Malware & Threats Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks Akamai warns that a Chinese threat actor is exploiting years-old remote code execution vulnerabilities in ThinkPHP in new attacks. Ionut ArghireJune 6, 2024
Malware & Threats Google, Microsoft: Russian Threat Actors Pose High Risk to 2024 Paris Olympics Google and Microsoft warn of elevated risks of cyber threats facing the 2024 Paris Olympics, especially from Russian threat actors. Ionut ArghireJune 6, 2024
Malware & Threats Multiple Chinese APTs Targeted Southeast Asian Government for Two Years Multiple Chinese state-sponsored groups have targeted a Southeast Asian government in a years-long cyberespionage campaign. Ionut ArghireJune 6, 2024
Malware & Threats Researchers Show How Malware Could Steal Windows Recall Data Cybersecurity researchers are demonstrating how malware could steal data collected by the new Windows Recall feature. Eduard KovacsJune 5, 2024
Malware & Threats CISA Warns of Attacks Exploiting Old Oracle WebLogic Vulnerability CISA has added an old Oracle WebLogic flaw tracked as CVE-2017-3506 to its known exploited vulnerabilities catalog. Eduard KovacsJune 4, 2024
Malware & Threats Identities of Cybercriminals Linked to Malware Loaders Revealed Law enforcement reveals the identities of eight cybercriminals linked to recently disrupted malware loaders. Ionut ArghireJune 3, 2024
Malware & Threats PoC Published for Exploited Check Point VPN Vulnerability PoC code targeting a recent Check Point VPN zero-day has been released as Censys identifies 14,000 internet-accessible appliances. Ionut ArghireJune 3, 2024
Malware & Threats Mysterious Threat Actor Used Chalubo Malware to Brick 600,000 Routers Over 600,000 SOHO routers belonging to a single ISP and infected with the Chalubo trojan were rendered inoperable. Ionut ArghireMay 31, 2024
Malware & Threats Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors Malicious campaign exploits high-severity XSS flaws in three WordPress plugins to backdoor websites. Ionut ArghireMay 30, 2024
Malware & Threats TrickBot and Other Malware Droppers Disrupted by Law Enforcement The TrickBot botnet and other malware droppers have been targeted by international law enforcement in Operation Endgame. Ionut ArghireMay 30, 2024
Malware & Threats Okta Warns of Credential Stuffing Attacks Targeting Cross-Origin Authentication Okta raises the alarm on credential stuffing attacks targeting endpoints used for cross-origin authentication. Ionut ArghireMay 30, 2024
Malware & Threats Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested The US announced that the 911 S5 (Cloud Router) botnet, likely the world’s largest, has been dismantled and its administrator arrested. Eduard KovacsMay 30, 2024