Malware & Threats
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
Hi, what are you looking for?
Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
The medtech giant has been working on restoring systems affected by the cyberattack conducted by the Handala hackers.
The botnet has increased its activity, peaking at 15,000 exploitation attempts per day, and taking a more targeted approach.
Storm-2561 is distributing fake VPN clients through SEO poisoning, deploying trojans, and stealing login information.
Hundreds of GitHub accounts were accessed using credentials stolen in the VS Code GlassWorm campaign.
Other noteworthy stories that might have slipped under the radar: Telus Digital data breach, vulnerabilities in Linux AppArmor allow root privileges, US defense contractor...
Law enforcement agencies in the US and Europe targeted the cybercrime service that has impacted 360,000 devices since 2020.
The 2024 incident was initially linked to China, but an infostealer infection has now revealed North Korean involvement.
The malware disables antivirus and EDR protections at the kernel level, clearing the path for credential harvesting, system reconnaissance, and eventual data exfiltration.
Fake CAPTCHA pages instruct victims to paste malicious commands in the Windows Terminal instead of the Run dialog.
Threat actors replace legitimate commands on the cloned installation webpages with malicious commands.
The malware targets browser and cryptocurrency wallet data, along with system information and user files.
Employees seeking free versions of paid software may unknowingly install malware-laced “cracked” apps that can steal credentials, deploy cryptominers, or open the door to...
Using Windows shortcut files, the APT deployed a new implant, a loader, a propagation tool, and two backdoors.
Other noteworthy stories that might have slipped under the radar: cyber valuations surge, OpenAI disrupts malicious AI use, ShinyHunters claims Odido breach.
Aeternum operates on smart contracts, making its command-and-control (C&C) infrastructure difficult to disrupt.
Already added to CISA’s KEV catalog, the flaw allows attackers to bypass authentication and gain administrative privileges.
The UNC2814 threat actor has been active since at least 2017, targeting organizations across 42 countries.
Written in C++ and Python, the malware exfiltrates system information, browser data, and steals files.
The malicious code propagates like a worm, poisons AI assistants, exfiltrates secrets, and contains a destructive dead switch.