Security News

Shadow Broker leaked NSA files point to unknown APT group
2020-04-24 10:35

Remember the Shadow Brokers, the mysterious group that stole and leaked a collection of NSA files in 2016? Well, it's the gift that keeps on giving. A security researcher claims to have unearthed a previously-unknown APT group after reading over some of the dumped files.

Unpatched VPN Servers Hit by Apparent Iranian APT Groups
2020-02-18 11:03

Now, security firm ClearSky says that at least three advanced persistent threat groups, all with apparent ties to the Iranian government, have been joining the fray and hitting unpatched Fortinet, Pulse Secure and Palo Alto Networks VPN servers and Citrix remote gateways. Specific flaws needing to be patched include CVE-2019-11510 in Pulse Secure's VPN SSL servers, CVE-2018-13379 in Fortigate's SSL VPN servers, and CVE-2019-1579 in Palo Alto Network VPN servers, all of which ClearSky says Fox Kitten is now exploiting.

APT Groups Planting Backdoors: Report
2020-02-17 22:48

Now, security firm ClearSky says that at least three advanced persistent threat groups, all with apparent ties to the Iranian government, have been joining the fray and hitting unpatched Fortinet, Pulse Secure and Palo Alto Networks VPN servers and Citrix remote gateways. Specific flaws needing to be patched include CVE-2019-11510 in Pulse Secure's VPN SSL servers, CVE-2018-13379 in Fortigate's SSL VPN servers, and CVE-2019-1579 in Palo Alto Network VPN servers, all of which ClearSky says Fox Kitten is now exploiting.

TA505 APT Group Returns With New Techniques: Report
2020-02-03 18:48

TA505 - a sophisticated advanced persistent threat group that has targeted financial companies and retailers in several countries, including the U.S. - has returned with a campaign that uses HTML redirectors to deliver malicious Excel documents, according to Microsoft and other security researchers. This threat group is believed to have caused over $100 million in losses over the years, according to the U.S. Treasury Department, which published a report about the group in December when it issued sanctions against some of its members.

Vietnamese APT Group Targets BMW, Hyundai: Report
2019-12-10 19:48

APT32/OceanLotus Suspected in Espionage IncidentHackers suspected to be based in Vietnam compromised the network of German automaker BMW to attempt industrial espionage, according to German media...

Chinese APT Group Targets Mobile Networks: FireEye Mandiant
2019-11-04 18:48

New Malware 'Messagetap' Intercepts Communications for Espionage, Researchers SayThe Chinese advanced threat group APT41 is using a new espionage tool to intercept SMS messages from specific phone...

Russian Hackers Coopted Iranian APT Group's Infrastructure
2019-10-21 14:48

UK and US Intelligence Agencies Report That Turla Group Seized OilRig APT AssetsTurla, an advanced persistent threat group with apparent ties to Russia, seized attack infrastructure and tools used...

APT Groups Exploiting Flaws in Unpatched VPNs, Officials Warn
2019-10-08 12:44

U.S. and U.K. agencies warn consumers to update technologies from Fortinet, Pulse Secure and Palo Alto Networks to mitigate attacks that are likely coming from China

Russia-Backed APT Groups Compete With Each Other: Report
2019-09-25 20:18

Researchers Find That State-Sponsored Cyberespionage Groups Seldom Share CodeAPT groups that are backed by the Russian government rarely share code with each other, fostering a competitive...

Chinese APT Group 'Thrip' Powers Ahead
2019-09-11 19:48

Hackers Have Attacked at Least 12 Targets Since 2018, Symantec Researchers SayA Chinese advanced persistent threat group dubbed "Thrip" has attacked at least 12 organizations in Southeast Asia...