Security News > 2024 > December

Secret Blizzard Deploys Kazuar Backdoor in Ukraine Using Amadey Malware-as-a-Service
2024-12-11 18:02

The Russian nation-state actor tracked as Secret Blizzard has been observed leveraging malware associated with other threat actors to deploy a known backdoor called Kazuar on target devices...

Russian cyber spies hide behind other hackers to target Ukraine
2024-12-11 17:00

Russian cyber-espionage group Turla, aka "Secret Blizzard," is utilizing other threat actors' infrastructure to target Ukrainian military devices connected via Starlink. [...]

Russian Turla hackers hit Starlink-connected devices in Ukraine
2024-12-11 17:00

Russian cyber-espionage group Turla, aka "Secret Blizzard," is utilizing other threat actors' infrastructure to target Ukrainian military devices connected via Starlink. [...]

Operation PowerOFF shuts down 27 DDoS-for-hire platforms
2024-12-11 16:34

Law enforcement agencies from 15 countries have taken 27 DDoS-for-hire services offline, also known as "booters" or "stressers," arrested three administrators, and identified 300 customers of the...

Lynx ransomware behind Electrica energy supplier cyberattack
2024-12-11 16:28

​The Romanian National Cybersecurity Directorate (DNSC) says the Lynx ransomware gang breached Electrica Group, one of the largest electricity suppliers in the country. [...]

New Malware Technique Could Exploit Windows UI Framework to Evade EDR Tools
2024-12-11 15:13

A newly devised technique leverages a Windows accessibility framework called UI Automation (UIA) to perform a wide range of malicious activities without tipping off endpoint detection and response...

Krispy Kreme cyberattack impacts online orders and operations
2024-12-11 14:44

US doughnut chain Krispy Kreme suffered a cyberattack in November that impacted portions of its business operations, including placing online orders. [...]

CrowdStrike vs Wiz: Which Offers Better Cloud Security and Value?
2024-12-11 14:35

Compare CrowdStrike and Wiz on cloud security, features, pricing, and performance to find the best cybersecurity solution for your business needs.

Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts
2024-12-11 14:32

Cybersecurity researchers have flagged a "critical" security vulnerability in Microsoft's multi-factor authentication (MFA) implementation that allows an attacker to trivially sidestep the...

ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms
2024-12-11 14:07

Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the...