Security News

Hackers target Russian govt with fake Windows updates pushing RATs
2022-05-24 19:27

Hackers are targeting Russian government agencies with phishing emails that pretend to be Windows security updates and other lures to install remote access malware. These operations spanned between February and April 2022, coinciding with the Russian invasion of Ukraine.

Why do hackers keep coming back to attack you? Because they can
2022-05-24 17:15

Hackers have a tendency to return to the scene of their crimes over and over again. If you want to fast forward your data security policy you should join our upcoming webinar, Your best defence against cyber attacks is an Iron Man suit for your data, on June 8th at 9am PT. Our own Martin Courtney will be joined by Rubrik's Murthy Mathiprakasam to discuss how, when it comes to protecting data, some heroes don't wear capes.

Trend Micro fixes bug Chinese hackers exploited for espionage
2022-05-24 16:09

Trend Micro says it patched a DLL hijacking flaw in Trend Micro Security used by a Chinese threat group to side-load malicious DLLs and deploy malware. As Sentinel Labs revealed in an early-May report, the attackers exploited the fact that security products run with high privileges on Windows to plant and load their own maliciously crafted DLL into memory, allowing them to elevate privileges and execute code.

Hackers can hack your online accounts before you even register them
2022-05-23 17:02

Security researchers have revealed that hackers can hijack your online accounts before you even register them by exploiting flaws that have been already been fixed on popular websites, including Instagram, LinkedIn, Zoom, WordPress, and Dropbox. Rew Paverd, a researcher at Microsoft Security Response Center, and Avinash Sudhodanan, an independent security researcher, analyzed 75 popular online services and found that at least 35 are vulnerable to account pre-hijacking attacks.

Russian hackers perform reconnaissance against Austria, Estonia
2022-05-23 13:14

In a new reconnaissance campaign, the Russian state-sponsored hacking group Turla was observed targeting the Austrian Economic Chamber, a NATO platform, and the Baltic Defense College. This discovery comes from cybersecurity firm Sekoia, which built upon previous findings of Google's TAG, which has been following Russian hackers closely this year.

Chinese "Twisted Panda" Hackers Caught Spying on Russian Defense Institutes
2022-05-22 23:12

At least two research institutes located in Russia and a third likely target in Belarus have been at the receiving end of an espionage attack by a Chinese nation-state advanced persistent threat. The attacks, codenamed "Twisted Panda," come in the backdrop of Russia's military invasion of Ukraine, prompting a wide range of threat actors to swiftly adapt their campaigns on the ongoing conflict to distribute malware and stage opportunistic attacks.

Hackers Gain Fileless Persistence on Targeted SQL Servers Using a Built-in Utility
2022-05-20 20:13

Microsoft on Tuesday warned that it recently spotted a malicious campaign targeting SQL Servers that leverages a built-in PowerShell binary to achieve persistence on compromised systems. The intrusions, which leverage brute-force attacks as an initial compromise vector, stand out for their use of the utility "Sqlps.exe," the tech giant said in a series of tweets.

Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware
2022-05-20 20:11

Fraudulent domains masquerading as Microsoft's Windows 11 download portal are attempting to trick users into deploying trojanized installation files to infect systems with the Vidar information stealer malware. "The spoofed sites were created to distribute malicious ISO files which lead to a Vidar info-stealer infection on the endpoint," Zscaler said in a report.

Hackers Exploiting VMware Horizon to Target South Korea with NukeSped Backdoor
2022-05-20 03:23

The North Korea-backed Lazarus Group has been observed leveraging the Log4Shell vulnerability in VMware Horizon servers to deploy the NukeSped implant against targets located in its southern counterpart. NukeSped is a backdoor that can perform various malicious activities based on commands received from a remote attacker-controlled domain.

U.S. DOJ will no longer prosecute ethical hackers under CFAA
2022-05-19 17:24

With this policy update, the DOJ is separating cases of good-faith security research from ill-intended hacking, which were previously distinguished by a blurred line that frequently placed ethical security research in a problematic, gray legal area. Under these new policies, software testing, investigation, security flaw analysis, and network breaches intended to promote the security and safety of the target devices or services are not to be prosecuted by federal prosecutors.