Security News
![Open-source Blender project battling DDoS attacks since Saturday](/static/build/img/news/open-source-blender-project-battling-ddos-attacks-since-saturday-small.jpg)
Blender has confirmed that recent site outages have been caused by ongoing DDoS attacks that started on Saturday. "Since last Saturday, 18 November, the blender.org servers are under a DDoS attack; bringing down our servers by overloading them with requests," reads the announcement.
![New Agent Tesla Malware Variant Using ZPAQ Compression in Email Attacks](/static/build/img/news/new-agent-tesla-malware-variant-using-zpaq-compression-in-email-attacks-small.jpg)
A new variant of the Agent Tesla malware has been observed delivered via a lure file with the ZPAQ compression format to harvest data from several email clients and nearly 40 web browsers. "ZPAQ...
![Maintaining a state of readiness to deal with cyber attacks](/static/build/img/news/maintaining-a-state-of-readiness-to-deal-with-cyber-attacks-small.jpg)
Sponsored Post You can never afford to drop your guard when it comes to cyber security - hackers never do. With cyber criminals constantly devising new methods of attack and exploitation, how do you stay ahead of the curve?
![How Multi-Stage Phishing Attacks Exploit QRs, CAPTCHAs, and Steganography](/static/build/img/news/how-multi-stage-phishing-attacks-exploit-qrs-captchas-and-steganography-small.jpg)
Phishing attacks are steadily becoming more sophisticated, with cybercriminals investing in new ways of deceiving victims into revealing sensitive information or installing malicious software. One...
![DarkGate and PikaBot Malware Resurrect QakBot's Tactics in New Phishing Attacks](/static/build/img/news/darkgate-and-pikabot-malware-resurrect-qakbot-s-tactics-in-new-phishing-attacks-small.jpg)
Phishing campaigns delivering malware families such as DarkGate and PikaBot are following the same tactics previously used in attacks leveraging the now-defunct QakBot trojan. “These include...
![Russian hackers use Ngrok feature and WinRAR exploit to attack embassies](/static/build/img/news/russian-hackers-use-ngrok-feature-and-winrar-exploit-to-attack-embassies-small.jpg)
NDSC says that the Russian hackers used a Ngrok free static domain to access the command and control server hosted on their Ngrok instance. A report from Google in October notes that the security issue was exploited by Russian and Chinese state hackers to steal credentials and other sensitive data, as well as to establish persistence on target systems.
![FCC adopts new rules to protect consumers from SIM-swapping attacks](/static/build/img/news/fcc-adopts-new-rules-to-protect-consumers-from-sim-swapping-attacks-small.jpg)
The Federal Communications Commission has revealed new rules to shield consumers from criminals who hijack their phone numbers in SIM swapping attacks and port-out fraud. In SIM swapping attacks, criminals trick a victim's wireless carrier into redirecting their service to a device controlled by the fraudster.
![Russian Cyber Espionage Group Deploys LitterDrifter USB Worm in Targeted Attacks](/static/build/img/news/russian-cyber-espionage-group-deploys-litterdrifter-usb-worm-in-targeted-attacks-small.jpg)
Russian cyber espionage actors affiliated with the Federal Security Service (FSB) have been observed using a USB propagating worm called LitterDrifter in attacks targeting Ukrainian entities....
![Bloomberg Crypto X account snafu leads to Discord phishing attack](/static/build/img/news/bloomberg-crypto-x-account-snafu-leads-to-discord-phishing-attack-small.jpg)
The official Twitter account for Bloomberg Crypto was used earlier today to redirect users to a deceptive website that stole Discord credentials in a phishing attack. As first spotted by crypto fraud investigator ZachXBT, the profile contained a link to a Telegram channel with 14,000 members, further pushing visitors to join a fake Bloomberg Discord server with 33,968 members.
![Bloomberg Crypto X account hijacked in Discord phishing attack](/static/build/img/news/bloomberg-crypto-x-account-hijacked-in-discord-phishing-attack-small.jpg)
The official Twitter account for Bloomberg Crypto was compromised earlier today, ultimately redirecting users to a deceptive website used to steal Discord credentials in a phishing attack. As first spotted by crypto fraud investigator ZachXBT, the hijacked profile contained a link to a fake Telegram channel with 14,000 members, further pushing visitors to join a fake Bloomberg Discord server with 33,968 members.