at influencing the upcoming U.S. presidential election. According to the State Department’s Rewards for Justice Program, Rybar has been accused of using its extensive social media reach,...

0

Sophos to Acquire Secureworks to Accelerate Cybersecurity Services and Technology for Organizations Worldwide – Editor

– We have exciting news! Two global cybersecurity leaders are joining forces to accelerate the delivery of advanced cybersecurity services and technology for organizations of all sizes around the world. Sophos today has announced a definitive agreement to acquire Secureworks®, the developer of TaegisTM, the SaaS-based, open MDR/XDR platform built on more than 20 years of […]  – Read More ...

0

THN Cybersecurity Recap: Top Threats, Tools and News (Oct 14 – Oct 20) – [email protected] (The Hacker News)

– [[{“value”:”Hi there! Here’s your quick update on the latest in cybersecurity. Hackers are using new tricks to break into systems we thought were secure—like finding hidden doors in locked houses. But the good news? Security experts are fighting back with smarter tools to keep data safe. Some big companies were hit with attacks, while others fixed their vulnerabilities just...

0

Guide:  The Ultimate Pentest Checklist for Full-Stack Security – [email protected] (The Hacker News)

– [[{“value”:”Pentest Checklists Are More Important Than Ever Given the expanding attack surface coupled with the increasing sophistication of attacker tactics and techniques, penetration testing checklists have become essential for ensuring thorough assessments across an organization’s attack surface, both internal and external. By providing a structured approach, these checklists help testers systematically”}]]  – Read More  – The Hacker News 

0

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have discovered severe cryptographic issues in various end-to-end encrypted (E2EE) cloud storage platforms that could be exploited to leak sensitive data. “The vulnerabilities range in severity: in many cases a malicious server can inject files, tamper with file data, and even gain direct access to plaintext,” ETH Zurich researchers Jonas Hofmann and Kien Tuong Truong”}]]  – Read...

0

Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login Credentials – [email protected] (The Hacker News)

– [[{“value”:”Unknown threat actors have been observed attempting to exploit a now-patched security flaw in the open-source Roundcube webmail software as part of a phishing attack designed to steal user credentials. Russian cybersecurity company Positive Technologies said it discovered last month that an email was sent to an unspecified governmental organization located in one of the Commonwealth of”}]]  – Read...

0

Acronym Overdose – Navigating the Complex Data Security Landscape – [email protected] (The Hacker News)

– In the modern enterprise, data security is often discussed using a complex lexicon of acronyms—DLP, DDR, DSPM, and many others. While these acronyms represent critical frameworks, architectures, and tools for protecting sensitive information, they can also overwhelm those trying to piece together an effective security strategy. This article aims to demystify some of the most important acronyms  – Read...

0

Celebrating Internet Day: The Tech Trifecta Shaping Our Digital Future – [email protected]

– [[{“value”:” The content of this post is solely the responsibility of the author.  LevelBlue does not adopt or endorse any of the views, positions, or information provided by the author in this article.  As we gear up to celebrate Internet Day on October 29th, let’s take a moment to appreciate how much the Internet has revolutionized our lives. From...

0

Crypt Ghouls Targets Russian Firms with LockBit 3.0 and Babuk Ransomware Attacks – [email protected] (The Hacker News)

– [[{“value”:”A nascent threat actor known as Crypt Ghouls has been linked to a set of cyber attacks targeting Russian businesses and government agencies with ransomware with the twin goals of disrupting business operations and financial gain. “The group under review has a toolkit that includes utilities such as Mimikatz, XenAllPasswordPro, PingCastle, Localtonet, resocks, AnyDesk, PsExec, and others,””}]]  – Read...

0

North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data – [email protected] (The Hacker News)

– [[{“value”:”North Korean information technology (IT) workers who obtain employment under false identities in Western companies are not only stealing intellectual property, but are also stepping up by demanding ransoms in order to not leak it, marking a new twist to their financially motivated attacks. “In some instances, fraudulent workers demanded ransom payments from their former employers after gaining”}]]  –...

0

Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach – BrianKrebs

– [[{“value”:” Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being “USDoD,” a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI’s InfraGard program and leaking contact information for 80,000 members. More recently, USDoD was behind a breach at the consumer data broker National Public Data that led to the leak of Social Security...

0

U.S. and Allies Warn of Iranian Cyberattacks on Critical Infrastructure in Year-Long Campaign – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity and intelligence agencies from Australia, Canada, and the U.S. have warned about a year-long campaign undertaken by Iranian cyber actors to infiltrate critical infrastructure organizations via brute-force attacks. “Since October 2023, Iranian actors have used brute force and password spraying to compromise user accounts and obtain access to organizations in the healthcare and”}]]  – Read More  – The...

0

The Ultimate DSPM Guide: Webinar on Building a Strong Data Security Posture – [email protected] (The Hacker News)

– [[{“value”:”Picture your company’s data as a vast, complex jigsaw puzzle—scattered across clouds, devices, and networks. Some pieces are hidden, some misplaced, and others might even be missing entirely. Keeping your data secure in today’s fast-evolving landscape can feel like an impossible challenge. But there’s a game-changing solution: Data Security Posture Management (DSPM). Think of it as a high-tech,”}]]  –...

0

Beware: Fake Google Meet Pages Deliver Infostealers in Ongoing ClickFix Campaign – [email protected] (The Hacker News)

– [[{“value”:”Threat actors are leveraging fake Google Meet web pages as part of an ongoing malware campaign dubbed ClickFix to deliver infostealers targeting Windows and macOS systems. “This tactic involves displaying fake error messages in web browsers to deceive users into copying and executing a given malicious PowerShell code, finally infecting their systems,” French cybersecurity company Sekoia said in”}]]  –...

0

Recapping Raid Forums: The Place Where Data Was Sold to the Highest Bidder – [email protected]

– [[{“value”:” The content of this post is solely the responsibility of the author.  LevelBlue does not adopt or endorse any of the views, positions, or information provided by the author in this article.  From stolen personal data to entire corporate databases, Raid Forums was a digital black market where the most valuable commodities weren’t physical goods but sensitive information....

0

Microsoft Reveals macOS Vulnerability that Bypasses Privacy Controls in Safari Browser – [email protected] (The Hacker News)

– [[{“value”:”Microsoft has disclosed details about a now-patched security flaw in Apple’s Transparency, Consent, and Control (TCC) framework in macOS that has likely come under exploitation to get around a user’s privacy preferences and access data. The shortcoming, codenamed HM Surf by the tech giant, is tracked as CVE-2024-44133. It was addressed by Apple as part of macOS Sequoia 15...

0

A glimmer of good news on the ransomware front, as encryption rates plummet – Graham Cluley

– [[{“value”:”No-one would be bold enough to say that the ransomware problem is receding, but a newly-published report by Microsoft does deliver a slither of encouraging news amongst the gloom. And boy do we need some good news – amid reports that 389 US-based healthcare institutions were hit by ransomware last year – more than one every single day. Read...

0

Alabama man arrested for role in SEC Twitter account hijacking – djohnson

– [[{“value”:” A 25-year-old Alabama man has been arrested and charged with hacking into the Securities and Exchange Commission’s Twitter/X account earlier this year and making fake regulatory posts that artificially inflated the price of Bitcoin by more than $1,000 per unit. Eric Council Jr., a resident of Athens, Ala., was arrested Thursday morning and charged with aggravated identity theft...

0

Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant – [email protected] (The Hacker News)

– [[{“value”:”The Russian threat actor known as RomCom has been linked to a new wave of cyber attacks aimed at Ukrainian government agencies and unknown Polish entities since at least late 2023. The intrusions are characterized by the use of a variant of the RomCom RAT dubbed SingleCamper (aka SnipBot or RomCom 5.0), said Cisco Talos, which is monitoring the...

0

Brazil’s Federal Police arrest alleged National Public Data hacker – Greg Otto

– [[{“value”:” The Federal Police of Brazil on Wednesday arrested a person allegedly responsible for a series of audacious data breaches targeting large international companies and U.S. government entities.  The suspect, who is known in the cybercrime underground as USDoD or EquationCorp, is allegedly the person responsible for a breach of the online background check and fraud prevention service National...

0

Researchers Uncover Cicada3301 Ransomware Operations and Its Affiliate Program – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have gleaned additional insights into a nascent ransomware-as-a-service (RaaS) called Cicada3301 after successfully gaining access to the group’s affiliate panel on the dark web. Singapore-headquartered Group-IB said it contacted the threat actor behind the Cicada3301 persona on the RAMP cybercrime forum via the Tox messaging service after the latter put out an”}]]  – Read More  – The...

0

Sudanese Brothers Arrested in ‘AnonSudan’ Takedown – BrianKrebs

– [[{“value”:” The U.S. government on Wednesday announced the arrest and charging of two Sudanese brothers accused of running Anonymous Sudan (a.k.a. AnonSudan), a cybercrime business known for launching powerful distributed denial-of-service (DDoS) attacks against a range of targets, including dozens of hospitals, news websites and cloud providers. The younger brother is facing charges that could land him life in...

0

SideWinder APT Strikes Middle East and Africa With Stealthy Multi-Stage Attack – [email protected] (The Hacker News)

– [[{“value”:”An advanced persistent threat (APT) actor with suspected ties to India has sprung forth with a flurry of attacks against high-profile entities and strategic infrastructures in the Middle East and Africa. The activity has been attributed to a group tracked as SideWinder, which is also known as APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor Tiger, and T-APT-04. “”}]] ...

0

5 Ways to Reduce SaaS Security Risks – [email protected] (The Hacker News)

– As technology adoption has shifted to be employee-led, just in time, and from any location or device, IT and security teams have found themselves contending with an ever-sprawling SaaS attack surface, much of which is often unknown or unmanaged. This greatly increases the risk of identity-based threats, and according to a recent report from CrowdStrike, 80% of breaches today...

0

Pitfalls of Cloud Sprawl and How to Avoid Them – [email protected]

– [[{“value”:” The content of this post is solely the responsibility of the author.  LevelBlue does not adopt or endorse any of the views, positions, or information provided by the author in this article.  Cloud computing has become a boon to organizations due to its flexibility, scalability, and cost-effectiveness. However, without proper oversight, it evolves into an untidy collection of...

0

U.S. Charges Two Sudanese Brothers for Record 35,000 DDoS Attacks – [email protected] (The Hacker News)

– [[{“value”:”Federal prosecutors in the U.S. have charged two Sudanese brothers with running a distributed denial-of-service (DDoS) botnet for hire that conducted a record 35,000 DDoS attacks in a single year, including those that targeted Microsoft’s services in June 2023. The attacks, which were facilitated by Anonymous Sudan’s “powerful DDoS tool,” singled out critical infrastructure, corporate networks,”}]]  – Read More ...

0

Critical Kubernetes Image Builder Vulnerability Exposes Nodes to Root Access Risk – [email protected] (The Hacker News)

– [[{“value”:”A critical security flaw has been disclosed in the Kubernetes Image Builder that, if successfully exploited, could be abused to gain root access under certain circumstances. The vulnerability, tracked as CVE-2024-9486 (CVSS score: 9.8), has been addressed in version 0.1.38. The project maintainers acknowledged Nicolai Rybnikar for discovering and reporting the vulnerability. “A security issue”}]]  – Read More  –...

0

Smashing Security podcast #389: WordPress vs WP Engine, and the Internet Archive is down – Graham Cluley

– [[{“value”:”WordPress’s emperor, Matt Mullenweg, demands a hefty tribute from WP Engine, and a battle erupts, leaving millions of websites hanging in the balance. Meanwhile, the Internet Archive, a digital library preserving our online history, is under siege from hackers. All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley...