Security News

APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDP
2024-12-18 11:15

The Russia-linked APT29 threat actor has been observed repurposing a legitimate red teaming attack methodology as part of cyber attacks leveraging malicious Remote Desktop Protocol (RDP)...

Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks
2024-12-17 14:11

A new phishing campaign has been observed employing tax-themed lures to deliver a stealthy backdoor payload as part of attacks targeting Pakistan. Cybersecurity company Securonix, which is...

Hackers Exploit Webview2 to Deploy CoinLurker Malware and Evade Security Detection
2024-12-17 09:03

Bogus software update lures are being used by threat actors to deliver a new stealer malware called CoinLurker. "Written in Go, CoinLurker employs cutting-edge obfuscation and anti-analysis...

Winnti hackers target other threat actors with new Glutton PHP backdoor
2024-12-15 15:19

​The Chinese Winnti hacking group is using a new PHP backdoor named 'Glutton' in attacks on organizations in China and the U.S., and also in attacks on other cybercriminals. [...]

390,000 WordPress accounts stolen from hackers in supply chain attack
2024-12-14 15:17

A threat actor tracked as MUT-1244 has stolen over 390,000 WordPress credentials in a large-scale, year-long campaign targeting other threat actors using a trojanized WordPress credentials checker. [...]

Russian cyber spies hide behind other hackers to target Ukraine
2024-12-11 17:00

Russian cyber-espionage group Turla, aka "Secret Blizzard," is utilizing other threat actors' infrastructure to target Ukrainian military devices connected via Starlink. [...]

Russian Turla hackers hit Starlink-connected devices in Ukraine
2024-12-11 17:00

Russian cyber-espionage group Turla, aka "Secret Blizzard," is utilizing other threat actors' infrastructure to target Ukrainian military devices connected via Starlink. [...]

U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls
2024-12-11 06:29

The U.S. government on Tuesday unsealed charges against a Chinese national for allegedly breaking into thousands of Sophos firewall devices globally in 2020. Guan Tianfeng (aka gbigmao and...

Chinese hackers use Visual Studio Code tunnels for remote access
2024-12-10 11:00

Chinese hackers targeting large IT service providers in Southern Europe were seen abusing Visual Studio Code (VSCode) tunnels to maintain persistent access to compromised systems. [...]

Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage
2024-12-10 11:00

A suspected China-nexus cyber espionage group has been attributed to an attacks targeting large business-to-business IT service providers in Southern Europe as part of a campaign codenamed...