Security News

Slovenia's largest power provider HSE hit by ransomware attack
2023-11-27 16:16

Slovenian power company Holding Slovenske Elektrarne has suffered a ransomware attack that compromised its systems and encrypted files, yet the company says the incident did not disrupt electric power production. HSE is Slovenia's largest power generation company, accounting for roughly 60% of domestic production, and it is considered critical infrastructure in the country.

General Electric investigates claims of cyber attack, data theft
2023-11-25 22:05

General Electric is investigating claims that a threat actor breached the company's development environment in a cyberattack and leaked allegedly stolen data.After not selling said alleged access, the threat actor posted again that they are now selling both the network access and allegedly stolen data.

New 'HrServ.dll' Web Shell Detected in APT Attack Targeting Afghan Government
2023-11-25 05:08

An unspecified government entity in Afghanistan was targeted by a previously undocumented web shell called HrServ in what’s suspected to be an advanced persistent threat (APT) attack. The web...

UK and South Korea: Hackers use zero-day in supply-chain attack
2023-11-24 17:28

The attack started with compromising a media outlet's website to embed malicious scripts into an article, allowing for a 'watering hole' attack. State-backed North Korean hacking operations consistently rely on supply chain attacks and the exploitation of zero-day vulnerabilities as part of their cyber warfare tactics.

Konni Group Using Russian-Language Malicious Word Docs in Latest Attacks
2023-11-23 14:46

A new phishing attack has been observed leveraging a Russian-language Microsoft Word document to deliver malware capable of harvesting sensitive information from compromised Windows hosts. The...

Attack on direct debit provider London & Zurich leaves customers with 6-figure backlogs
2023-11-23 11:47

A ransomware attack and resulting outages at direct debit collection company London & Zurich has forced at least one customer to take out a short-term loan as six-figure backlogs continue to cause cash flow mayhem. London & Zurich's outage began on November 10 and was confirmed as a ransomware attack four days later on the company's website.

Mirai-based Botnet Exploiting Zero-Day Bugs in Routers and NVRs for Massive DDoS Attacks
2023-11-23 10:47

An active malware campaign is leveraging two zero-day vulnerabilities with remote code execution (RCE) functionality to rope routers and video recorders into a Mirai-based distributed...

N. Korean Hackers Distribute Trojanized CyberLink Software in Supply Chain Attack
2023-11-23 05:46

A North Korean state-sponsored threat actor tracked as Diamond Sleet is distributing a trojanized version of a legitimate application developed by a Taiwanese multimedia software developer called...

Cybercriminals turn to ready-made bots for quick attacks
2023-11-23 05:30

Researchers assessed the attacks across three primary attack vectors: basic bots, intelligent bots, and human fraud farms. The analysis found bot attacks overall increased 167% in the H1 of 2023, weighted heavily by a 291% increase in intelligent bots.

Microsoft: Lazarus hackers breach CyberLink in supply chain attack
2023-11-22 18:06

Microsoft says a North Korean hacking group has breached Taiwanese multimedia software company CyberLink and trojanized one of its installers to push malware in a supply chain attack targeting potential victims worldwide. According to Microsoft Threat Intelligence, activity suspected to be linked with the altered CyberLink installer file surfaced as early as October 20, 2023.